Cybersecurity Fundamentals Explained: Attacks, Encryption, Zero Trust, Authentication and Risk

    Five core topics for beginners in plain English. Each part has a definition, analogy, step-by-step, example, defences, how it appears in the Google Cybersecurity Certificate, exam-style questions and five further-learning links.

    Independent study aid. Not affiliated with or endorsed by Google or Coursera. All explanations, examples and questions are original. Confirm current course content on the official Coursera page.

    Part 1: Types of cyberattacks

    Types of cyberattacks: tap to open or close

    1. Definition

    A cyberattack is a deliberate attempt to steal, damage, disrupt or gain unauthorised access to systems or data. Attacks are grouped by method, such as tricking people, abusing software flaws, or overwhelming services.

    2. Real-world analogy

    Think of different burglars: one picks the lock (exploit), one poses as a delivery driver (social engineering), one blocks the entrance with a crowd so no customer can enter (denial of service), and one copies a key left under the mat (stolen credentials).

    3. How it works, step by step

    AttackHow it worksMain defence
    Phishing / social engineeringDeceives a person into clicking, sharing or payingTraining, email filtering, MFA
    Malware (ransomware, trojan, worm, virus)Malicious software runs on a device; ransomware encrypts data for paymentPatching, endpoint protection, backups
    Password attacksBrute force, password spraying, credential stuffing with leaked passwordsMFA, lockout, unique passwords
    DoS / DDoSFloods a service so real users cannot reach itRate limiting, DDoS protection, redundancy
    Man-in-the-middleIntercepts or alters traffic between two partiesTLS, trusted networks, VPN
    Injection / XSSUntrusted input runs as code in a web appParameterised queries, output encoding
    Supply chainCompromises a trusted vendor or software updateVendor checks, signed updates
    Insider threatMisuse of legitimate accessLeast privilege, monitoring

    A typical attack lifecycle:

    1. Reconnaissance: learn about the target.
    2. Initial access: phishing, stolen login or unpatched flaw.
    3. Execution and persistence: run code and stay in.
    4. Privilege escalation and lateral movement: gain more access.
    5. Action on objectives: steal, encrypt or disrupt.
    6. Cover tracks.

    4. Real-world example

    A staff member gets an email that looks like a shared invoice, enters their password on a fake page, and the attacker signs in. They read mail, find admin credentials, move to the file server and deploy ransomware. One click became a company-wide outage.

    5. How to defend or apply it

    • Defend in layers: awareness, MFA, patching, backups, network segmentation, monitoring.
    • Map events to known techniques using the MITRE ATT&CK knowledge base.
    • Break the lifecycle early: stopping initial access is cheaper than recovery.

    6. In the Google Cybersecurity Certificate

    The programme teaches common attack types, threats, vulnerabilities and incident response, mostly in its early risk and assets-and-threats material, then revisits them in SIEM and incident scenarios. Course titles and ordering can change, so check the official syllabus.

    7. Exam-style questions (tap to reveal)

    Q1. Which attack tries many passwords against many accounts to avoid lockouts?

    Password spraying.

    Q2. What is the aim of a DDoS attack?

    To make a service unavailable by overwhelming it with traffic.

    Q3. Which control best limits the damage of ransomware?

    Tested, offline backups (plus patching and MFA to prevent entry).

    Q4. Which attack inserts untrusted input that a web app runs as code?

    Injection, such as SQL injection or cross-site scripting.

    Q5. Why is phishing so common?

    It targets people instead of technology and is cheap and scalable.

    8. Further learning (5 links)

    YouTube searches

    Part 2: Encryption, hashing and PKI

    Encryption, hashing and PKI: tap to open or close

    1. Definition

    Encryption scrambles data so only someone with the right key can read it, while hashing turns data into a fixed-length fingerprint that cannot be reversed. Public key infrastructure (PKI) is the system of certificates and trusted authorities that proves public keys belong to who they claim.

    2. Real-world analogy

    Encryption is a locked box with a key. A hash is a fingerprint: it identifies the document but you cannot rebuild the document from it. PKI is the passport office: a trusted body vouches that this public key belongs to this website.

    3. How it works, step by step

    IdeaKeysReversible?Use
    Symmetric encryption (e.g. AES)One shared keyYes, with the keyFast bulk data protection
    Asymmetric encryption (e.g. RSA, ECC)Public + private key pairYes, with the private keyKey exchange, signatures
    Hashing (e.g. SHA-256)NoneNoIntegrity checks, password storage

    How HTTPS uses all three:

    1. Your browser connects to a site.
    2. The server sends its certificate, containing its public key.
    3. The browser checks the certificate was signed by a trusted certificate authority (CA), is valid and matches the site name.
    4. Both sides agree a temporary session key using asymmetric methods.
    5. Data is then encrypted with fast symmetric encryption.
    6. Hashes and signatures detect tampering.

    4. Real-world example

    When you open your bank’s website, the padlock means the certificate was trusted and traffic is encrypted. When you download software, you can compare its SHA-256 hash to the publisher’s value to confirm the file was not altered.

    5. How to defend or apply it

    • Use TLS everywhere and keep certificates renewed.
    • Protect private keys; never share or hard-code them.
    • Store passwords as salted hashes using a slow algorithm such as bcrypt, scrypt or Argon2.
    • Avoid outdated algorithms (MD5, SHA-1, DES) and never invent your own cryptography.

    6. In the Google Cybersecurity Certificate

    The programme introduces encryption, hashing, digital signatures and certificates as tools that protect confidentiality and integrity, and ties them to secure communication and password storage. Course titles and ordering can change, so check the official syllabus.

    7. Exam-style questions (tap to reveal)

    Q1. Which is reversible, encryption or hashing?

    Encryption, with the right key. Hashing is one way.

    Q2. What does a certificate authority do?

    It vouches for a public key’s owner by signing certificates browsers trust.

    Q3. Why salt password hashes?

    So identical passwords give different hashes and precomputed attacks fail.

    Q4. Which key decrypts data encrypted with a public key?

    The matching private key.

    Q5. Which goal does a hash check mainly support?

    Integrity.

    8. Further learning (5 links)

    YouTube searches

    Part 3: Zero trust

    Zero trust: tap to open or close

    1. Definition

    Zero trust is a security approach that assumes no user, device or network is trusted by default, even inside the company network. Every request must be verified, and access is limited to what is needed.

    2. Real-world analogy

    A traditional network is a castle: guarded at the gate, relaxed inside. Zero trust is an office building where you scan your badge at every door, and your badge only opens the rooms your job needs.

    3. How it works, step by step

    Core principles: verify explicitly, use least privilege, assume breach.

    1. Identify what to protect: critical data, apps and services.
    2. Map who and what needs access and how traffic flows.
    3. Set policy: who, from which device, to what, under what conditions.
    4. Enforce it with identity checks, MFA, device health and segmentation at each request.
    5. Monitor and log everything, then refine the rules.

    NIST describes this in SP 800-207.

    4. Real-world example

    An employee on café Wi-Fi opens the HR app. The system checks their identity with MFA, confirms the laptop is patched and encrypted, and allows access only to their own records. The same login on an unknown device is blocked, and one stolen password no longer opens everything.

    5. How to defend or apply it

    • Enforce MFA and strong identity management.
    • Check device health before allowing access.
    • Segment the network so a breach cannot spread freely.
    • Apply least privilege and review access regularly.
    • Log and monitor continuously. Adopt step by step, starting with your most sensitive systems.

    6. In the Google Cybersecurity Certificate

    Zero trust ideas appear through least privilege, access control, network security and secure architecture themes, and they underpin how modern organisations limit the damage of stolen credentials. Course titles and ordering can change, so check the official syllabus.

    7. Exam-style questions (tap to reveal)

    Q1. What does ‘assume breach’ mean?

    Design as if an attacker may already be inside, so every access is checked and damage is contained.

    Q2. Is zero trust a single product?

    No. It is a strategy combining identity, devices, network controls and monitoring.

    Q3. Why is network segmentation useful?

    It limits lateral movement after a compromise.

    Q4. Name two signals a zero-trust policy may check.

    User identity (with MFA) and device health; also location or behaviour.

    Q5. How does zero trust relate to least privilege?

    Least privilege is a core principle: users get only the access they need.

    8. Further learning (5 links)

    YouTube searches

    Part 4: Authentication vs authorization

    Authentication vs authorization: tap to open or close

    1. Definition

    Authentication proves who you are, and authorization decides what you are allowed to do once you are known. Both are needed: knowing someone’s identity does not mean they should access everything.

    2. Real-world analogy

    At an airport, the passport check is authentication. Your boarding pass then decides which flight, gate and lounge you can use: that is authorization.

    3. How it works, step by step

    AuthenticationAuthorization
    QuestionWho are you?What may you do?
    HappensFirstAfter authentication
    ExamplesPassword, MFA code, fingerprint, passkeyRoles, permissions, access control lists
    HTTP status when it fails401 (not authenticated)403 (authenticated but not allowed)
    1. Identify: claim an identity (username).
    2. Authenticate: prove it with something you know, have or are. Using two or more is MFA.
    3. Authorize: the system checks your role and permissions.
    4. Access: you perform allowed actions only.
    5. Account/audit: actions are logged.

    4. Real-world example

    A new employee signs in to company email with a password and a phone prompt (authentication). As a regular user they can read their own mailbox but cannot change other people’s mailboxes; the admin role can (authorization). If a regular user could open another person’s mailbox by changing an ID in a URL, that would be broken authorization.

    5. How to defend or apply it

    • Use MFA or passkeys, and avoid reused passwords.
    • Apply role-based access control and least privilege.
    • Check permissions on the server for every request.
    • Review access when people change roles or leave.
    • Log sign-ins and permission changes.

    6. In the Google Cybersecurity Certificate

    The programme covers authentication methods, MFA, access control and the AAA idea (authentication, authorization, accounting) when discussing assets, identity and secure design. Course titles and ordering can change, so check the official syllabus.

    7. Exam-style questions (tap to reveal)

    Q1. Which comes first, authentication or authorization?

    Authentication.

    Q2. Name the three factor types.

    Something you know, something you have, something you are.

    Q3. A user logs in but gets ‘403 Forbidden’. What failed?

    Authorization: they are known but not allowed.

    Q4. What is least privilege?

    Giving only the minimum access needed for a job.

    Q5. Why is MFA valuable?

    A stolen password alone is not enough to sign in.

    8. Further learning (5 links)

    YouTube searches

    Part 5: Risk management basics

    Risk management basics: tap to open or close

    1. Definition

    Risk management is the process of finding what could go wrong, judging how likely and how damaging it is, and deciding what to do about it. It helps organisations spend limited time and money on the problems that matter most.

    2. Real-world analogy

    Think of insuring a home. You check what could happen (fire, flood, theft), estimate how likely and how costly each is, then choose to install smoke alarms, buy insurance, or accept a small risk.

    3. How it works, step by step

    A simple rule: risk = likelihood × impact, driven by assets, threats and vulnerabilities.

    1. Identify assets: data, systems, people.
    2. Identify threats and vulnerabilities.
    3. Assess likelihood and impact (low, medium, high).
    4. Prioritise using a risk register or matrix.
    5. Treat each risk (table below).
    6. Monitor and review as things change; remaining risk is called residual risk.
    TreatmentMeaningExample
    MitigateReduce likelihood or impactEnable MFA
    TransferShare the riskCyber insurance, vendor contract
    AcceptKnowingly live with itLow-value test system
    AvoidStop the risky activityRetire an old unsupported app

    4. Real-world example

    A clinic finds that staff laptops holding patient data are unencrypted (vulnerability), and laptop theft is plausible (threat). Impact is high and likelihood is medium, so the risk is high. The clinic enables disk encryption (mitigate), buys insurance (transfer), and records the small remaining residual risk.

    5. How to defend or apply it

    • Keep an up-to-date asset inventory and risk register.
    • Rank by business impact, not just technical severity.
    • Assign an owner and a due date to every treatment.
    • Use frameworks such as NIST (see the NIST CSF and RMF section) for structure.
    • Re-assess after incidents, changes and new threats.

    6. In the Google Cybersecurity Certificate

    Risk management is a core theme of the programme’s early material: identifying assets, threats and vulnerabilities, assessing risk and applying frameworks and controls. It feeds later work on incident response and reporting. Course titles and ordering can change, so check the official syllabus.

    7. Exam-style questions (tap to reveal)

    Q1. How is risk commonly estimated?

    By combining likelihood and impact.

    Q2. What is residual risk?

    The risk that remains after controls are applied.

    Q3. Name the four risk treatments.

    Mitigate, transfer, accept, avoid.

    Q4. Is a vulnerability the same as a threat?

    No. A vulnerability is a weakness; a threat is something that could exploit it.

    Q5. Why prioritise risks?

    Resources are limited, so effort goes to the highest-impact risks first.

    8. Further learning (5 links)

    YouTube searches

    One-screen revision summary

    • Attacks: phishing, malware, password attacks, DDoS, MITM, injection, supply chain, insiders. Defend in layers.
    • Crypto: symmetric = one key; asymmetric = key pair; hash = one-way fingerprint; PKI = trusted certificates.
    • Zero trust: never trust, always verify; least privilege; assume breach.
    • AuthN = who you are (401). AuthZ = what you can do (403).
    • Risk = likelihood × impact; treat by mitigate, transfer, accept or avoid.

    ← Back to hub

    Educational summary for learners; not affiliated with Google or Coursera. Verify details against official sources. Last reviewed: October 2026.