Google Cybersecurity Certificate, Course 5: Assets, Threats, and Vulnerabilities (Study Notes)
Plain-English notes on asset classification, CVE and CVSS, vulnerability scanning, cryptography, authentication and authorization, and common attack types. Includes practice questions with explanations.
Independent study aid. Not affiliated with or endorsed by Google or Coursera. All explanations and questions are original. Confirm current course content on the official Coursera page.
1. Course overview
You cannot protect what you do not know you have. This course starts with finding and classifying assets, then looks at the weaknesses and attacks that put them at risk, and the safeguards that help: finding vulnerabilities early, encrypting data, and controlling who can sign in and what they can do.
Core idea
Know your assets, find the weak spots, fix the most dangerous first.
Builds on
Linux and SQL skills from Course 4.
Study tip
Make a personal asset list (phone, email, bank app) and note the weakest protection on each.
2. Weekly breakdown (study plan)
A suggested four-part plan grouped by topic. Follow the official course order for graded work, as week titles may differ.
Part 1: Asset management and classification
- An asset is anything valuable: data, devices, software, people, reputation.
- An asset inventory is a list of what you own, where it is and who is responsible. Missing items are blind spots.
- Classification labels assets by sensitivity so the right protection is applied.
| Level | Meaning | Example |
|---|---|---|
| Restricted | Highest sensitivity, serious harm if exposed | Customer payment data, encryption keys |
| Confidential | Sensitive, limited audience | Contracts, employee records |
| Internal-only | For staff, low harm if leaked | Internal memos, org charts |
| Public | Meant to be shared | Press releases, website text |
Labels vary between organisations. The idea is more sensitive means stricter controls. Also remember data states: at rest, in transit, in use.
Part 2: Vulnerabilities, CVE, CVSS and scanning
- A vulnerability is a weakness; an exploit is what takes advantage of it. A zero-day is unknown to the vendor, so no patch exists yet.
- CVE gives each publicly known flaw an ID such as CVE-2024-12345. See cve.org and NVD.
- CVSS scores severity from 0 to 10 so teams can compare and prioritise.
| CVSS score | Rating |
|---|---|
| 0.0 | None |
| 0.1 to 3.9 | Low |
| 4.0 to 6.9 | Medium |
| 7.0 to 8.9 | High |
| 9.0 to 10.0 | Critical |
- Vulnerability scanning uses tools to find known weaknesses automatically and regularly. Penetration testing is an authorised, manual attempt to exploit them and shows real impact.
- The vulnerability management cycle: find, prioritise, fix, verify, repeat. The OWASP Top 10 lists the biggest web application risks.
Part 3: Cryptography
- Encryption scrambles data so only someone with the right key can read it. Symmetric uses one shared key (fast, e.g. AES). Asymmetric uses a public and private key pair (e.g. RSA), which solves the “how do we share the key” problem.
- Hashing turns data into a fixed-length fingerprint that cannot be reversed. Used for integrity checks and password storage. Weak, old algorithms such as MD5 should not be used for security.
- Salting adds random data before hashing so identical passwords give different hashes and precomputed tables fail.
- Digital signatures prove who sent something and that it was not altered. PKI and certificates let you trust a public key. TLS uses these to protect HTTPS.
- Rule of thumb: never invent your own cryptography; use well-reviewed standards.
Part 4: Authentication, authorization and attack types
- Authentication proves who you are using something you know (password), have (phone, token) or are (fingerprint). MFA combines two or more types. SSO lets one login open many apps.
- Authorization decides what you may do once identified. RBAC gives permissions by job role; least privilege keeps them minimal. AAA adds accounting, which records what was done.
| Attack | How it works | Defence |
|---|---|---|
| Phishing / social engineering | Tricks people into sharing data or clicking | Training, filtering, MFA |
| Malware / ransomware | Harmful software runs on a device | Patching, EDR, backups |
| Password attacks | Brute force, credential stuffing, dictionary guesses | Long passwords, MFA, lockouts, salted hashes |
| SQL injection | Malicious database commands in input | Parameterised queries, input validation |
| Cross-site scripting (XSS) | Script injected into a page other users view | Output encoding, content security policy |
| Supply chain | Compromising a trusted vendor or software update | Vendor review, signed updates, monitoring |
3. 15 must-know terms
| Term | Plain meaning |
|---|---|
| Asset inventory | List of what the organisation owns |
| Data classification | Labelling data by sensitivity |
| Vulnerability | Weakness that can be exploited |
| Exploit | Method that uses a vulnerability |
| Zero-day | Flaw with no vendor fix yet |
| CVE | Public ID for a known flaw |
| CVSS | 0 to 10 severity score |
| Vulnerability scan | Automated search for known weaknesses |
| Penetration test | Authorised simulated attack |
| Encryption | Making data unreadable without a key |
| Hash | One-way fingerprint of data |
| Salt | Random addition that strengthens hashing |
| MFA | Two or more proofs of identity |
| RBAC | Permissions assigned by role |
| SQL injection | Database commands smuggled through input |
4. Three worked examples
Example 1: Classify assets
Scenario: A clinic holds (a) patient records, (b) a staff holiday calendar, (c) its public opening hours.
Answer: (a) restricted, because exposure would harm patients and breach privacy law; (b) internal-only; (c) public. Apply encryption and tight access to (a), and ordinary staff access to (b).
Example 2: Prioritise vulnerabilities
Scenario: Scan results show (1) a Critical flaw (9.8) on an isolated test machine with no data, and (2) a High flaw (7.5) on the public web server that stores customer data.
Reasoning: CVSS is a starting point; context matters. The public server is reachable by attackers and holds valuable data. Answer: fix (2) first or at least in parallel, then (1). Record the reasoning for the audit trail.
Example 3: Pick the right cryptography
Scenario: Store user passwords, protect a large backup file, and verify a downloaded installer is unmodified.
Answer: passwords: salted hash with a modern password-hashing method (never reversible encryption). Backup: symmetric encryption such as AES, with the key stored separately. Installer: compare its hash or digital signature with the publisher’s official value.
5. Common mistakes
- Skipping the inventory. Unknown assets are never patched or monitored.
- Treating CVSS as the whole story. Severity needs context: exposure, data value and available fixes.
- Confusing encryption and hashing. Encryption is reversible with a key; hashing is one-way.
- Mixing up authentication and authorization. First prove who you are; then the system decides what you may do.
- Thinking a scan equals a pen test. Scans list possible weaknesses; pen tests try to exploit them.
- Relying on one control. MFA is strong but does not fix an unpatched server; use layers.
6. 10 practice questions (tap to reveal)
Q1. Why classify data before choosing protections?
So effort and cost match sensitivity: strong controls for restricted data, lighter ones for public information.
Q2. What is the difference between a CVE and CVSS?
A CVE is the identifier for a specific known flaw; CVSS is the score that rates how severe it is.
Q3. A flaw scores 9.1 on CVSS. What rating is that?
Critical (9.0 to 10.0).
Q4. What is a zero-day vulnerability?
A flaw the vendor does not yet know about or has not fixed, so no patch exists and defenders must rely on mitigations and monitoring.
Q5. How does vulnerability scanning differ from penetration testing?
Scanning is automated and broad, finding known weaknesses. Penetration testing is a deliberate, authorised attempt to exploit them, showing real impact.
Q6. When would you choose asymmetric over symmetric encryption?
When two parties have not shared a secret key beforehand, such as setting up a secure web connection. Symmetric is then used for bulk data because it is faster.
Q7. Why salt passwords before hashing?
Salting makes identical passwords produce different hashes and defeats precomputed rainbow tables.
Q8. Which factor type is a fingerprint?
Something you are (inherence). A password is something you know; a phone code is something you have.
Q9. A new employee can read the finance folder though their job does not need it. Which principle is broken?
Least privilege. Role-based access control would assign only the access their role requires.
Q10. How can developers reduce the risk of SQL injection?
Use parameterised queries, validate and sanitise input, and give the application a database account with minimal rights.
7. YouTube search links
- Asset management and data classification
- CVE and CVSS explained
- Vulnerability scanning vs penetration testing
- Encryption and hashing explained
- Authentication, authorization and MFA
8. One-screen revision summary
- Assets: inventory first; classify as restricted, confidential, internal-only, public.
- Vulnerabilities: CVE = ID, CVSS = severity (0 to 10); zero-day = no patch yet.
- Testing: scan (automated, broad) vs pen test (authorised exploitation).
- Prioritise by score plus exposure plus data value.
- Crypto: symmetric (one key, fast), asymmetric (key pair), hash (one-way), salt, signature, TLS.
- AuthN: know, have, are; MFA; SSO. AuthZ: RBAC, least privilege. AAA adds accounting.
- Attacks: phishing, malware, password attacks, SQL injection, XSS, supply chain.
- Mindset: layers of defence, not a single fix.
9. What you should be able to do
Related pages
Educational summary for learners; not affiliated with Google or Coursera. Verify details against official course materials. Last reviewed: October 2026.
