Google Cybersecurity Certificate, Course 5: Assets, Threats, and Vulnerabilities (Study Notes)

    Plain-English notes on asset classification, CVE and CVSS, vulnerability scanning, cryptography, authentication and authorization, and common attack types. Includes practice questions with explanations.

    Independent study aid. Not affiliated with or endorsed by Google or Coursera. All explanations and questions are original. Confirm current course content on the official Coursera page.

    1. Course overview

    You cannot protect what you do not know you have. This course starts with finding and classifying assets, then looks at the weaknesses and attacks that put them at risk, and the safeguards that help: finding vulnerabilities early, encrypting data, and controlling who can sign in and what they can do.

    Core idea

    Know your assets, find the weak spots, fix the most dangerous first.

    Builds on

    Linux and SQL skills from Course 4.

    Study tip

    Make a personal asset list (phone, email, bank app) and note the weakest protection on each.

    2. Weekly breakdown (study plan)

    A suggested four-part plan grouped by topic. Follow the official course order for graded work, as week titles may differ.

    Part 1: Asset management and classification
    • An asset is anything valuable: data, devices, software, people, reputation.
    • An asset inventory is a list of what you own, where it is and who is responsible. Missing items are blind spots.
    • Classification labels assets by sensitivity so the right protection is applied.
    LevelMeaningExample
    RestrictedHighest sensitivity, serious harm if exposedCustomer payment data, encryption keys
    ConfidentialSensitive, limited audienceContracts, employee records
    Internal-onlyFor staff, low harm if leakedInternal memos, org charts
    PublicMeant to be sharedPress releases, website text

    Labels vary between organisations. The idea is more sensitive means stricter controls. Also remember data states: at rest, in transit, in use.

    Part 2: Vulnerabilities, CVE, CVSS and scanning
    • A vulnerability is a weakness; an exploit is what takes advantage of it. A zero-day is unknown to the vendor, so no patch exists yet.
    • CVE gives each publicly known flaw an ID such as CVE-2024-12345. See cve.org and NVD.
    • CVSS scores severity from 0 to 10 so teams can compare and prioritise.
    CVSS scoreRating
    0.0None
    0.1 to 3.9Low
    4.0 to 6.9Medium
    7.0 to 8.9High
    9.0 to 10.0Critical
    • Vulnerability scanning uses tools to find known weaknesses automatically and regularly. Penetration testing is an authorised, manual attempt to exploit them and shows real impact.
    • The vulnerability management cycle: find, prioritise, fix, verify, repeat. The OWASP Top 10 lists the biggest web application risks.
    Part 3: Cryptography
    • Encryption scrambles data so only someone with the right key can read it. Symmetric uses one shared key (fast, e.g. AES). Asymmetric uses a public and private key pair (e.g. RSA), which solves the “how do we share the key” problem.
    • Hashing turns data into a fixed-length fingerprint that cannot be reversed. Used for integrity checks and password storage. Weak, old algorithms such as MD5 should not be used for security.
    • Salting adds random data before hashing so identical passwords give different hashes and precomputed tables fail.
    • Digital signatures prove who sent something and that it was not altered. PKI and certificates let you trust a public key. TLS uses these to protect HTTPS.
    • Rule of thumb: never invent your own cryptography; use well-reviewed standards.
    Part 4: Authentication, authorization and attack types
    • Authentication proves who you are using something you know (password), have (phone, token) or are (fingerprint). MFA combines two or more types. SSO lets one login open many apps.
    • Authorization decides what you may do once identified. RBAC gives permissions by job role; least privilege keeps them minimal. AAA adds accounting, which records what was done.
    AttackHow it worksDefence
    Phishing / social engineeringTricks people into sharing data or clickingTraining, filtering, MFA
    Malware / ransomwareHarmful software runs on a devicePatching, EDR, backups
    Password attacksBrute force, credential stuffing, dictionary guessesLong passwords, MFA, lockouts, salted hashes
    SQL injectionMalicious database commands in inputParameterised queries, input validation
    Cross-site scripting (XSS)Script injected into a page other users viewOutput encoding, content security policy
    Supply chainCompromising a trusted vendor or software updateVendor review, signed updates, monitoring

    3. 15 must-know terms

    TermPlain meaning
    Asset inventoryList of what the organisation owns
    Data classificationLabelling data by sensitivity
    VulnerabilityWeakness that can be exploited
    ExploitMethod that uses a vulnerability
    Zero-dayFlaw with no vendor fix yet
    CVEPublic ID for a known flaw
    CVSS0 to 10 severity score
    Vulnerability scanAutomated search for known weaknesses
    Penetration testAuthorised simulated attack
    EncryptionMaking data unreadable without a key
    HashOne-way fingerprint of data
    SaltRandom addition that strengthens hashing
    MFATwo or more proofs of identity
    RBACPermissions assigned by role
    SQL injectionDatabase commands smuggled through input

    4. Three worked examples

    Example 1: Classify assets

    Scenario: A clinic holds (a) patient records, (b) a staff holiday calendar, (c) its public opening hours.

    Answer: (a) restricted, because exposure would harm patients and breach privacy law; (b) internal-only; (c) public. Apply encryption and tight access to (a), and ordinary staff access to (b).

    Example 2: Prioritise vulnerabilities

    Scenario: Scan results show (1) a Critical flaw (9.8) on an isolated test machine with no data, and (2) a High flaw (7.5) on the public web server that stores customer data.

    Reasoning: CVSS is a starting point; context matters. The public server is reachable by attackers and holds valuable data. Answer: fix (2) first or at least in parallel, then (1). Record the reasoning for the audit trail.

    Example 3: Pick the right cryptography

    Scenario: Store user passwords, protect a large backup file, and verify a downloaded installer is unmodified.

    Answer: passwords: salted hash with a modern password-hashing method (never reversible encryption). Backup: symmetric encryption such as AES, with the key stored separately. Installer: compare its hash or digital signature with the publisher’s official value.

    5. Common mistakes

    • Skipping the inventory. Unknown assets are never patched or monitored.
    • Treating CVSS as the whole story. Severity needs context: exposure, data value and available fixes.
    • Confusing encryption and hashing. Encryption is reversible with a key; hashing is one-way.
    • Mixing up authentication and authorization. First prove who you are; then the system decides what you may do.
    • Thinking a scan equals a pen test. Scans list possible weaknesses; pen tests try to exploit them.
    • Relying on one control. MFA is strong but does not fix an unpatched server; use layers.

    6. 10 practice questions (tap to reveal)

    Q1. Why classify data before choosing protections?

    So effort and cost match sensitivity: strong controls for restricted data, lighter ones for public information.

    Q2. What is the difference between a CVE and CVSS?

    A CVE is the identifier for a specific known flaw; CVSS is the score that rates how severe it is.

    Q3. A flaw scores 9.1 on CVSS. What rating is that?

    Critical (9.0 to 10.0).

    Q4. What is a zero-day vulnerability?

    A flaw the vendor does not yet know about or has not fixed, so no patch exists and defenders must rely on mitigations and monitoring.

    Q5. How does vulnerability scanning differ from penetration testing?

    Scanning is automated and broad, finding known weaknesses. Penetration testing is a deliberate, authorised attempt to exploit them, showing real impact.

    Q6. When would you choose asymmetric over symmetric encryption?

    When two parties have not shared a secret key beforehand, such as setting up a secure web connection. Symmetric is then used for bulk data because it is faster.

    Q7. Why salt passwords before hashing?

    Salting makes identical passwords produce different hashes and defeats precomputed rainbow tables.

    Q8. Which factor type is a fingerprint?

    Something you are (inherence). A password is something you know; a phone code is something you have.

    Q9. A new employee can read the finance folder though their job does not need it. Which principle is broken?

    Least privilege. Role-based access control would assign only the access their role requires.

    Q10. How can developers reduce the risk of SQL injection?

    Use parameterised queries, validate and sanitise input, and give the application a database account with minimal rights.

    7. YouTube search links

    8. One-screen revision summary

    • Assets: inventory first; classify as restricted, confidential, internal-only, public.
    • Vulnerabilities: CVE = ID, CVSS = severity (0 to 10); zero-day = no patch yet.
    • Testing: scan (automated, broad) vs pen test (authorised exploitation).
    • Prioritise by score plus exposure plus data value.
    • Crypto: symmetric (one key, fast), asymmetric (key pair), hash (one-way), salt, signature, TLS.
    • AuthN: know, have, are; MFA; SSO. AuthZ: RBAC, least privilege. AAA adds accounting.
    • Attacks: phishing, malware, password attacks, SQL injection, XSS, supply chain.
    • Mindset: layers of defence, not a single fix.

    9. What you should be able to do

    ← Back to hub

    Educational summary for learners; not affiliated with Google or Coursera. Verify details against official course materials. Last reviewed: October 2026.