Look inside the OCR A-Level Computer Science guide (H446)
Guide overview All 16 topics Sample questions Papers and weighting Look inside Questions and answers
Look inside the OCR A-Level Computer Science guide
Questions for a subtopic print together. The answers for that section print after them. Nothing else is in the file.
- Processors: Structure, Performance and Types91
- Input, Output and Storage46
- Systems Software97
- Applications Generation64
- Software Development41
- Types of Programming Language64
- Exchanging Data122
- Networks92
- Web Technologies71
- Data Types and Number Representation152
- Data Structures124
- Boolean Algebra85
- and 4 more
- How should you decide which input device suits a particular problem?
- Which input device suits a supermarket checkout, and why?
- A national testing organisation must mark twenty thousand multiple choice answer sheets. What input device, and what limitation does it have?
- A company wants to turn a filing cabinet of printed letters into searchable text. Which devices and techniques?
- Why is a touchscreen the right input device for a self-service ticket machine at a railway station?
- Which input device would you specify for a professional digital illustrator?
- What input options exist for a user who cannot use their hands?
- Describe suitable output devices for a blind user.
- Which type of printer for which job?
- Match the characteristics of the device to the demands of the problem: how much data must be entered and how quickly, how accurate the entry has to be, the physical environment the device will live in, who the users are and what they can physically do, the cost and durability required, and what form the data is already in. A good justification always names the property of the device and links it to a stated requirement of the problem.
- A barcode scanner. A laser or camera reads the pattern of bars and spaces, which is far quicker than typing a product code and removes typing errors entirely; the code is already printed on the goods so nothing has to be prepared; the scanners are cheap and hard-wearing enough for constant use. The till uses the code to look up the price and update the stock count automatically. A keypad is still needed as a fallback for damaged barcodes and for loose items.
- Optical mark recognition. The reader detects the position of pencil marks in pre-printed boxes on the form, processing thousands of sheets an hour with almost no errors and no operator typing anything. The limitation is that it only works with specially designed forms, marks must be in the right place and made with the right kind of pencil, and it reads only the presence of a mark, not any handwriting.
- A sheet-feed or flatbed scanner to capture each page as an image, followed by optical character recognition software to convert the shapes of the printed characters into character codes. Scanning alone gives only a picture, which cannot be searched or edited; OCR is what makes the text usable. Accuracy depends on the quality of the print, and OCR output has to be checked, unlike optical mark recognition which is essentially exact.
- It combines the display and the input in one sealed unit, so there is no separate keyboard or mouse to be stolen, vandalised or damaged by weather; it tolerates dirt and wet hands; it needs no training, because the user simply touches what they can see; and the controls can be redrawn at every step to show only the choices that are currently relevant. Its weaknesses are that it is slow for entering long text and that an alternative must be offered for users who cannot see or reach the screen.
- A graphics tablet with a pressure-sensitive stylus. Pressure and tilt are captured as well as position, so the software can vary line width and opacity as a real brush would; the absolute positioning and high resolution give far finer control than a mouse, which reports only relative movement. The illustrator draws with a hand movement they already have years of practice in.
- Speech recognition through a microphone, for both dictation and commands, which is fast but needs a quiet environment and reliable speech. Eye-tracking or head-tracking to move a pointer, selecting by dwelling on a target. A single switch operated by any reliable movement, combined with on-screen scanning that highlights each option in turn. The choice depends on which movements the user has available, how much text they need to enter and how noisy or public the setting is.
- A screen reader converting on-screen text to synthesised speech through speakers or headphones, which is quick for reading prose and needs no extra hardware. A refreshable braille display, which raises and lowers pins to form a line of braille cells that the user reads by touch, and which is far better for anything where exact characters matter, such as programming, spelling or numerical data. Many users combine both. Tactile or embossed printouts can be produced for diagrams.
- A laser printer for high volume office documents: it is fast, cheap per page and gives sharp text, using a laser to write a charged image on a drum which picks up toner and fuses it to the paper with heat. An inkjet for occasional colour photographs, since it blends colours well on photo paper and the machine is cheap, though the ink is expensive per page. A 3D printer to make a physical prototype, building the object up in thin layers of deposited material. A large-format plotter for architectural and engineering drawings that must stay accurate at full size.
- What is encryption, and what problem does it solve?
- Describe how symmetric encryption works.
- What is the key distribution problem in symmetric encryption?
- Describe how asymmetric encryption works.
- In asymmetric encryption, which key encrypts and which key decrypts when the goal is confidentiality? Explain why that way round.
- In asymmetric encryption used for authentication or a digital signature, which key signs and which key verifies?
- Alice wants to send Bob a secret message using asymmetric encryption. Whose key does she use, and which one?
- How does asymmetric encryption solve the key distribution problem?
- Compare symmetric and asymmetric encryption on speed and key management.
- Encryption is the process of scrambling plaintext into ciphertext using an algorithm and a key, so that anyone intercepting it cannot understand it. Only someone holding the correct key can decrypt the ciphertext back into readable plaintext. It solves the problem that data sent over a network, or stored on a device that might be stolen, can be read by people it was not intended for; encryption means intercepted data is useless to them.
- In symmetric encryption a single shared key is used both to encrypt the plaintext and to decrypt the ciphertext. The sender and the recipient must both hold that same secret key. The sender encrypts with it, transmits the ciphertext, and the recipient applies the same key to recover the plaintext.
- Both parties need the same secret key before they can communicate securely, but sending that key over the same insecure network risks it being intercepted, and if it is intercepted all the encrypted traffic can be read. Handing it over in person is secure but impractical between strangers or across the internet. The problem worsens with scale, because a group of communicators needs a separate key for every pair, so the number of keys to distribute and protect grows very rapidly.
- Asymmetric encryption uses a mathematically related pair of keys: a public key, which the owner publishes freely to anyone, and a private key, which the owner keeps secret and never shares. Data processed with one key of the pair can only be processed back with the other. Knowing the public key does not let an attacker work out the private key in any practical time.
- The recipient's public key encrypts the message and the recipient's private key decrypts it. It must be that way round because only the recipient holds the private key, so only the recipient can read the message. If the private key encrypted, anyone with the freely published public key could decrypt it and there would be no secrecy at all.
- The sender's private key signs, and the sender's public key verifies. Because only the sender holds the private key, a signature that the sender's public key successfully verifies could only have been produced by that sender, which proves who sent the message. This is the opposite arrangement to confidentiality, where the recipient's public key encrypts and the recipient's private key decrypts.
- She uses Bob's public key to encrypt the message. Bob then decrypts it with his own private key, which he alone possesses. Alice's own keys play no part in keeping the message secret; her private key would only be involved if she also wanted to sign the message to prove it came from her.
- The only key that has to be distributed is the public key, and it does not matter who sees it, so it can be published openly or sent over an insecure network without risk. The private key is generated on the owner's own machine and never travels anywhere. Two parties who have never met and share no prior secret can therefore communicate securely, and each participant needs only one key pair rather than a separate shared key for every other participant.
- Symmetric encryption uses simpler operations and is much faster, so it is well suited to encrypting large volumes of data, but it suffers from the key distribution problem and from needing a great many keys when many parties communicate. Asymmetric encryption is far slower and computationally heavier for the same amount of data, but it removes the need to share any secret in advance, needs only one key pair per participant, and additionally supports digital signatures, which symmetric encryption cannot provide.
- The Data Protection Act 1998 gets quoted in exam answers as though it protects computers. What does it actually protect, and who does it place the duty on?
- State the eight data protection principles set out in the Data Protection Act 1998.
- Distinguish between a data subject, a data controller and a data processor, and give an example of each in a single scenario.
- What is a subject access request, and what could a person get from one under the 1998 Act?
- The 1998 Act treated some categories of information as needing extra protection. Which categories, and why does that classification matter for a system designer?
- Why could a police force keep a database of suspects without letting each suspect see their entry, if the Act gave a right of access?
- A gym employee leaves an unencrypted laptop on a train. It holds ten thousand members' names, addresses, card details and the health questionnaires they filled in on joining. Which parts of the Data Protection Act 1998 are engaged?
- An online retailer collects email addresses solely to send order confirmations, then sells the whole list to an advertising broker. Explain, without naming penalties, which data protection principles this breaches.
- Who enforced the Data Protection Act 1998, and what could they do about a breach?
- It protects people, not machines, and not data in general. Its subject matter is personal data: data relating to a living individual who can be identified either from that data alone, or from that data together with other information that the data controller holds or is likely to hold. The person the data is about is the data subject. The duty falls on the data controller, the person or organisation that decides why and how the data is processed, and on any data processor acting on the controller's instructions. Data about a dead person, or about a company rather than an individual, falls outside it, as does data that has been genuinely anonymised so no individual can be identified. Important point of fact: the 1998 Act is the legislation you should write about in the exam, but it is no longer the law. It was repealed on 25 May 2018 and replaced by the Data Protection Act 2018 working alongside the UK General Data Protection Regulation.
- Personal data must be: (1) processed fairly and lawfully, and only where a stated condition for processing is met; (2) obtained for one or more specified and lawful purposes, and not further processed in a way incompatible with those purposes; (3) adequate, relevant and not excessive for those purposes; (4) accurate and, where necessary, kept up to date; (5) not kept for longer than is necessary for the purpose; (6) processed in accordance with the rights of data subjects under the Act; (7) protected by appropriate technical and organisational measures against unauthorised or unlawful processing and against accidental loss, destruction or damage; (8) not transferred outside the European Economic Area unless the destination country ensures an adequate level of protection for the rights of data subjects. The 2018 replacement regime keeps very similar principles but merges them into six and adds an explicit accountability principle requiring the controller to be able to demonstrate compliance.
- The data subject is the living individual the personal data is about. The data controller is the person or organisation that determines the purposes for which and the manner in which the data is processed, and it is the controller who carries the legal responsibility. The data processor processes the data on the controller's behalf and on its instructions, without deciding the purpose. In one scenario: a secondary school stores pupil records. Each pupil is a data subject. The school is the data controller, because it decides what to record and why. The cloud provider hosting the management information system is a data processor, because it stores and backs up the data but has no say in what is collected or what it is used for. If the school decides to sell the records to a revision company, that decision is the controller's and the liability is the school's.
- A subject access request is a request made by a data subject to a data controller for the personal data the controller holds about them. Under the 1998 Act the controller had to be told in writing, could charge a small fee (generally up to ten pounds, capped lower at two pounds for a credit reference file and higher at up to fifty pounds for health and education records), and had to respond within forty days. The subject was entitled to be told whether their data was being processed, to be given a description of the data, the purposes of processing and who it might be disclosed to, to receive a copy of the information in intelligible form, and to be told any information available about the source of the data. Certain material could be withheld, for example where disclosing it would also reveal information about another identifiable person who had not consented. Under the current 2018 regime the request need not be in writing, the fee has gone in ordinary cases, and the deadline is one month.
- The Act called these sensitive personal data: racial or ethnic origin; political opinions; religious beliefs or other beliefs of a similar nature; trade union membership; physical or mental health or condition; sexual life; the commission or alleged commission of any offence; and any proceedings for an offence, their disposal or the sentence. Processing these lawfully required an additional condition to be satisfied on top of the ordinary conditions, typically explicit consent or a specific statutory ground such as medical purposes or equal-opportunity monitoring. It matters to a designer because it changes the engineering: these fields normally warrant stricter access control, separate storage or encryption, tighter audit logging, shorter retention, and an explicit consent-capture step in the interface rather than a pre-ticked box. The current regime keeps the idea under the label special category data and adds biometric and genetic data used for identification.
- Because the Act contained exemptions that switched off some of its provisions in defined circumstances. The most relevant here is the crime and taxation exemption, which disapplied the subject access right and the first principle where compliance would be likely to prejudice the prevention or detection of crime, the apprehension or prosecution of offenders, or the assessment or collection of tax. Other exemptions covered national security, journalism, literature and art, regulatory activity, and processing purely for domestic or recreational purposes by an individual. An exemption is narrow and conditional: it applies only so far as compliance would actually cause the prejudice in question, so a force cannot refuse every request as a matter of blanket policy. The same structure of exemptions survives in the 2018 Act.
- Principally the seventh principle, which required appropriate technical and organisational measures against accidental loss and unauthorised processing. Full-disk encryption, a policy against holding the whole membership file locally, and staff training are exactly the measures expected, and the absence of them is the breach; the theft or loss itself is not what the law punishes. The health questionnaires make this worse, because health data was sensitive personal data attracting a higher standard of care. The third principle is also in play if the whole database was on the laptop when the employee only needed a subset, and the fifth if the file included ex-members retained with no continuing purpose. The Information Commissioner could serve an enforcement notice or a monetary penalty; under the 1998 Act penalties were capped at five hundred thousand pounds, whereas the current regime allows far larger fines and requires most breaches to be reported to the Commissioner within seventy-two hours.
- The second principle, because the data was obtained for the specified purpose of fulfilling orders and selling it for advertising is further processing incompatible with that purpose. The first principle, because processing was not fair: customers were not told at the point of collection that their addresses would be sold, so they could not have anticipated it, and no valid condition for the new processing was met. The sixth principle is engaged too, because data subjects had a right to prevent processing for direct marketing and were given no opportunity to exercise it. If the broker is outside the European Economic Area in a country without adequate protection, the eighth principle is breached as well. Note that the breach lies in the mismatch between the stated purpose and the actual use, not in the sale of data as such, which could have been lawful had it been disclosed and consented to.
- The Information Commissioner, heading the Information Commissioner's Office, an independent regulator reporting to Parliament. Controllers processing personal data generally had to notify, that is register, with the Commissioner, and processing without notifying was itself a criminal offence. On a breach the Commissioner could carry out an assessment at a data subject's request, issue an information notice compelling the controller to supply information, serve an enforcement notice requiring specified steps or requiring processing to stop, and from 2010 impose a monetary penalty of up to five hundred thousand pounds for a serious breach likely to cause substantial damage or distress. Separately, data subjects could sue the controller in the courts for compensation and could apply for an order to have inaccurate data rectified, blocked, erased or destroyed.
questions
Scroll sideways to turn through the pages.
How the guide is worked
Answering a question from memory stores it far better than reading the answer again. The guide runs that as a fixed procedure on one subtopic at a time, about twenty minutes a session.
-
Step 1 · Closed book
Cover the answers. Work through one subtopic and write down what you can. Leave blanks where you have nothing.
-
Step 2 · Open book
Go back to the top. Read each printed answer and write it out in full, including the ones you had right.
-
Step 3 · Closed book again
Same questions, same order, from memory. The gap between pass one and pass three is the session result.
Read the full method, the return schedule and the research behind it.
OCR A-Level Computer Science Active Recall Guide
Every question paired with its answer, ready to work in three passes.