A network connects devices so they can exchange data and share services. Follow one message through the system to understand which protocol, address and device does each job.
Content owner: Michael Print · Written for A-Level learners · Checked against official specifications
The idea to start with
Protocols define rules for communication, including message formats, addressing and expected responses. Standards permit independently built devices/software to interoperate. Layering separates responsibilities and allows one implementation to change while preserving an agreed interface.
DNS resolves a domain name to appropriate records such as IP addresses. TCP provides reliable ordered byte-stream transport; IP routes packets between networks; link technologies such as Ethernet or Wi-Fi deliver frames on a local link.
Security needs several controls because no single firewall or encrypted channel prevents every threat.
OCR H446 · 1.3.3(a–e)
Before you start
Useful foundations
Data as bits and packets
Client applications and server services
By the end, you should be able to
Explain standards, layering and the four-layer TCP/IP model
Describe DNS and LAN/WAN connections
Compare packet/circuit switching and network models
Identify hardware functions and contextual security controls
Network characteristics, LANs and WANs
Networks support shared files, printers, collaboration and centrally managed services. Benefits depend on availability, bandwidth, latency, maintenance and security. Bandwidth is a capacity/rate; latency is delay before data arrives. A high-capacity distant link can still have inconvenient latency for interactive requests.
A local area network (LAN) covers a limited site and is commonly managed by one organisation. A wide area network (WAN) connects geographically separated networks, often through provider infrastructure. The internet is an interconnection of many networks, not one central machine.
A router connecting a school's LAN to its provider forwards traffic beyond the local subnet; internal traffic need not travel through the public internet.
Use the four-layer TCP/IP model
We use four layers: application, transport, internet and link/network access. Other teaching models split the link/physical responsibilities into more layers; keep the named model consistent. Application protocols express the service, such as HTTP for web messages and DNS for name queries.
Transport identifies communicating application endpoints using ports and supplies transport behaviour.
TCP numbers bytes, acknowledges receipt, detects/retransmits loss and presents an ordered reliable stream. IP supplies addressing/routing between networks, without guaranteeing reliable ordered delivery itself. Link protocols frame data for a local link.
Encapsulation adds relevant headers as data moves down the stack, then the receiving side processes them in reverse. A router generally forwards using IP addressing; a LAN switch generally forwards using link-layer MAC addressing.
Responsibilities in the four-layer model
Layer
Example
Main job
Application
HTTP, DNS
Service requests and responses
Transport
TCP, UDP
Application endpoints and transport behaviour
Internet
IP
Addressing/routing between networks
Link/network access
Ethernet, Wi-Fi
Local-link framing/transmission
DNS and routing are separate tasks
A resolver can answer from an unexpired cached record. On a cache miss, it can query the DNS hierarchy. Caching reduces repeated work, but changed records may not reach every user immediately.
After finding an address, the application can contact the destination. DNS has not sent the requested web page and has not computed a packet route. Routers use forwarding/routing information to choose next hops.
A destination IP identifies a network endpoint; a destination port distinguishes a service/process endpoint on that host. The domain name, IP address and MAC address perform different jobs.
A DNS cache miss: find the address first
1
Root server
Direct the resolver towards the relevant top-level-domain servers.
2
Top-level-domain server
Direct it towards an authoritative server for the domain.
3
Authoritative answer
Return the requested records. A/AAAA records contain IPv4/IPv6 addresses.
4
Application connection
Use the resulting address to contact the destination. DNS has not delivered the web page or computed the packet route.
Packet and circuit switching
Packet switching divides data into addressed packets that share network capacity. Routers forward each packet; congestion can create queueing/loss and packets may follow different routes. Higher-layer mechanisms can reconstruct the intended data. Shared capacity suits bursty traffic, but delays can vary and headers impose overhead.
Circuit switching establishes a path with reserved resources for the communication session. This can offer predictable capacity once established, but setup takes time and reserved capacity can remain unused during silence.
Compare resource reservation and usage patterns rather than saying packet switching is always faster or circuit switching is immune to failure.
Hardware has distinct roles
A network interface controller (NIC) connects a device to a network and implements link-level functions. A switch connects devices within a LAN and learns MAC-to-port mappings to forward frames. A router connects networks and forwards IP packets toward their destinations.
A wireless access point connects wireless devices to a network; a modem handles the signalling/modulation required by a particular access link. A consumer box may combine several roles.
A hub repeats signals to its other ports rather than learning destinations, making unnecessary sharing of traffic/capacity more likely. Physical media also matter: copper, fibre and radio have different range, interference, installation and mobility constraints.
Pick the characteristic connected to the scenario, rather than treating wireless as automatically slower regardless of equipment.
Client-server and peer-to-peer
In client-server systems, a server provides a service requested by clients, enabling centralised permissions, backups and consistent records. A failure/overload can affect many clients unless redundancy is provided; administration and infrastructure cost resources.
The server can be dedicated or a process on a machine with other roles.
In peer-to-peer systems, peers can both request and provide resources, distributing work and reducing dependence on one dedicated server. Resource availability and administration depend on participating peers, and consistent access controls/backups can be harder.
Peer-to-peer does not mean there are no protocols or that every system lacks any central discovery service.
Threats and layered controls
Threats include unauthorised access, interception, malware, spoofing/phishing and denial of service. A firewall filters traffic according to rules such as source/destination, ports and connection state; permitted malicious traffic can still pass.
A proxy acts as an intermediary and may filter requests, cache content or mediate access. Neither makes a compromised endpoint safe.
Encryption protects confidentiality of transmitted data; authenticated secure protocols also help detect tampering and establish who is communicating. HTTPS normally protects the browser-to-server connection through TLS. Encryption does not stop a user giving credentials to a fraudulent site or malware reading plaintext at an endpoint.
Authentication, least-privilege permissions, updates, backups, segmentation and monitoring address different risks. Tie each control to a threat and mention a relevant limitation.
Worked example
Follow an HTTPS request from a classroom
The browser needs an address for the requested host. Assume the DNS cache has no answer, so the configured resolver obtains and caches the authoritative record.
For this example the browser uses HTTP over TLS over TCP, as with a common HTTP/1.1 or HTTP/2 connection. HTTP/3 uses QUIC/UDP, so TCP is an example rather than a claim about every web connection.
The device sends local frames through its NIC/access point or switch. For a destination outside the LAN, the router forwards IP packets toward the provider and subsequent networks.
TCP handles reliable ordered delivery; TLS protects/authenticates the channel; the application processes the HTTP request and returns content. DNS supplied the address, the router forwarded packets and the server supplied the page: three different tasks.
Worked example
A secure school file service
Use client-server file sharing for consistent permissions and centrally maintained backups. Students authenticate; group permissions restrict each folder.
A firewall restricts unnecessary network services; a filtering proxy can control selected outbound web requests. Encrypted connections protect data in transit, while device updates and endpoint protection address malicious software.
An offline/versioned backup and tested restoration reduce damage from deletion/ransomware. Additional availability measures can protect a central service, but do not justify exposing every folder to every client.
Original A-Level practice
6 original questions total 21 marks. Attempt each before opening the independently written indicative marking guidance.
Question 1
4 marks
Name the four TCP/IP layers used here and give one responsibility for each.
1 mark: transport handles application endpoints/transport behaviour.
1 mark: internet handles IP addressing/routing.
1 mark: link/network access handles local framing/transmission.
Question 2
4 marks
Explain a DNS cache miss and why changing a domain's address may not have an immediate effect for every user.
Show solution and marking guidance+
Indicative answer
1 mark: the resolver seeks a record rather than serving a valid cached answer.
1 mark: hierarchy/referrals lead toward an authoritative source.
1 mark: the resulting record supplies an address for later application communication.
1 mark: other resolvers may retain unexpired cached records until their time to live expires.
Question 3
4 marks
Compare packet and circuit switching for traffic that is silent much of the time but occasionally sends large bursts.
Show solution and marking guidance+
Indicative answer
1 mark: packet switching shares capacity between communications.
1 mark: this avoids reserving an idle circuit throughout the silent periods.
1 mark: circuit switching reserves resources after setup and can offer predictable capacity.
1 mark: packet queues/congestion create variable delay, so choose according to tolerance for that delay and resource efficiency.
Question 4
3 marks
Distinguish a switch, router and wireless access point.
Show solution and marking guidance+
Indicative answer
1 mark: a switch forwards local frames using destination MAC information.
1 mark: a router forwards IP packets between networks.
1 mark: an access point connects wireless devices to the network. A physical appliance can combine roles.
Question 5
4 marks
A manager says a firewall makes the network fully safe. Evaluate the claim with two further controls.
Show solution and marking guidance+
Indicative answer
1 mark: firewall filtering restricts selected traffic but cannot guarantee permitted content/endpoints are safe.
1 mark: authenticated encryption helps protect confidential traffic from interception/tampering.
1 mark: updates/endpoint protection, authentication or least-privilege permissions address an additional specific risk.
1 mark: connect limitations, for example encryption cannot prevent phishing or an infected authenticated device. Accept alternative justified controls.
Question 6
2 marks
Give a reason to choose client-server for a shared records system and a peer-to-peer drawback in that context.
Show solution and marking guidance+
Indicative answer
1 mark: central control supports consistent records, permissions or backups.
1 mark: distributing records across peers can complicate consistent updates, availability or managed access.
Specification and references
This guide addresses OCR H446 1.3.3(a–e). Check your examination year and the complete specification for the assessment scope.
These are independently written explanations and practice questions. CompSciTutoring.co.uk is not affiliated with or endorsed by an examination board. The marking guidance is indicative; always check the syllabus for your examination year.