CSC334 · TU past paper
Society and Ethics in Information Technology 2079 question paper
The complete TU 2079 exam paper for Society and Ethics in Information Technology (CSC334), all 12 questions with solved model answers written to the mark scheme.
Tap a question to open its answer.
- 110 marksRole of Media and Communication in Social HideAnswer
Explain the role of media and communication in social and cultural changes. What are the reason for resisting social change?[10]
--- Media and communication are among the most powerful agents of social and cultural change in modern society. They transmit ideas, values, and information across vast populations, influencing how people think, behave, and relate to one...
- 210 marksCyberspace and EthicsHideAnswer
Explain cyberspace in brief. Explain different techniques that can be used to secure cyberspace users.[10]
Cyberspace and Techniques to Secure Cyberspace Users
Part 1: Cyberspace (Brief Explanation)
Cyberspace is a virtual, interconnected digital environment created by the global network of computers, servers, routers, and communication infrastructure (primarily the Internet). The term was coined by William Gibson in his 1984 novel Neuromancer.
Cyberspace encompasses:
- The Internet and World Wide Web
- Online communication platforms (email, social media, messaging)
- Digital data storage and processing systems
- Virtual environments and online communities
Key characteristics of cyberspace:
- Borderless - transcends geographical boundaries
- Anonymous - users can operate with hidden identities
- Dynamic - constantly evolving with new technologies
- Interconnected - billions of devices linked together
- Vulnerable - susceptible to attacks, fraud, and misuse
Because of its open and anonymous nature, cyberspace presents significant security challenges including hacking, identity theft, phishing, malware, and cybercrime.
Part 2: Techniques to Secure Cyberspace Users
1. Firewalls
A firewall is a network security system that monitors and controls incoming and outgoing network traffic based on predefined security rules.
- Acts as a barrier between trusted internal networks and untrusted external networks
- Can be hardware-based or software-based
- Blocks unauthorized access while permitting legitimate communication
- Example: Windows Defender Firewall, Cisco ASA
2. Encryption
Encryption converts readable data (plaintext) into an unreadable format (ciphertext) using cryptographic algorithms, so only authorized parties can read it.
- Symmetric Encryption: Same key for encryption and decryption (e.g., AES, DES)
- Asymmetric Encryption: Public key encrypts, private key decrypts (e.g., RSA)
- Used in HTTPS, email security (PGP), VPNs, and file protection
- Protects data in transit and at rest
3. Antivirus and Anti-malware Software
Antivirus software detects, prevents, and removes malicious software (malware) such as viruses, worms, trojans, ransomware, and spyware.
- Uses signature-based detection (known malware patterns)
- Uses heuristic analysis (behavior-based detection of unknown threats)
- Regular updates are essential to protect against new threats
- Examples: Norton, Kaspersky, Avast, Malwarebytes
4. Authentication and Access Control
Strong authentication ensures that only legitimate users can access systems and data.
- Password-based authentication: Use of strong, complex passwords
- Multi-Factor Authentication (MFA): Combines two or more factors:
- Something you know (password)
- Something you have (OTP, token)
- Something you are (biometrics - fingerprint, face recognition)
- Role-Based Access Control (RBAC): Users are granted access only to resources needed for their role (principle of least privilege)
5. Virtual Private Network (VPN)
A VPN creates a secure, encrypted tunnel between a user's device and the internet, masking the user's IP address and protecting data from interception.
- Protects users on public Wi-Fi networks
- Hides browsing activity from ISPs and attackers
- Used by organizations to allow secure remote access
- Examples: NordVPN, OpenVPN, ExpressVPN
6. Intrusion Detection and Prevention Systems (IDS/IPS)
- IDS (Intrusion Detection System): Monitors network traffic and alerts administrators about suspicious activity
- IPS (Intrusion Prevention System): Actively blocks detected threats in real time
- Helps identify attacks such as port scanning, DoS attacks, and unauthorized access attempts
7. Secure Communication Protocols
Using secure protocols ensures data transmitted over cyberspace is protected.
Protocol Purpose HTTPS Secure web browsing (SSL/TLS) SSH Secure remote login SFTP Secure file transfer S/MIME Secure email communication
8. User Awareness and Cyber Hygiene
Technical measures alone are insufficient; human behavior is a major vulnerability.
- Educating users about phishing attacks (fraudulent emails/links)
- Avoiding suspicious downloads and attachments
- Regularly updating software and operating systems (patch management)
- Using strong, unique passwords and a password manager
- Not sharing sensitive information on unsecured platforms
9. Backup and Disaster Recovery
- Regularly backing up data ensures recovery in case of ransomware attacks or data loss
- Follow the 3-2-1 rule: 3 copies of data, on 2 different media, with 1 offsite backup
- Helps maintain data availability and business continuity
10. Digital Certificates and Public Key Infrastructure (PKI)
- Digital certificates verify the identity of websites and users
- Issued by trusted Certificate Authorities (CA)
- PKI manages the creation, distribution, and revocation of digital certificates
- Ensures authenticity and non-repudiation in online transactions
Summary Table
Technique Primary Protection Firewall Unauthorized network access Encryption Data confidentiality Antivirus Malware and viruses MFA/Authentication Identity theft VPN Data interception, privacy IDS/IPS Intrusion and attacks Secure Protocols Data in transit User Awareness Social engineering, phishing Backup Data loss, ransomware Digital Certificates Identity verification
Note: Since no specific curriculum notes were provided for this topic, this answer is based on standard, widely accepted cybersecurity concepts appropriate for BSc CSIT level examinations.
- 310 marksCauses of Software FailuresHideAnswer
What does the code of ethics reflect? What are the causes of software failure? Explain the factors that justify the risks in software issues.[10]
Code of Ethics, Software Failure, and Risk Justification in Software Engineering
1. What Does the Code of Ethics Reflect?
The Code of Ethics in software engineering reflects the professional responsibilities and moral obligations of software engineers toward their clients, employers, the public, and the profession itself.
The ACM/IEEE Software Engineering Code of Ethics is built around 8 principles. It reflects the following:
Principle What It Reflects Public Software engineers shall act consistently with the public interest Client and Employer Act in the best interest of client and employer, consistent with public interest Product Ensure products meet the highest professional standards Judgment Maintain integrity and independence in professional judgment Management Managers shall promote ethical approaches Profession Advance the integrity and reputation of the profession Colleagues Be fair and supportive of colleagues Self Participate in lifelong learning and promote ethical practice In Summary, the Code of Ethics Reflects:
- Honesty and integrity in professional work
- Accountability for the software products developed
- Respect for privacy, confidentiality, and intellectual property
- Commitment to quality and public safety
- Fairness in professional relationships
- Responsibility to society and the environment
2. Causes of Software Failure
Software failure refers to the inability of a software system to perform its required functions within specified performance requirements. The major causes include:
A. Technical Causes
-
Poor Requirements Analysis
- Incomplete, ambiguous, or misunderstood requirements lead to building the wrong product.
-
Design Flaws
- Inadequate architectural design, poor module decomposition, or ignoring non-functional requirements.
-
Coding Errors (Bugs)
- Logic errors, off-by-one errors, null pointer exceptions, memory leaks, etc.
-
Inadequate Testing
- Insufficient test coverage, missing edge cases, no regression testing.
-
Integration Problems
- Incompatibility between modules or third-party components.
-
Complexity
- Overly complex systems are harder to understand, maintain, and test.
B. Managerial/Process Causes
-
Poor Project Management
- Unrealistic schedules, poor resource allocation, lack of planning.
-
Lack of Documentation
- Makes maintenance and debugging extremely difficult.
-
Changing Requirements (Scope Creep)
- Frequent changes without proper change management destabilize the system.
-
Inadequate Communication
- Miscommunication between developers, clients, and stakeholders.
C. Human Causes
-
Lack of Skilled Personnel
- Inexperienced developers making poor design and coding decisions.
-
Negligence and Complacency
- Skipping reviews, ignoring warnings, or rushing through phases.
D. Environmental Causes
-
Hardware/Platform Changes
- Software not updated to match new hardware or OS environments.
-
Security Vulnerabilities
- Failure to address security threats leads to exploitation and failure.
3. Factors That Justify the Risks in Software Issues
Risk in software engineering refers to the probability of an undesirable outcome and its potential impact. Certain factors justify (i.e., explain or validate the existence of) risks in software projects.
Factor 1: Complexity of Software Systems
- Modern software systems are extremely complex with millions of lines of code.
- High complexity inherently increases the probability of defects and failures.
- Justification: It is practically impossible to test all execution paths; some risk is unavoidable.
Factor 2: Changing Technology
- Rapid changes in hardware, operating systems, and platforms introduce compatibility risks.
- New technologies may not be fully understood or tested.
- Justification: Adopting new technology always carries uncertainty.
Factor 3: Evolving Requirements
- User needs and business environments change over time.
- Requirements that change mid-project introduce instability.
- Justification: Dynamic environments make it impossible to freeze requirements completely.
Factor 4: Human Factors
- Software is built by humans who make mistakes.
- Communication gaps between team members and stakeholders introduce risk.
- Justification: Human error is an inherent part of any engineering process.
Factor 5: Time and Budget Constraints
- Tight deadlines force teams to cut corners in testing and review.
- Insufficient budget leads to under-staffing and poor tooling.
- Justification: Resource limitations make it impossible to achieve zero-risk development.
Factor 6: Dependency on Third-Party Components
- Use of external libraries, APIs, and frameworks introduces risks outside the team's control.
- Justification: Third-party failures or vulnerabilities directly impact the product.
Factor 7: Inadequate Risk Management Processes
- Organizations that do not formally identify, analyze, and mitigate risks are more exposed.
- Justification: Without a risk management plan, risks go undetected until they cause failure.
Factor 8: Security Threats
- Increasing cyber threats mean software is always at risk of being compromised.
- Justification: The threat landscape evolves faster than most software can be patched.
Summary Table
Aspect Key Points Code of Ethics Reflects honesty, accountability, public safety, integrity, and professional responsibility Causes of Software Failure Poor requirements, design flaws, coding errors, poor management, scope creep, lack of testing Risk Justifying Factors Complexity, changing technology, human error, budget constraints, third-party dependencies, security threats - 45 marksEthics and ProfessionsHideAnswer
Why is education and licensing essential to become an ethical professional? [5]
An ethical professional is one who not only possesses technical competence but also understands and upholds moral responsibilities toward clients, society, and the profession. Education and licensing serve as the two foundational pillars...
- 55 marksDevelopment PlanningHideAnswer
Define development planning. Why do we need development planning? [5]
Development Planning: Definition and Need
Definition of Development Planning
Development planning is a systematic process of setting goals, objectives, and strategies for the growth and progress of a nation, region, organization, or community over a defined period of time. It involves the deliberate allocation of available resources (human, financial, natural, and technological) to achieve specific socio-economic targets within a given timeframe.
In simple terms, development planning is the conscious and organized effort by a government or authority to guide economic and social development by formulating policies, programs, and projects aimed at improving the overall well-being of the people.
Why Do We Need Development Planning?
Development planning is essential for the following reasons:
1. Optimal Use of Scarce Resources
Resources such as capital, labor, land, and technology are limited. Development planning ensures these scarce resources are allocated efficiently to priority sectors, avoiding wastage and duplication.
2. Setting Clear Goals and Direction
Planning provides a clear vision and direction for development. Without planning, development activities may be scattered and uncoordinated. It helps define what needs to be achieved and by when.
3. Reduction of Regional and Social Inequalities
Development planning helps address imbalances between urban and rural areas, rich and poor populations, and different regions. It ensures that marginalized groups also benefit from development activities.
4. Coordination Among Sectors
A country has many sectors such as agriculture, industry, education, health, and infrastructure. Planning coordinates activities across these sectors so they support each other and work toward common national goals.
5. Mobilization of Resources
Planning helps identify sources of funding (domestic savings, foreign aid, loans, taxes) and mobilizes them effectively for development programs and projects.
6. Dealing with Market Failures
In developing countries, markets often fail to provide public goods, control monopolies, or address externalities. Development planning allows the government to intervene and correct these failures.
7. Achieving Sustainable Development
Planning ensures that development is not only rapid but also sustainable, balancing economic growth with environmental protection and social equity for future generations.
8. Monitoring and Evaluation
Planning provides a framework for monitoring progress and evaluating outcomes. It allows policymakers to identify gaps and make necessary adjustments to policies and programs.
Summary Table
Reason Purpose Resource allocation Efficient use of limited resources Goal setting Clear direction for development Equity Reduce inequalities Coordination Integrate sectoral activities Resource mobilization Secure and channel funds Market failure correction Government intervention Sustainability Long-term balanced growth Monitoring Track and improve performance
Conclusion: Development planning is a vital tool for any country, especially developing nations like Nepal, to achieve organized, equitable, and sustainable progress. It transforms national aspirations into actionable programs and ensures that limited resources produce maximum benefit for the population.
- 65 marksEthical Reasoning and Decision MakingHideAnswer
What is ethical decision-making? Explain the framework for ethical decision-making. [5]
Ethical Decision-Making
Definition
Ethical decision-making is the process of evaluating and choosing among alternatives in a manner that is consistent with ethical principles such as honesty, fairness, responsibility, and respect for others. It involves identifying a situation that raises ethical concerns, considering the possible courses of action, and selecting the option that best aligns with moral values and professional standards.
Framework for Ethical Decision-Making
A structured framework helps individuals and organizations make sound moral choices. The commonly accepted steps are:
1. Identify the Ethical Issue or Problem
- Recognize that an ethical dilemma exists.
- Determine who is affected (stakeholders) and what values or rights are at stake.
- Ask: Is this situation involving harm, fairness, honesty, or rights?
2. Gather Relevant Information
- Collect all facts related to the situation.
- Understand the context, applicable laws, organizational policies, and professional codes of conduct.
- Avoid making decisions based on incomplete or biased information.
3. Identify All Possible Alternatives
- Brainstorm all available courses of action.
- Consider both obvious and creative solutions.
- Do not limit options prematurely.
4. Evaluate Each Alternative Using Ethical Principles
Apply major ethical theories to assess each option:
Ethical Theory Question to Ask Utilitarianism Which option produces the greatest good for the greatest number? Deontology (Duty-based) Which option respects rules, duties, and rights? Virtue Ethics What would a person of good character do? Justice/Fairness Which option treats all parties fairly and equally? 5. Make a Decision
- Select the alternative that best satisfies the ethical criteria.
- The chosen action should be one you could openly justify to others.
- Apply the "newspaper test": Would you be comfortable if your decision was reported publicly?
6. Implement the Decision
- Put the chosen course of action into practice.
- Communicate the decision clearly and transparently to those affected.
7. Reflect and Evaluate the Outcome
- After implementation, review the results.
- Ask: Did the decision achieve the intended ethical outcome?
- Use lessons learned to improve future decision-making.
Summary Diagram
Identify Issue --> Gather Information --> List Alternatives | v Evaluate with Ethical Principles --> Make Decision --> Implement --> Reflect
Importance of Ethical Decision-Making
- Builds trust and credibility in professional environments.
- Prevents legal and reputational harm.
- Promotes a positive organizational culture.
- Ensures technology and resources are used responsibly (especially relevant in IT/CS fields).
- 75 marksTransnational Issues and Intellectual PropHideAnswer
Most copyright violations are found in developing, usually, poor countries. Why? [5]
Copyright violations (software piracy, media piracy, etc.) are disproportionately high in developing and economically poor countries due to the following key reasons: --- - Licensed software, music, films, and books are priced according ...
- 85 marksArtificial Intelligence ad EthicsHideAnswer
Discuss future of AI and its ethical implications. [5]
The future of Artificial Intelligence holds tremendous potential across multiple domains: - Artificial General Intelligence (AGI): Development of AI systems that can perform any intellectual task that a human can do, moving beyond narrow...
- 95 marksFunctional Definition of EthicsHideAnswer
Write short notes on: a. Functional definition of ethics b. Employee monitoring [5]
Ethics can be defined functionally as a set of moral principles, values, and standards that guide human behavior in determining what is right and wrong, good and bad, in a given situation or context. From a functional perspective, ethics...
- 105 marksE-governanceHideAnswer
What is e-governance? How can we achieve good governance through e-governance? [5]
E-Governance and Achieving Good Governance Through E-Governance
What is E-Governance?
E-Governance (Electronic Governance) is the application of Information and Communication Technology (ICT) by government agencies to deliver services, exchange information, communicate, and integrate various stand-alone systems between government-to-citizen (G2C), government-to-business (G2B), government-to-government (G2G), and government-to-employees (G2E) interactions.
In simple terms, e-governance means using digital tools and the internet to make government processes more efficient, transparent, and accessible to citizens.
Example: Online tax filing, digital land records, online passport applications, etc.
Achieving Good Governance Through E-Governance
Good governance can be achieved through e-governance in the following ways:
1. Transparency
- All government activities, policies, budgets, and decisions are made publicly available online.
- Citizens can monitor how public funds are spent, reducing corruption.
2. Accountability
- Digital records and audit trails make it easier to track government actions.
- Officials are held responsible for their decisions as everything is documented electronically.
3. Efficiency and Effectiveness
- Automation of government processes reduces paperwork, delays, and human errors.
- Services are delivered faster and at lower cost.
4. Citizen Participation
- Online portals and platforms allow citizens to give feedback, file complaints, and participate in decision-making.
- Promotes democratic participation and inclusive governance.
5. Rule of Law
- Standardized digital processes ensure uniform application of laws and regulations.
- Reduces arbitrary decision-making by officials.
6. Reduced Corruption
- Direct delivery of services to citizens (e.g., direct benefit transfers) eliminates middlemen.
- Digital transactions leave traceable records, discouraging corrupt practices.
7. Accessibility and Equity
- Government services become available 24/7 from anywhere.
- Reaches remote and rural populations who previously had limited access to government services.
Summary Table
Principle of Good Governance Role of E-Governance Transparency Online disclosure of information Accountability Digital audit trails Efficiency Process automation Participation Online feedback and portals Equity 24/7 accessible services Anti-corruption Traceable digital transactions
Conclusion: E-governance is a powerful tool to transform traditional governance into good governance by making government services transparent, efficient, accountable, and citizen-friendly through the use of ICT.
- 115 marksWorkplace, Employee, Health, and ProductivHideAnswer
Explain different health-related issues of using computer technology in brief. [5]
Prolonged and improper use of computer technology can lead to several physical and mental health problems. The major health-related issues are described below: --- Staring at a computer screen for long hours causes eye fatigue, blurred v...
- 125 marksRiskHideAnswer
Compare security with safety. Why is software safety so difficult to attain? Can it be guaranteed? [5]
Aspect Safety Security --------- Definition Ensures the system does not cause harm to people or the environment Ensures the system is protected from unauthorized access, attacks, and misuse Focus Accidental failures and unintended behavi...