CSC378 · TU past paper
NET Centric Computing 2078 question paper
The complete TU 2078 exam paper for NET Centric Computing (CSC378), all 12 questions with solved model answers written to the mark scheme.
Tap a question to open its answer.
- 110 marksNumericalState Management on stateless HTTPHideAnswer
What are the advantages of stateless HTTP in ASP.NET core application? Create a method to insert a record (3, 'John', 12000) onto the table Employee having fields EmployeeId(int), Name varchar(200), Salary(int) using Entity Framework.[10]
- Record to insert: (3, 'John', 12000) - Table: Employee - Fields: EmployeeId (int), Name (varchar(200)), Salary (int) --- HTTP is a stateless protocol: each request is independent and the server keeps no memory of previous requests. Thi...
- 210 marksstructs and enumsHideAnswer
Differentiate between struct and enum. Why do we need to handle the exception? Illustrate with an example with your own customized exception.[10]
--- As per the course notes, the key differences are: Feature Struct Enum --------- Keyword struct keyword is used to declare a structure enum keyword is used to declare an enumeration Contents Can contain both data variables and methods...
- 310 marks.NET CLIHideAnswer
Explain the procedure for building, running, and deploying .NET core applications. Write a program to show the possibility of SQL injection attack.[10]
The .NET Core Command-Line Interface (CLI) is a cross-platform tool for creating, restoring packages, building, running, and publishing .NET applications. It is installed with the .NET Core SDK and does not need to be installed separatel...
- 45 marksRequest and Response Message FormatHideAnswer
Explain about request and response message format with example. [5]
To communicate with a web server, the client makes calls over the network using HTTP (HyperText Transfer Protocol). A client makes an HTTP request for a resource, and the server sends back an HTTP response. --- An HTTP request message is...
- 55 marksCommon VulnerabilitiesHideAnswer
Define open redirect attacks. Discuss about docker and containerization. [5]
Open Redirect Attacks and Docker/Containerization
Part 1: Open Redirect Attacks (2 marks)
An open redirect attack is a web security vulnerability where an attacker manipulates a web application to redirect users to an arbitrary, potentially malicious external URL without proper validation.
How It Works:
- Web applications often use URL parameters to redirect users after an action (e.g., login).
- Example of a vulnerable URL:
https://trustedsite.com/login?returnUrl=https://malicious.com - If the application does not validate the
returnUrlparameter, the user is silently redirected to the attacker's site.
Common Consequences:
- Phishing attacks: Users are redirected to fake login pages to steal credentials.
- Malware distribution: Users are sent to sites hosting malicious downloads.
- Credential harvesting: Combined with XSS (Cross-Site Scripting), attackers can steal cookies and session tokens (as noted in the reference: XSS can "redirect the browser to another page").
Prevention:
- Validate and whitelist all redirect URLs.
- Avoid using user-supplied input directly in redirect logic.
- Use relative URLs instead of absolute URLs for redirects.
Part 2: Docker and Containerization (3 marks)
Containerization
Containerization is a lightweight form of virtualization where an application and all its dependencies (libraries, configuration files, runtime) are packaged together into a single unit called a container. Containers run in isolated environments on the host operating system without needing a full virtual machine.
Key Characteristics:
- Containers share the host OS kernel (unlike VMs which have separate OS).
- Lightweight, fast to start, and portable.
- Ensures "works on my machine" consistency across environments (development, testing, production).
Docker
Docker is the most widely used platform for building, shipping, and running containers. It provides tools and a runtime to create and manage containers easily.
Core Docker Concepts:
Concept Description Docker Image A read-only template/blueprint used to create containers (e.g., an image with Node.js + app code) Docker Container A running instance of a Docker image Dockerfile A script containing instructions to build a Docker image Docker Hub A public registry to store and share Docker images Docker Engine The runtime that builds and runs containers Basic Dockerfile Example:
FROM node:14 WORKDIR /app COPY . . RUN npm install CMD ["node", "server.js"]Advantages of Docker and Containerization:
- Portability: Containers run consistently across any environment (local, cloud, server).
- Isolation: Each container runs independently, preventing conflicts between applications.
- Efficiency: Containers are lightweight compared to virtual machines as they share the host OS kernel.
- Scalability: Containers can be easily scaled up or down using orchestration tools like Kubernetes.
- Faster Deployment: Applications can be deployed quickly using pre-built images.
- Version Control: Docker images can be versioned, allowing easy rollback.
Docker vs Virtual Machine:
Feature Docker Container Virtual Machine OS Shares host OS kernel Has its own OS Size Megabytes Gigabytes Startup Time Seconds Minutes Performance Near native Overhead due to hypervisor
Note: The reference notes provided do not directly cover open redirect attacks or Docker. The above answer is based on standard, correct Computer Science knowledge appropriate for BSc CSIT curriculum, with open redirect attacks linked to the XSS/redirect concepts mentioned in the reference context (ctx3).
- 65 marksAttributesHideAnswer
What is named and positional attribute parameters? Describe the .Net architecture design and principles. [5]
Named and Positional Attribute Parameters & .NET Architecture Design and Principles
Part 1: Named and Positional Attribute Parameters
From the notes, the syntax for an attribute is:
[attribute(positional_parameters, name_parameter=value, ...)] elementPositional Parameters
- Positional parameters are the mandatory parameters of an attribute.
- They must be passed in a fixed order as defined in the attribute constructor.
- They correspond directly to the constructor arguments of the attribute class.
Example:
[Obsolete("This method is deprecated")] public void OldMethod() { }Here,
"This method is deprecated"is a positional parameter passed in order.Named Parameters
- Named parameters are optional parameters of an attribute.
- They are specified using a name=value syntax and can be provided in any order.
- They correspond to properties or fields of the attribute class.
Example:
[AttributeUsage(AttributeTargets.Class, AllowMultiple = true, Inherited = false)]Here:
AttributeTargets.Classis the positional parameter (mandatory, in order).AllowMultiple = trueandInherited = falseare named parameters (optional, any order).
Part 2: .NET Architecture Design and Principles
.NET Architecture Overview
The layered architecture of .NET (as described in the notes) is as follows:
+------------------------------------------+ | VB.NET | C# | JScript.NET | More Languages | +------------------------------------------+ | Common Language Specification (CLS) | +------------------------------------------+ | Common Type System (CTS) | +------------------------------------------+ | .NET Framework Class Library (FCL) | +------------------------------------------+ | ASP.NET | Windows Forms | Console | ADO.NET | | Web Forms | XML Web Services | .NET Remoting | +------------------------------------------+ | Common Language Runtime (CLR) | | [JIT Compilers, Security Manager, etc.] | +------------------------------------------+ | Common Language Infrastructure (CLI) | +------------------------------------------+ | Operating System | +------------------------------------------+
Key Components Explained
Component Description CLR (Common Language Runtime) The heart of .NET Framework. Resides above the OS and handles all .NET applications. Manages garbage collection, Code Access Security (CAS), and memory management. CLI (Common Language Infrastructure) Provides a language-independent platform for app development. Handles exception handling, garbage collection, and security. CTS (Common Type System) Specifies a standard that defines what types of data and values can be defined and managed in memory at runtime. CLS (Common Language Specification) A subset of CTS that defines rules and regulations that every .NET language must follow to ensure interoperability. FCL (Framework Class Library) Provides system functionality including classes, interfaces, and data types to build desktop, web, and mobile applications.
Design Principles of .NET
-
Clean Architecture: Applications following the Dependency Inversion Principle and Domain-Driven Design (DDD) are known as clean architecture. It places business logic and application model at the center.
-
MVC Pattern: Separates the application into three components:
- Model: Represents the shape/structure of data.
- View: User interface that displays model data.
- Controller: Handles user requests and manages the flow.
-
N-Tier Architecture: ASP.NET Core automatically creates a pre-defined N-tier architecture for developers, saving time and effort, and easing tier deployment.
-
Separation of Concerns: Each layer/component handles a specific responsibility, making the application maintainable and testable.
-
Language Interoperability: Through CLS and CTS, .NET supports multiple languages (C#, VB.NET, JScript.NET) that can work together seamlessly.
Summary: .NET architecture is a layered, language-independent framework where CLR acts as the execution engine, CTS/CLS ensure type safety and interoperability, and FCL provides reusable libraries. Its design principles promote clean, maintainable, and scalable application development.
- 75 marksForms and ValidationHideAnswer
Why do we need to validate the form? How can you use react for this? [5]
Form validation is the process of checking user input before it is submitted to the server. We need form validation for the following reasons: - Data Integrity: Ensures that only correct and complete data is sent to the server (e.g., emp...
- 85 marksAdding EF Core to an applicationHideAnswer
Define data model and data context. What does URL routing mean? [5]
--- According to Entity Framework Core, a data model (also called Entity Data Model) is the model that Entity Framework uses to communicate with the underlying database. It is built based on the shape of domain classes, Data Annotations,...
- 95 marksServer-side strategiesHideAnswer
Give an example to manage the session state. [5]
Session State is an ASP.NET Core mechanism to store user data while the user browses the application. It uses a store maintained by the application to carry on data across requests from a client. ASP.NET Core maintains the session state ...
- 105 marksCommon VulnerabilitiesHideAnswer
How can you prevent SQL injection attack? Explain with an example. [5]
SQL Injection is a security vulnerability where an attacker inserts or "injects" malicious SQL code into an input field, which is then executed by the database. This can allow attackers to bypass authentication, access unauthorized data,...
- 115 marksApp Servers and Hosting modelsHideAnswer
Explain the process to deploy the core application. [5]
Deploying an ASP.NET Core application involves choosing an appropriate hosting model and web server to serve the application to end users. The .NET Core CLI also plays a key role in building and publishing the application before deployme...
- 1215 marksLINQHideAnswer
Write short notes on (any two): a. LINQ b. Open Redirected Attack c. Query String [5+5+5]
--- Definition: LINQ (Language Integrated Query) is the name for a set of technologies based on the integration of query capabilities directly into the C language. With LINQ, a query is a first-class language construct, just like classes...