2078

CSC378 · TU past paper

NET Centric Computing 2078 question paper

The complete TU 2078 exam paper for NET Centric Computing (CSC378), all 12 questions with solved model answers written to the mark scheme.

Tap a question to open its answer.

  1. 110 marksNumericalState Management on stateless HTTPAnswer

    What are the advantages of stateless HTTP in ASP.NET core application? Create a method to insert a record (3, 'John', 12000) onto the table Employee having fields EmployeeId(int), Name varchar(200), Salary(int) using Entity Framework.[10]

    • Record to insert: (3, 'John', 12000) - Table: Employee - Fields: EmployeeId (int), Name (varchar(200)), Salary (int) --- HTTP is a stateless protocol: each request is independent and the server keeps no memory of previous requests. Thi...
  2. 210 marksstructs and enumsAnswer

    Differentiate between struct and enum. Why do we need to handle the exception? Illustrate with an example with your own customized exception.[10]

    --- As per the course notes, the key differences are: Feature Struct Enum --------- Keyword struct keyword is used to declare a structure enum keyword is used to declare an enumeration Contents Can contain both data variables and methods...

  3. 310 marks.NET CLIAnswer

    Explain the procedure for building, running, and deploying .NET core applications. Write a program to show the possibility of SQL injection attack.[10]

    The .NET Core Command-Line Interface (CLI) is a cross-platform tool for creating, restoring packages, building, running, and publishing .NET applications. It is installed with the .NET Core SDK and does not need to be installed separatel...

  4. 45 marksRequest and Response Message FormatAnswer

    Explain about request and response message format with example. [5]

    To communicate with a web server, the client makes calls over the network using HTTP (HyperText Transfer Protocol). A client makes an HTTP request for a resource, and the server sends back an HTTP response. --- An HTTP request message is...

  5. 55 marksCommon VulnerabilitiesAnswer

    Define open redirect attacks. Discuss about docker and containerization. [5]

    Open Redirect Attacks and Docker/Containerization


    Part 1: Open Redirect Attacks (2 marks)

    An open redirect attack is a web security vulnerability where an attacker manipulates a web application to redirect users to an arbitrary, potentially malicious external URL without proper validation.

    How It Works:

    • Web applications often use URL parameters to redirect users after an action (e.g., login).
    • Example of a vulnerable URL:
      https://trustedsite.com/login?returnUrl=https://malicious.com
      
    • If the application does not validate the returnUrl parameter, the user is silently redirected to the attacker's site.

    Common Consequences:

    • Phishing attacks: Users are redirected to fake login pages to steal credentials.
    • Malware distribution: Users are sent to sites hosting malicious downloads.
    • Credential harvesting: Combined with XSS (Cross-Site Scripting), attackers can steal cookies and session tokens (as noted in the reference: XSS can "redirect the browser to another page").

    Prevention:

    • Validate and whitelist all redirect URLs.
    • Avoid using user-supplied input directly in redirect logic.
    • Use relative URLs instead of absolute URLs for redirects.

    Part 2: Docker and Containerization (3 marks)

    Containerization

    Containerization is a lightweight form of virtualization where an application and all its dependencies (libraries, configuration files, runtime) are packaged together into a single unit called a container. Containers run in isolated environments on the host operating system without needing a full virtual machine.

    Key Characteristics:

    • Containers share the host OS kernel (unlike VMs which have separate OS).
    • Lightweight, fast to start, and portable.
    • Ensures "works on my machine" consistency across environments (development, testing, production).

    Docker

    Docker is the most widely used platform for building, shipping, and running containers. It provides tools and a runtime to create and manage containers easily.

    Core Docker Concepts:

    ConceptDescription
    Docker ImageA read-only template/blueprint used to create containers (e.g., an image with Node.js + app code)
    Docker ContainerA running instance of a Docker image
    DockerfileA script containing instructions to build a Docker image
    Docker HubA public registry to store and share Docker images
    Docker EngineThe runtime that builds and runs containers

    Basic Dockerfile Example:

    FROM node:14
    WORKDIR /app
    COPY . .
    RUN npm install
    CMD ["node", "server.js"]
    

    Advantages of Docker and Containerization:

    1. Portability: Containers run consistently across any environment (local, cloud, server).
    2. Isolation: Each container runs independently, preventing conflicts between applications.
    3. Efficiency: Containers are lightweight compared to virtual machines as they share the host OS kernel.
    4. Scalability: Containers can be easily scaled up or down using orchestration tools like Kubernetes.
    5. Faster Deployment: Applications can be deployed quickly using pre-built images.
    6. Version Control: Docker images can be versioned, allowing easy rollback.

    Docker vs Virtual Machine:

    FeatureDocker ContainerVirtual Machine
    OSShares host OS kernelHas its own OS
    SizeMegabytesGigabytes
    Startup TimeSecondsMinutes
    PerformanceNear nativeOverhead due to hypervisor

    Note: The reference notes provided do not directly cover open redirect attacks or Docker. The above answer is based on standard, correct Computer Science knowledge appropriate for BSc CSIT curriculum, with open redirect attacks linked to the XSS/redirect concepts mentioned in the reference context (ctx3).

  6. 65 marksAttributesAnswer

    What is named and positional attribute parameters? Describe the .Net architecture design and principles. [5]

    Named and Positional Attribute Parameters & .NET Architecture Design and Principles


    Part 1: Named and Positional Attribute Parameters

    From the notes, the syntax for an attribute is:

    [attribute(positional_parameters, name_parameter=value, ...)]
    element
    

    Positional Parameters

    • Positional parameters are the mandatory parameters of an attribute.
    • They must be passed in a fixed order as defined in the attribute constructor.
    • They correspond directly to the constructor arguments of the attribute class.

    Example:

    [Obsolete("This method is deprecated")]
    public void OldMethod() { }
    

    Here, "This method is deprecated" is a positional parameter passed in order.

    Named Parameters

    • Named parameters are optional parameters of an attribute.
    • They are specified using a name=value syntax and can be provided in any order.
    • They correspond to properties or fields of the attribute class.

    Example:

    [AttributeUsage(AttributeTargets.Class, AllowMultiple = true, Inherited = false)]
    

    Here:

    • AttributeTargets.Class is the positional parameter (mandatory, in order).
    • AllowMultiple = true and Inherited = false are named parameters (optional, any order).

    Part 2: .NET Architecture Design and Principles

    .NET Architecture Overview

    The layered architecture of .NET (as described in the notes) is as follows:

    +------------------------------------------+
    |  VB.NET | C# | JScript.NET | More Languages |
    +------------------------------------------+
    |   Common Language Specification (CLS)    |
    +------------------------------------------+
    |      Common Type System (CTS)            |
    +------------------------------------------+
    |   .NET Framework Class Library (FCL)     |
    +------------------------------------------+
    | ASP.NET | Windows Forms | Console | ADO.NET |
    | Web Forms | XML Web Services | .NET Remoting |
    +------------------------------------------+
    |  Common Language Runtime (CLR)           |
    |  [JIT Compilers, Security Manager, etc.] |
    +------------------------------------------+
    |  Common Language Infrastructure (CLI)    |
    +------------------------------------------+
    |          Operating System                |
    +------------------------------------------+
    

    Key Components Explained

    ComponentDescription
    CLR (Common Language Runtime)The heart of .NET Framework. Resides above the OS and handles all .NET applications. Manages garbage collection, Code Access Security (CAS), and memory management.
    CLI (Common Language Infrastructure)Provides a language-independent platform for app development. Handles exception handling, garbage collection, and security.
    CTS (Common Type System)Specifies a standard that defines what types of data and values can be defined and managed in memory at runtime.
    CLS (Common Language Specification)A subset of CTS that defines rules and regulations that every .NET language must follow to ensure interoperability.
    FCL (Framework Class Library)Provides system functionality including classes, interfaces, and data types to build desktop, web, and mobile applications.

    Design Principles of .NET

    1. Clean Architecture: Applications following the Dependency Inversion Principle and Domain-Driven Design (DDD) are known as clean architecture. It places business logic and application model at the center.

    2. MVC Pattern: Separates the application into three components:

      • Model: Represents the shape/structure of data.
      • View: User interface that displays model data.
      • Controller: Handles user requests and manages the flow.
    3. N-Tier Architecture: ASP.NET Core automatically creates a pre-defined N-tier architecture for developers, saving time and effort, and easing tier deployment.

    4. Separation of Concerns: Each layer/component handles a specific responsibility, making the application maintainable and testable.

    5. Language Interoperability: Through CLS and CTS, .NET supports multiple languages (C#, VB.NET, JScript.NET) that can work together seamlessly.


    Summary: .NET architecture is a layered, language-independent framework where CLR acts as the execution engine, CTS/CLS ensure type safety and interoperability, and FCL provides reusable libraries. Its design principles promote clean, maintainable, and scalable application development.

  7. 75 marksForms and ValidationAnswer

    Why do we need to validate the form? How can you use react for this? [5]

    Form validation is the process of checking user input before it is submitted to the server. We need form validation for the following reasons: - Data Integrity: Ensures that only correct and complete data is sent to the server (e.g., emp...

  8. 85 marksAdding EF Core to an applicationAnswer

    Define data model and data context. What does URL routing mean? [5]

    --- According to Entity Framework Core, a data model (also called Entity Data Model) is the model that Entity Framework uses to communicate with the underlying database. It is built based on the shape of domain classes, Data Annotations,...

  9. 95 marksServer-side strategiesAnswer

    Give an example to manage the session state. [5]

    Session State is an ASP.NET Core mechanism to store user data while the user browses the application. It uses a store maintained by the application to carry on data across requests from a client. ASP.NET Core maintains the session state ...

  10. 105 marksCommon VulnerabilitiesAnswer

    How can you prevent SQL injection attack? Explain with an example. [5]

    SQL Injection is a security vulnerability where an attacker inserts or "injects" malicious SQL code into an input field, which is then executed by the database. This can allow attackers to bypass authentication, access unauthorized data,...

  11. 115 marksApp Servers and Hosting modelsAnswer

    Explain the process to deploy the core application. [5]

    Deploying an ASP.NET Core application involves choosing an appropriate hosting model and web server to serve the application to end users. The .NET Core CLI also plays a key role in building and publishing the application before deployme...

  12. 1215 marksLINQAnswer

    Write short notes on (any two): a. LINQ b. Open Redirected Attack c. Query String [5+5+5]

    --- Definition: LINQ (Language Integrated Query) is the name for a set of technologies based on the integration of query capabilities directly into the C language. With LINQ, a query is a first-class language construct, just like classes...