CSC381 · TU past paper
E-Commerce 2078 question paper
The complete TU 2078 exam paper for E-Commerce (CSC381), all 12 questions with solved model answers written to the mark scheme.
Tap a question to open its answer.
- 110 marksElements of Business ModelHideAnswer
What is e-commerce business model? Describe the key elements of e-commerce business model.[10]
A business model is a set of planned activities designed to result in a profit in a marketplace. The business model spells out how a company makes money by specifying where it is positioned on the value chain. An e-commerce business mode...
- 210 marksSecurity Threats in E-commerceHideAnswer
What are the security threats in e-commerce? How client server and data transactions securities are maintained in e-commerce?[10]
Security Threats in E-Commerce and Maintaining Client-Server & Data Transaction Security
Part 1: Security Threats in E-Commerce
E-commerce involves buying and selling over public networks, making it vulnerable to various security threats. The most common and damaging threats are described below:
1. Malicious Code (Malware)
Malicious code includes a variety of threats such as viruses, trojan horses, worms, and ransomware. It refers to any unwanted file or program that can cause harm to a computer or compromise data stored on it.
Prevention:
- Installing and maintaining antivirus software
- Using caution with links and attachments
- Keeping software updated
- Using accounts with limited permissions
2. Hacking
A hacker is an individual who intends to gain unauthorized access to a computer system. Hackers find weaknesses in the security procedures of websites and computer systems to gain such access.
Prevention:
- Maximum security procedures must be implemented
- Regular security audits of websites and systems
3. Credit Card Fraud and Identity Theft
- Credit Card Fraud occurs when a thief gets hold of a victim's credit card information and misuses it, typically affecting one or more open credit card accounts.
- Identity Theft is a crime where someone wrongfully accesses and uses another person's personal information (such as bank account numbers, address, birth date) for economic gain.
4. Spoofing and Pharming
- Spoofing describes a criminal who mimics another individual or organization with the intent to gather personal or business information.
- Pharming involves creating a malicious website that closely resembles a legitimate website, used to gather usernames and passwords from unsuspecting users.
5. Other Threats (from challenges perspective)
- Data Security breaches during online transactions
- Online Identity Verification Problems where people may enter wrong or false information
- Trust issues between buyers and sellers
Part 2: Maintaining Client-Server and Data Transaction Security
From a technology perspective, there are three key points of vulnerability in e-commerce:
- The Client
- The Server
- The Communications Pipeline (Data Transaction)
A. Client and Server Security
i. Operating System Security Enhancement
The best way to protect both servers and clients is to take advantage of automatic security updates. Major operating systems such as Microsoft Windows, Apple macOS, and Linux are continuously updated to patch vulnerabilities.
- These patches are automatic; users are prompted and informed when enhancements are available.
- Security patches can be downloaded for free.
- The most commonly known worms and viruses can be prevented by simply keeping server and client operating systems and applications up to date.
ii. Anti-Virus Software
- Operating system features combined with anti-virus software help further protect servers and clients from certain types of attacks.
- Regular scanning and real-time protection prevent malicious code from executing.
iii. Summary of Client-Server Security Measures
Measure Purpose Automatic OS updates Patch known vulnerabilities Anti-virus software Detect and remove malware Limited user permissions Reduce attack surface Regular security audits Identify and fix weaknesses
B. Data Transaction Security
Because e-commerce transactions must flow over the public Internet, they involve thousands of routers and servers through which transaction packets travel. Security experts believe the greatest security threats occur at the level of data transaction. This is very different from a private network where a dedicated communication line is established between two parties.
A number of tools are available to protect the security of Internet communications:
i. Message Encryption
The most basic tool for data transaction security is message encryption. Encryption converts readable data (plaintext) into an unreadable format (ciphertext) so that only authorized parties with the correct key can read it.
ii. Payment Gateway Security
A payment gateway is a service that authorizes and processes payments online for e-commerce websites. It:
- Serves as a portal to facilitate transaction flow between customers and merchants
- Uses security protocols and encryption to pass transaction data safely
- Complies with financial regulations such as PCI DSS (Payment Card Industry Data Security Standard)
iii. Secure Communication Protocols
Standard secure protocols used in data transactions include:
- SSL/TLS (Secure Sockets Layer / Transport Layer Security): Encrypts data between the client browser and the web server
- HTTPS: HTTP over SSL/TLS, ensuring secure communication
iv. Summary of Data Transaction Security Measures
Tool/Method Function Message Encryption Protects data from interception SSL/TLS Protocols Secures communication channel Payment Gateway (PCI DSS) Authorizes and secures payment transactions HTTPS Ensures encrypted web communication
Conclusion
E-commerce faces serious security threats including malware, hacking, identity theft, spoofing, and pharming. These threats are addressed at three levels: the client (OS updates, antivirus), the server (patches, security enhancements), and the data transaction pipeline (encryption, SSL/TLS, secure payment gateways). A combination of these measures ensures a reasonably secure e-commerce environment for both consumers and businesses.
- 310 marksE-payment SystemHideAnswer
What is e-payment? Discuss how credit card transactions, electronic checks and stored value payment system work. Mention their pros and cons.[10]
Electronic Payment System (EPS) is a way of paying for goods and services electronically instead of using direct cash or physical cheque. EPS simply means online transaction of values. New types of purchasing relationships, such as betwe...
- 45 marksTypes of E-commerceHideAnswer
Describe the factors that make U-commerce different from M-commerce? [5]
M-Commerce (Mobile Commerce): M-commerce refers to the use of mobile devices (smartphones, tablets, laptops) connected via cellular and wireless networks to enable online transactions such as banking, stock trades, travel reservations, a...
- 55 marksE-commerce and Industry Value ChainHideAnswer
What is industry value chain? Mention the generic players in the value chain. [5]
Value chain is an interconnected set of value-adding activities for a product from its raw inputs to final products and services. It describes the complete journey of a product, starting from raw materials through production, distributio...
- 65 marksDigital and Mobile WalletHideAnswer
What is digital wallet? How it works? [5]
A digital wallet (also called e-wallet or mobile wallet) is a type of electronic payment system that provides a user account which can be accessed through mobile applications. People can use it to pay through websites, transfer balance, ...
- 75 marksBuilding CatalogsHideAnswer
What is a catalog in e-commerce application? How can you create catalogs? [5]
A catalog (or product catalog) in an e-commerce application is an organized online list or collection of products available on a company's website. It includes product details and descriptions presented using text and graphics, allowing ...
- 85 marksSecurity Threats in E-commerceHideAnswer
Define malicious code. How the potentially unwanted programs like adware and spyware work? [5]
Malicious code (Malware) includes a variety of threats such as viruses, trojan horses, worms, ransomware, and other harmful programs. It refers to any unwanted file or program that can cause harm to a computer or compromise data stored o...
- 95 marksPricing Models for Online AdvertisementsHideAnswer
Discuss different pricing models for online advertisements. [5]
Online advertising is a core component of the advertising revenue model, where a company that offers content, services, and/or products also provides a forum for advertisements and receives fees from advertisers. Google, for instance, de...
- 105 marksSocial MarketingHideAnswer
How facebook exchanges, reaction buttons and sponsored message are used for social marketing and advertisement. [5]
Facebook is one of the most powerful platforms for social marketing and advertisement. It provides several tools that businesses and marketers use to reach their target audience, build brand awareness, and drive sales. --- Definition: Re...
- 115 marksOn Page SEOHideAnswer
What is Search Engine Optimization (SEO)? How on page SEO can be done? [5]
Search Engine Optimization (SEO) is the process of improving the ranking of the pages with search engines by altering the content and design of the web pages and site. In simple terms, SEO involves a set of techniques and strategies used...
- 125 marksRecommendation SystemsHideAnswer
How content based and collaborative filtering approaches are used for product recommendation in e-commerce? [5]
A recommendation system is a tool that uses algorithms, data analysis, and AI to make recommendations online. These systems predict user interests and recommend product items that might be interesting for them. For example, if a user buy...