Question 1 — Multiple Choice
5 points · 0.5 eachQuestion 2 — Network Security & Safety-Critical Systems
5 points
Part A (1/3) — Name and describe one type of network security
attack, with an example.
Aim for a definition plus a concrete real-world example.
Answer Key
Any of the three below (with a valid example) earns credit:
- Social Engineering — exploiting human trust to obtain information directly from victims. Example: phishing emails or fake login pages.
- Password Attacks — attempting to crack account or network passwords. Example: a dictionary attack that automates repeated login guesses.
- Man-in-the-Middle Attack — intercepting and altering traffic between two communicating nodes. Example: a hacker rerouting network traffic through their own machine.
Part A (2/3) — Name and describe a second, different type of network
security attack, with an example.
Answer Key
Same three options as above — must be different from your first
answer: Social Engineering, Password Attacks, or Man-in-the-Middle
Attack.
Part A (3/3) — Name and describe a third, different type of network
security attack, with an example.
Answer Key
The complete set: Social Engineering (e.g. phishing), Password
Attacks (e.g. dictionary attack), Man-in-the-Middle Attack (e.g.
traffic rerouting).
Part B — List four methods for developing safety-critical systems to
overcome potential issues.
List format is fine — one line per method.
Answer Key
- Implement a Comprehensive Security Policy
- Enforce Checks and Balances via Staffing
- Utilize Technical Authentication Controls
- Conduct Regular Audits and Logging
Question 3 — The Whistleblower's Dilemma
5 pointsScenario: You are a software engineer at a major tech firm. You discover a hidden "backdoor" in a new application that collects sensitive user data without informed consent. You signed a strict NDA as part of your employment contract.
Part A (1 pt) — According to Kantianism, what is the primary
consideration when deciding whether to keep the NDA or report the
company?
Answer Key
The primary consideration is your
moral duty to universalize your actions, not the consequences
(such as getting fired or losing your job). Kantianism is
duty-based, not outcome-based.
Part B (2 pts) — Explain how the Categorical Imperative (2nd
Formulation) applies to this scenario.
Answer Key
The 2nd formulation states you should
treat others as ends, not merely as a means. By deceiving
users to collect their data, the company uses them merely as a means
to profit. You have a duty to respect users' rationality/autonomy,
which outweighs the NDA's secrecy requirement.
Part C (2 pts) — If Rule Utilitarianism were applied, how would the
conclusion differ from Act Utilitarianism?
Answer Key
Act Utilitarianism might justify keeping the secret if the
immediate good (job security, company profit) outweighs the harm in
this single case. Rule Utilitarianism instead evaluates the
long-term consequences of a general rule like "employees should
never report unethical company behavior" — if everyone followed it,
societal trust in technology would collapse, causing greater
long-term harm. So a Rule Utilitarian would likely support reporting
the breach.
0 / 15
Review the answer key on each question above for anything you missed.