ETHC303 · Section 81 · Term 253 Major Exam Practice
60:00
Prince Sultan University — CCIS · Closed Book Practice Run

Ethical and Social Aspects of Computing

Self-graded practice exam. Answer all three questions, then submit for instant grading, keyword feedback on written responses, and a full answer key.

Total: 15 points Time limit: 60 minutes Questions: 3 Format: MCQ + Written

Question 1 — Multiple Choice

5 points · 0.5 each

Question 2 — Network Security & Safety-Critical Systems

5 points
Part A (1/3) — Name and describe one type of network security attack, with an example.
Aim for a definition plus a concrete real-world example.
Answer Key
Any of the three below (with a valid example) earns credit:
  • Social Engineering — exploiting human trust to obtain information directly from victims. Example: phishing emails or fake login pages.
  • Password Attacks — attempting to crack account or network passwords. Example: a dictionary attack that automates repeated login guesses.
  • Man-in-the-Middle Attack — intercepting and altering traffic between two communicating nodes. Example: a hacker rerouting network traffic through their own machine.
Part A (2/3) — Name and describe a second, different type of network security attack, with an example.
Answer Key
Same three options as above — must be different from your first answer: Social Engineering, Password Attacks, or Man-in-the-Middle Attack.
Part A (3/3) — Name and describe a third, different type of network security attack, with an example.
Answer Key
The complete set: Social Engineering (e.g. phishing), Password Attacks (e.g. dictionary attack), Man-in-the-Middle Attack (e.g. traffic rerouting).
Part B — List four methods for developing safety-critical systems to overcome potential issues.
List format is fine — one line per method.
Answer Key
  1. Implement a Comprehensive Security Policy
  2. Enforce Checks and Balances via Staffing
  3. Utilize Technical Authentication Controls
  4. Conduct Regular Audits and Logging

Question 3 — The Whistleblower's Dilemma

5 points

Scenario: You are a software engineer at a major tech firm. You discover a hidden "backdoor" in a new application that collects sensitive user data without informed consent. You signed a strict NDA as part of your employment contract.

Part A (1 pt) — According to Kantianism, what is the primary consideration when deciding whether to keep the NDA or report the company?
Answer Key
The primary consideration is your moral duty to universalize your actions, not the consequences (such as getting fired or losing your job). Kantianism is duty-based, not outcome-based.
Part B (2 pts) — Explain how the Categorical Imperative (2nd Formulation) applies to this scenario.
Answer Key
The 2nd formulation states you should treat others as ends, not merely as a means. By deceiving users to collect their data, the company uses them merely as a means to profit. You have a duty to respect users' rationality/autonomy, which outweighs the NDA's secrecy requirement.
Part C (2 pts) — If Rule Utilitarianism were applied, how would the conclusion differ from Act Utilitarianism?
Answer Key
Act Utilitarianism might justify keeping the secret if the immediate good (job security, company profit) outweighs the harm in this single case. Rule Utilitarianism instead evaluates the long-term consequences of a general rule like "employees should never report unethical company behavior" — if everyone followed it, societal trust in technology would collapse, causing greater long-term harm. So a Rule Utilitarian would likely support reporting the breach.
0 / 15
Review the answer key on each question above for anything you missed.