a) Neural Network
• Neural networks are brain-inspired machine learning models that mimic human learning
behavior.
• Comprise input, hidden, and output layers; hidden layers transform input for meaningful
output.
• Ideal for identifying complex patterns beyond human programming capabilities.
• The concept dates back to the 1940s but gained traction with backpropagation, which adjusts
weights based on errors.
• Advancement through deep learning: multilayer networks extract hierarchical features for better
accuracy and learning.
b) Duties of Certifying Authorities
• Must follow legal procedures in issuing digital signatures.
• Ensure all employees comply with the law and digital signature standards.
• Required to display their license publicly and surrender it after suspension or cancellation.
• Must disclose issued digital certificates and maintain transparency.
• (Note: Ideally, should also manage certificate revocation and maintain a public repository – not
explicitly stated in original.)
c) B2C e-Commerce
• Business-to-Consumer (B2C) e-commerce involves businesses directly selling goods/services to
end customers, usually online.
• Transactions occur on the business’s website, where customers select, order, and pay for
products.
• The business processes the order and delivers the product directly to the consumer without
intermediaries.
• Common examples: Amazon, Daraz, Flipkart.
d) Request for Proposal (RFP)
• An RFP is a formal document issued by an organization to invite bids for systems, services, or
equipment.
• Contains technical specifications, contract terms, payment schedules, and other procurement
details.
• Outlines the submission, evaluation, and selection process for bids.
• The RFP becomes the foundation of the contract between the organization and the chosen
supplier.
e) Challenges of Using Outsourcing for IT Operations
• Confidentiality risks arise from sharing sensitive data with third-party vendors.
• Quality may suffer if the outsourced team lacks proper training or domain knowledge.
• Difficult to find skilled outsourcing partners for niche or specialized IT operations.
• Replacing vendors can be complex due to transition difficulties, including retraining and system
handovers.
• Business operations are vulnerable if the vendor shuts down, faces legal issues, or dissolves.
a) Types of E-Commerce
• Business-to-Business (B2B)
o Involves transactions between companies, such as manufacturers and wholesalers, or
wholesalers and retailers.
o Often deals with bulk sales, supply chains, and long-term contracts.
• Business-to-Consumer (B2C)
o Refers to businesses selling directly to consumers via digital platforms.
o Includes product browsing, online orders, and home delivery.
o Examples: [Link], [Link]
• Consumer-to-Consumer (C2C)
o Consumers sell used goods or services to other consumers using a third-party platform.
o Platforms facilitate the transaction and provide trust mechanisms.
o Example: [Link]
b) Duties of Certifying Authorities
• Must follow prescribed procedures related to issuance of digital signatures.
• Ensure that employees comply with applicable laws and guidelines.
• Must display license publicly and surrender it if suspended or cancelled.
• Required to disclose issued digital signature certificates.
c) Genetic Algorithm
• Mimics natural selection and mutation to find optimized solutions.
• Starts with a random population of possible solutions.
• Evaluates fitness of each solution to determine suitability.
• Combines and mutates best solutions to create next generation.
• Process is repeated iteratively until the most optimal solution is found.
d) IT Governance
• A system of tools, policies, and processes aligning IT services with business goals.
• Ensures IT delivers value, supports business strategy, and manages risk.
• Helps evaluate IT performance in the context of organizational growth.
• Uses frameworks like COBIT for compliance, efficiency, and business benefits.
• Ensures controlled, effective, and accountable IT operations.
e) Vulnerability Assessment and Penetration Testing (VAPT)
• Vulnerability Assessment (VA):
o Identifies, categorizes, and prioritizes security weaknesses in systems and software.
o Detects flaws but does not exploit them.
• Penetration Testing (PT):
o Involves actively exploiting vulnerabilities to simulate real-world attacks.
o Helps assess how attackers might gain unauthorized access.
• Combined (VAPT) approach offers both detection and exploitation insights, improving overall
system security.
a) Disadvantages of IT Outsourcing
• Loss of Control: Outsourcing transfers control of IT functions to third-party vendors, which can
risk internal oversight.
• Dependency: Over-reliance on external service providers can be risky if they underperform.
• Hidden Costs: Unexpected costs such as contract termination fees or scope changes may arise.
• Long Distance Issues: Outsourcing to distant countries may create time zone and communication
challenges, increasing costs and delays.
b) Cloud Computing
• Definition: Delivery of hosted services (e.g., VM, storage, apps) over the internet, avoiding in-
house infrastructure.
• Key Benefits:
o Self-Service Provisioning: Users can access resources on demand.
o Elasticity: Resources can be scaled up/down as needed.
o Pay-per-Use: Charges based on actual usage.
o Workload Resilience: Redundant systems ensure continuity across global regions.
o Migration Flexibility: Easy movement of workloads across platforms for efficiency.
c) High Availability Planning
• Definition: Planning to ensure business continuity during system failures, disasters, or outages.
• Key Components:
o Infrastructure Design: Server, storage, and network redundancy.
o Disaster Recovery: Backup sites and failover procedures.
o Action Plan: Step-by-step recovery, including who is responsible for what.
o Geographical Redundancy: Ensures services can resume from alternate locations.
d) B2C e-Commerce
• Definition: Direct online selling of goods/services from business to end consumers.
• Process:
o Consumers access business websites, select products, place orders.
o Businesses receive orders and dispatch goods directly.
• Examples: Online retail stores like Daraz, Jeevee, etc.
e) Categories of Application Controls
• Objective: Ensure data input, processing, and output are accurate, complete, and authorized.
• Types:
o Input Controls: Validate integrity and validity of entered data.
o Processing Controls: Ensure accuracy and completeness during processing.
o Output Controls: Confirm output matches expected results.
o Integrity Controls: Monitor stored/processed data for consistency.
o Management Trail: Track transaction lifecycle and assess control effectiveness.
a) High Availability Computing
• Ensures continuous operation of business-critical systems despite disruptions (natural or man-
made).
• Achieved through hardware and software redundancy like:
o Clustered, multi-node setups across geographic locations
o Automatic failover, data replication (RAID, mirroring)
• Supports 24/7 availability by avoiding single points of failure.
• Redundant resources include:
o Power supplies, UPS, diesel generators
o Cooling systems and multiple network connections
b) PERT (Program Evaluation Review Technique)
• A project management tool used to estimate time and resources for completing a project.
• Visualized using charts with nodes and vectors to show tasks and dependencies.
• Helps in identifying:
o Task sequencing and dependencies
o Critical path (minimum time to complete project)
• Enables project managers to estimate time, resources, and budget.
• Useful for identifying parallel and dependent tasks.
c) Distinction between Network Access Control and Application Control
• Network Access Control (NAC)
o Controls external access to systems through network (intranet/internet).
o Implemented via access policies, firewalls, secure credentials.
o Focused on controlling who connects and what data flows through the network.
• Application Control
o Restricts which applications users can access and use.
o Example: Limiting use of social media or allowing only specific software (e.g. CRM,
email client).
o Ensures compliance with security standards, licenses, and productivity goals.
d) Importance of IS Audit
• IS Audit evaluates the health, security, and effectiveness of IT systems.
• Ensures systems are used by the right people with proper privileges.
• Identifies strengths and weaknesses in systems and processes.
• Helps management make informed decisions to improve IT performance and governance.
• Vital for maintaining control, security, and strategic alignment of IT with business goals.
e) Benefits of Personalization in Modern E-Commerce
• Personalization uses user data, behavior, and preferences to tailor offerings.
• Driven by social media, mobile tech, consumer profiling, and AI.
• Helps push relevant products/services, improving customer satisfaction.
• Increases chances of conversion and customer retention.
• Saves time by filtering out irrelevant content, benefiting both user and business.
a) Virtualization and Its Advantages
• Virtualization: Creating virtual versions of computing resources (e.g., servers, operating
systems, networks).
• Types: Network, Server, Desktop, Hardware, Software, Storage virtualization.
• Advantages:
o Improves resource performance and efficiency (e.g., CPU virtualization).
o Enhances security by isolating virtual machines (VMs).
o Reduces hardware costs and requires less physical infrastructure.
o Increases reliability with better disaster recovery, backup, and data retrieval.
b) Electronic Payment
• Definition: Digital payment mechanism eliminating the need for cash handling.
• Process: Money stored in digital wallets or bank accounts is transferred electronically during
transactions.
• Importance: Key enabler of e-commerce and online trade growth.
• Benefits:
o Faster and more accurate transactions.
o Transparency and ease in record-keeping.
o Simplifies auditing, taxation, and regulatory compliance.
c) Business Applications of Expert Systems
• Used in:
o Decision management.
o Diagnostic and troubleshooting.
o Maintenance scheduling.
o Design and configuration.
o Selection and classification tasks.
o Process monitoring and control.
d) CASE Tools
• Definition: Computer Assisted System Engineering tools automate system development
processes.
• Functions:
o Reduce development time, cost, and errors.
o Facilitate documentation, team coordination, and communication.
o Provide graphics for charts, screen/report generators, code and documentation generation.
• Benefits: Enforce standards, improve user-technical communication, automate coding, testing,
and rollout.
e) High Availability Planning
• Purpose: Ensure systems and services remain functional and accessible even during disasters or
outages.
• Techniques:
o Redundancy through multiple identical installations, often in different locations.
o Network and power system redundancies.
o Server replication and clustering with automatic switchover for failover.
• Goal: Minimize downtime caused by power outages, network failures, or other disruptions.
a) User Interface Design
• Focuses on designing systems for users with varying IT skills.
• Key for usability and user acceptance; complex interfaces cause resistance.
• Ensures ease, intuitiveness, accuracy, consistency, and data integrity.
• Considers time efficiency for data input and retrieval.
• Involves IT, marketing, and design teams to enhance user experience.
b) General Attributes of Information System Security
• Confidentiality: Only authorized users can access data; unauthorized access denied.
• Integrity: Data remains accurate and unaltered throughout its lifecycle.
• Availability & Access Control: System and data available when needed; right access given to
the right users.
• Non-Repudiation: Prevents denial of actions, ensuring accountability and rejecting false claims.
c) Electronic Fund Transfer (EFT)
• Digital transfer of money between bank accounts without paper documents or bank employees.
• Simple, fast, and direct method replacing paper checks.
• Widely used in business transactions due to cost-effectiveness and speed.
d) e-Governance
• Delivery of government services using IT across government-to-people (G2P), government-to-
business (G2B), government-to-employee (G2E), and government-to-government (G2G).
• Depends on IT infrastructure, internet/mobile coverage, and user capability.
• Improves service efficiency, transparency, and reduces revenue leakage.
• In Nepal, examples include the Nagarik App for service applications and payments.
• Still evolving due to infrastructure and adoption challenges.
e) Liabilities of Network Service Provider (Electronic Transaction Act, 2063)
• Liabilities as per subscriber agreements and provider licenses.
• Other prescribed liabilities by law.
• Not liable for breaches caused by third-party data using their network service or connectivity.
a) Fuzzy Logic
• Deals with reasoning that is approximate rather than fixed and exact.
• Unlike Boolean logic (true = 1, false = 0), fuzzy logic allows intermediate truth values (partially
true/false).
• Useful for handling uncertainty and vagueness in real-world scenarios.
• Applied in controlling machines and consumer products.
• Provides acceptable (not always precise) reasoning useful in engineering.
b) Functions, Duties and Powers of Controller under Electronic Transaction Act, 2063
• Appointed by Government of Nepal with qualified personnel and support staff.
• Issues licenses to Certifying Authorities (CAs).
• Supervises and monitors Certifying Authorities’ activities.
• Sets standards for digital signature verification by CAs.
• Specifies operational conditions and certificate formats for CAs.
• Maintains public database of certified information.
• Performs other prescribed functions under the Act.
c) Customization of Website
• Tailors user experience based on visitor’s past behavior, location, and preferences.
• Aims to increase customer satisfaction, visit duration, and conversion rates.
• Personalization mimics in-person retail experience online.
• Helps businesses retain visitors, boost sales, and enhance brand reputation.
• Increasingly important with growth of online retail.
d) C2C E-commerce
• Consumer-to-consumer transactions facilitated via electronic platforms.
• Transactions occur directly between individuals using third-party platforms (e.g., Facebook).
• Third parties (digital wallets, courier services) provide support but do not engage in the sale itself.
• Growth driven by social media, digital payments, and delivery services.
• Enables peer-to-peer buying and selling without organizational involvement.
e) XML Standard for Digital Data Exchange
• Extensible Markup Language (XML) is a universal standard for data exchange.
• Enables different systems to communicate via APIs with a clear, structured format.
• Supports flexible, secure data exchange over public networks.
• Compatible with many devices, including handheld and portable ones.
• XML schemas define standardized data structures for interoperability.
• Extensible design allows creation of new tags and data flows.
• Widely adopted for modern cross-platform data exchange.
a) Information System Audit
• Examines management controls within IT infrastructure.
• Evaluates if systems safeguard assets, maintain data integrity, and operate effectively.
• Often part of financial or internal audits.
• Focuses on system availability, security/confidentiality, and data integrity.
• Ensures controls are effective, prevents breaches, and supports organizational goals.
• Important for reducing risks like data loss, tampering, service disruption, and poor IT
management.
b) Business to Customer (B2C) e-Commerce
• Online business transactions between companies and individual customers.
• Businesses provide product/service info on websites.
• Customers browse, order, pay, and receive products remotely.
• Enables convenient shopping without physical store visits.
• Common in retail, increasing accessibility for customers.
c) Mobile Computing
• Technology enabling data, voice, and video transmission via wireless devices without fixed
connections.
• Key components:
o Mobile Communication: Wireless networks, protocols, data formats, bandwidths.
o Mobile Hardware: Devices like smartphones, laptops with network connectivity.
o Mobile Software: Operating systems (Android, iOS, Windows, Linux), and applications
running on devices.
• Supports seamless, on-the-go computing and communication.
d) Dimensions of Feasibility Study of Information System
• Technical Feasibility: Availability and capability of technology, system scalability, security, and
reliability.
• Economic Feasibility: Cost-benefit analysis including technology costs and expected savings.
• Operational Feasibility: Practicality of system usage within the organization (implied in general
feasibility).
• Schedule Feasibility: Time required to develop and implement the system; timely service
delivery.
• Legal Feasibility: Compliance with laws, regulations, and contractual obligations.
e) Importance of Patents for IT Industry
• Protect intellectual property of inventions and innovations from unauthorized copying.
• Ensure creators receive recognition and rewards for their work.
• Crucial in IT due to ease of copying technology and ideas.
• Patents encourage ongoing innovation by securing legal rights for creators.
• Acts as a catalyst for continued development and improvement in IT and other industries.
a) Executive Information System (EIS)
• Supports top-level executives in long-term policy, strategy, and decision-making.
• Focuses on unstructured decision processes and organizational goals.
• Provides summary reports with ability to drill down into detailed data.
• Enables analysis of business factors affecting performance (e.g., profit changes based on pricing
or incentives).
• Integrates data inputs from operational, supervisory, and middle management systems.
b) Strategic E-Business Planning
• Evaluates benefits and risks of adopting e-business strategies for competitive advantage.
• Uses models to guide planning:
o Competitive Forces Model: competitors, customers, suppliers, new entrants, substitutes.
o Competitive Strategies Model: cost leadership, differentiation, growth, innovation,
alliances.
o Value Chain Model: primary and support activities adding value to products/services.
o Strategic Opportunities Matrix: assesses risk and payoff of e-business initiatives.
c) Business Continuity Plan (BCP)
• Aims to prevent and recover systems from potential threats/disasters.
• Ensures quick system functionality post-disaster (natural or man-made risks).
• Involves risk identification, impact analysis, safeguards implementation, and rigorous testing.
• Integral to organizational risk management strategy.
d) Software as a Service (SaaS)
• Delivers software applications over the Internet as a service.
• Eliminates need for installation or maintenance on user devices.
• Provider manages security, availability, and performance.
• Can be hosted by independent vendors or software vendors themselves (e.g., Microsoft).
• Used by businesses and individuals for various applications, from entertainment (Netflix) to
advanced IT tools.
e) Disk Mirroring (RAID 1)
• Data replication on two or more disks for high availability and performance.
• Read operations are fast as data can be read simultaneously from multiple disks.
• Write operations slower as data must be written twice.
• Provides instant failover if one disk fails, ensuring continuous data access.
• Part of RAID (Redundant Array of Independent Disks) technology; RAID 1 prioritizes reliability.
• Other RAID levels include RAID 0 (fastest) and RAID 5 (balance of speed and reliability).