Q1
a) Label the following as Target or Tool cybercrime: phishing, hacking, fraud.
Phishing → Tool Cybercrime
Phishing uses deceptive emails, SMS, or fake websites to trick users into revealing personal
data. Here, the computer/internet is used as a tool to commit fraud. For example, a phishing
email pretending to be from a bank requesting login details.
Hacking → Tool Cybercrime
Hacking involves unauthorized access to systems or networks. The attacker uses digital tools
to break security barriers. Example: 2017 Equifax hack where hackers accessed the data of
147 million Americans.
Fraud → Target Cybercrime
Online fraud aims directly at victims’ assets, data, or accounts. The computer or its
resources become the target of exploitation. Example: Credit card cloning, online banking
fraud.
👉 Summary:
Tool crimes → Use computer as a weapon (phishing, hacking).
Target crimes → Attack computer/data directly (fraud).
b) Steps involved in investigating a computer crime scene (Cyber-CSI):
1. Identification – Recognizing suspicious activities such as unusual logins, network spikes, or
unauthorized data transfer.
2. Preservation – Preventing evidence alteration by isolating affected systems, imaging hard
drives, and securing logs.
3. Collection – Gathering evidence like emails, browsing history, malware samples, and devices
while ensuring chain of custody.
4. Examination – Using forensic tools (e.g., EnCase, Autopsy, FTK) to recover hidden, deleted, or
encrypted files.
5. Analysis – Reconstructing the sequence of events, identifying attackers through IP tracking,
and linking evidence to suspects.
6. Presentation – Preparing admissible evidence reports under Section 65B of Indian Evidence
Act. The findings are presented in a clear format for courts.
👉 This systematic approach ensures credibility of digital evidence in cybercrime trials.
Q2
Explain the aims and objectives of IT Act 2000 along with its key features.
The Information Technology (IT) Act, 2000 was India’s first legislation to address issues arising in
cyberspace.
Aims/Objectives:
1. To provide legal recognition to electronic records and digital signatures.
2. To promote e-commerce and e-governance by allowing valid online contracts.
3. To define, regulate, and punish cybercrimes like hacking, identity theft, and
cyberstalking.
4. To establish a framework for secure electronic transactions.
5. To encourage trust in digital platforms for banking, trade, and government services.
Key Features:
o Digital Signatures (Sec. 3–10) → Recognized as equivalent to handwritten signatures.
o Electronic Governance (Sec. 4–10A) → Government forms and contracts can be
digitally signed.
o Cybercrimes and Penalties (Sec. 65–74) → Defines hacking, identity theft, cyber
pornography, and prescribes penalties.
o Intermediary Liability (Sec. 79) → Platforms like Google, Facebook are not liable if
they remove unlawful content promptly.
o Cyber Appellate Tribunal → For cyber disputes.
o Amendments (2008) → Introduced cyber terrorism (Sec. 66F), identity theft,
phishing, and stricter punishments.
👉 The IT Act transformed India’s digital ecosystem, giving legal teeth to fight cybercrimes.
Q3
a) Analyze the challenges of privacy vs. security in cyber law enforcement.
In the digital era, privacy and security often clash.
Privacy Concerns:
o Individuals expect their personal data, communications, and browsing habits to
remain private.
o Over-surveillance by the State (CCTV, digital monitoring) threatens personal
freedom.
o Example: Debate over WhatsApp’s end-to-end encryption.
Security Concerns:
o Governments argue for access to encrypted communication to prevent terrorism,
cyber fraud, and money laundering.
o Example: India demanding access to WhatsApp data in cases of child abuse and
terrorism.
Challenges Faced:
1. Encryption vs. Law Enforcement – Criminals hide behind strong encryption.
2. Jurisdiction Issues – Cybercrimes often cross borders; laws differ from country to
country.
3. Misuse of Power – Excessive surveillance may be misused for political control.
4. Balancing Act – Too much privacy hampers investigations; too much surveillance
violates rights.
👉 Conclusion: The challenge is to strike a balance where individual privacy is respected while
ensuring national security.
b) Grey areas of IT Act with examples:
1. Data Privacy Gaps → No robust data protection law until 2023 (Digital Personal Data
Protection Act). Example: Aadhaar data leaks.
2. Cyberbullying & Revenge Porn → Not explicitly defined under IT Act; often booked under
IPC.
3. Cross-Border Crimes → Indian law struggles to prosecute foreign cybercriminals (e.g.,
Nigerian fraudsters).
4. Outdated Provisions → IT Act does not cover modern threats like ransomware,
cryptocurrency fraud, or deepfake misuse.
5. Intermediary Liability Confusion → Platforms like Twitter/YouTube are caught between free
speech and government takedown orders.
👉 These grey areas demand urgent amendments for stronger cyber governance.
Q4
Judge whether DDoS attacks are more damaging than malware. Justify.
DDoS (Distributed Denial of Service):
o Floods servers with huge traffic until they collapse.
o Example: In 2016, the Mirai botnet DDoS attack shut down Twitter, Netflix, and CNN.
o Losses: Millions lost due to service downtime, reputational damage.
Malware Attacks:
o Malicious software that can spy, steal, or lock data (viruses, ransomware, Trojans).
o Example: WannaCry ransomware (2017) hit 200,000 computers globally, including
Indian banks and hospitals.
o Losses: Data theft, financial extortion, permanent corruption of systems.
Comparison:
o DDoS → Disruptive, but usually temporary (services can be restored).
o Malware → Permanent, long-term, and harder to recover from.
👉 Conclusion:
Malware is more damaging overall because it causes lasting data loss and financial harm. However,
for critical services like airlines, hospitals, and stock markets, even a short DDoS attack can be
catastrophic.
Q5
a) Construct a case study comparing Indian and global cybercrime enforcement approaches.
India (IT Act 2000 & 2008 Amendment):
o Strengths: Recognized e-signatures, created cyber police cells, CERT-In for incident
response.
o Weaknesses: Poor international coordination, outdated provisions, weaker privacy
protections.
Global Approaches:
o USA (Computer Fraud and Abuse Act, 1986): Very strict against hacking, credit card
fraud. FBI Cyber Division is proactive.
o EU (GDPR, 2018): Strongest privacy law with fines up to €20 million or 4% of
turnover.
o UK (Computer Misuse Act, 1990): Covers hacking, unauthorized access, malware.
o Interpol Cybercrime Centre: Promotes global cooperation against cross-border
attacks.
👉 Observation:
India focuses more on reactive investigation, while global models focus on data protection, strict
penalties, and international cooperation.
b) Develop a case study where IT Act provisions successfully resolve a cyber-offence.
Case: [Link] MMS Scandal (2004)
o Incident: An obscene MMS clip was uploaded for sale on [Link].
o Action: CEO Avnish Bajaj was booked under Section 67 (publishing obscene content)
of IT Act.
o Court Ruling: Intermediary ([Link]) not directly liable if it removes content
swiftly.
o Impact: Established “Intermediary Liability” under Section 79 IT Act.
Case: Bank Fraud Cases (2018 onwards)
o Many online banking frauds in India have been prosecuted using Sections 66C
(identity theft) and 66D (cheating by impersonation).
o Example: In 2019, Pune Police arrested a group for OTP fraud using these provisions.
👉 These cases show how IT Act is used in real-life enforcement to bring cybercriminals to justice.