a) Neural Network
Neural networks are brain-inspired machine learning models that mimic human learning
behavior.
Comprise input, hidden, and output layers; hidden layers transform input for meaningful
output.
Ideal for identifying complex patterns beyond human programming capabilities.
The concept dates back to the 1940s but gained traction with backpropagation, which adjusts
weights based on errors.
Advancement through deep learning: multilayer networks extract hierarchical features for better
accuracy and learning.
b) Duties of Certifying Authorities
Must follow legal procedures in issuing digital signatures.
Ensure all employees comply with the law and digital signature standards.
Required to display their license publicly and surrender it after suspension or cancellation.
Must disclose issued digital certificates and maintain transparency.
(Note: Ideally, should also manage certificate revocation and maintain a public repository – not
explicitly stated in original.)
c) B2C e-Commerce
Business-to-Consumer (B2C) e-commerce involves businesses directly selling goods/services to
end customers, usually online.
Transactions occur on the business’s website, where customers select, order, and pay for
products.
The business processes the order and delivers the product directly to the consumer without
intermediaries.
Common examples: Amazon, Daraz, Flipkart.
d) Request for Proposal (RFP)
An RFP is a formal document issued by an organization to invite bids for systems, services, or
equipment.
Contains technical specifications, contract terms, payment schedules, and other procurement
details.
Outlines the submission, evaluation, and selection process for bids.
The RFP becomes the foundation of the contract between the organization and the chosen
supplier.
e) Challenges of Using Outsourcing for IT Operations
Confidentiality risks arise from sharing sensitive data with third-party vendors.
Quality may suffer if the outsourced team lacks proper training or domain knowledge.
Difficult to find skilled outsourcing partners for niche or specialized IT operations.
Replacing vendors can be complex due to transition difficulties, including retraining and system
handovers.
Business operations are vulnerable if the vendor shuts down, faces legal issues, or dissolves.
a) Types of E-Commerce
Business-to-Business (B2B)
o Involves transactions between companies, such as manufacturers and wholesalers, or
wholesalers and retailers.
o Often deals with bulk sales, supply chains, and long-term contracts.
Business-to-Consumer (B2C)
o Refers to businesses selling directly to consumers via digital platforms.
o Includes product browsing, online orders, and home delivery.
o Examples: [Link], [Link]
Consumer-to-Consumer (C2C)
o Consumers sell used goods or services to other consumers using a third-party platform.
o Platforms facilitate the transaction and provide trust mechanisms.
o Example: [Link]
b) Duties of Certifying Authorities
Must follow prescribed procedures related to issuance of digital signatures.
Ensure that employees comply with applicable laws and guidelines.
Must display license publicly and surrender it if suspended or cancelled.
Required to disclose issued digital signature certificates.
c) Genetic Algorithm
Mimics natural selection and mutation to find optimized solutions.
Starts with a random population of possible solutions.
Evaluates fitness of each solution to determine suitability.
Combines and mutates best solutions to create next generation.
Process is repeated iteratively until the most optimal solution is found.
d) IT Governance
A system of tools, policies, and processes aligning IT services with business goals.
Ensures IT delivers value, supports business strategy, and manages risk.
Helps evaluate IT performance in the context of organizational growth.
Uses frameworks like COBIT for compliance, efficiency, and business benefits.
Ensures controlled, effective, and accountable IT operations.
e) Vulnerability Assessment and Penetration Testing (VAPT)
Vulnerability Assessment (VA):
o Identifies, categorizes, and prioritizes security weaknesses in systems and software.
o Detects flaws but does not exploit them.
Penetration Testing (PT):
o Involves actively exploiting vulnerabilities to simulate real-world attacks.
o Helps assess how attackers might gain unauthorized access.
Combined (VAPT) approach offers both detection and exploitation insights, improving overall
system security.
a) Disadvantages of IT Outsourcing
Loss of Control: Outsourcing transfers control of IT functions to third-party vendors, which can
risk internal oversight.
Dependency: Over-reliance on external service providers can be risky if they underperform.
Hidden Costs: Unexpected costs such as contract termination fees or scope changes may arise.
Long Distance Issues: Outsourcing to distant countries may create time zone and communication
challenges, increasing costs and delays.
b) Cloud Computing
Definition: Delivery of hosted services (e.g., VM, storage, apps) over the internet, avoiding in-
house infrastructure.
Key Benefits:
o Self-Service Provisioning: Users can access resources on demand.
o Elasticity: Resources can be scaled up/down as needed.
o Pay-per-Use: Charges based on actual usage.
o Workload Resilience: Redundant systems ensure continuity across global regions.
o Migration Flexibility: Easy movement of workloads across platforms for efficiency.
c) High Availability Planning
Definition: Planning to ensure business continuity during system failures, disasters, or outages.
Key Components:
o Infrastructure Design: Server, storage, and network redundancy.
o Disaster Recovery: Backup sites and failover procedures.
o Action Plan: Step-by-step recovery, including who is responsible for what.
o Geographical Redundancy: Ensures services can resume from alternate locations.
d) B2C e-Commerce
Definition: Direct online selling of goods/services from business to end consumers.
Process:
o Consumers access business websites, select products, place orders.
o Businesses receive orders and dispatch goods directly.
Examples: Online retail stores like Daraz, Jeevee, etc.
e) Categories of Application Controls
Objective: Ensure data input, processing, and output are accurate, complete, and authorized.
Types:
o Input Controls: Validate integrity and validity of entered data.
o Processing Controls: Ensure accuracy and completeness during processing.
o Output Controls: Confirm output matches expected results.
o Integrity Controls: Monitor stored/processed data for consistency.
o Management Trail: Track transaction lifecycle and assess control effectiveness.
a) High Availability Computing
Ensures continuous operation of business-critical systems despite disruptions (natural or man-
made).
Achieved through hardware and software redundancy like:
o Clustered, multi-node setups across geographic locations
o Automatic failover, data replication (RAID, mirroring)
Supports 24/7 availability by avoiding single points of failure.
Redundant resources include:
o Power supplies, UPS, diesel generators
o Cooling systems and multiple network connections
b) PERT (Program Evaluation Review Technique)
A project management tool used to estimate time and resources for completing a project.
Visualized using charts with nodes and vectors to show tasks and dependencies.
Helps in identifying:
o Task sequencing and dependencies
o Critical path (minimum time to complete project)
Enables project managers to estimate time, resources, and budget.
Useful for identifying parallel and dependent tasks.
c) Distinction between Network Access Control and Application Control
Network Access Control (NAC)
o Controls external access to systems through network (intranet/internet).
o Implemented via access policies, firewalls, secure credentials.
o Focused on controlling who connects and what data flows through the network.
Application Control
o Restricts which applications users can access and use.
o Example: Limiting use of social media or allowing only specific software (e.g. CRM,
email client).
o Ensures compliance with security standards, licenses, and productivity goals.
d) Importance of IS Audit
IS Audit evaluates the health, security, and effectiveness of IT systems.
Ensures systems are used by the right people with proper privileges.
Identifies strengths and weaknesses in systems and processes.
Helps management make informed decisions to improve IT performance and governance.
Vital for maintaining control, security, and strategic alignment of IT with business goals.
e) Benefits of Personalization in Modern E-Commerce
Personalization uses user data, behavior, and preferences to tailor offerings.
Driven by social media, mobile tech, consumer profiling, and AI.
Helps push relevant products/services, improving customer satisfaction.
Increases chances of conversion and customer retention.
Saves time by filtering out irrelevant content, benefiting both user and business.
a) Virtualization and Its Advantages
Virtualization: Creating virtual versions of computing resources (e.g., servers, operating
systems, networks).
Types: Network, Server, Desktop, Hardware, Software, Storage virtualization.
Advantages:
o Improves resource performance and efficiency (e.g., CPU virtualization).
o Enhances security by isolating virtual machines (VMs).
o Reduces hardware costs and requires less physical infrastructure.
o Increases reliability with better disaster recovery, backup, and data retrieval.
b) Electronic Payment
Definition: Digital payment mechanism eliminating the need for cash handling.
Process: Money stored in digital wallets or bank accounts is transferred electronically during
transactions.
Importance: Key enabler of e-commerce and online trade growth.
Benefits:
o Faster and more accurate transactions.
o Transparency and ease in record-keeping.
o Simplifies auditing, taxation, and regulatory compliance.
c) Business Applications of Expert Systems
Used in:
o Decision management.
o Diagnostic and troubleshooting.
o Maintenance scheduling.
o Design and configuration.
o Selection and classification tasks.
o Process monitoring and control.
d) CASE Tools
Definition: Computer Assisted System Engineering tools automate system development
processes.
Functions:
o Reduce development time, cost, and errors.
o Facilitate documentation, team coordination, and communication.
o Provide graphics for charts, screen/report generators, code and documentation generation.
Benefits: Enforce standards, improve user-technical communication, automate coding, testing,
and rollout.
e) High Availability Planning
Purpose: Ensure systems and services remain functional and accessible even during disasters or
outages.
Techniques:
o Redundancy through multiple identical installations, often in different locations.
o Network and power system redundancies.
o Server replication and clustering with automatic switchover for failover.
Goal: Minimize downtime caused by power outages, network failures, or other disruptions.
a) User Interface Design
Focuses on designing systems for users with varying IT skills.
Key for usability and user acceptance; complex interfaces cause resistance.
Ensures ease, intuitiveness, accuracy, consistency, and data integrity.
Considers time efficiency for data input and retrieval.
Involves IT, marketing, and design teams to enhance user experience.
b) General Attributes of Information System Security
Confidentiality: Only authorized users can access data; unauthorized access denied.
Integrity: Data remains accurate and unaltered throughout its lifecycle.
Availability & Access Control: System and data available when needed; right access given to
the right users.
Non-Repudiation: Prevents denial of actions, ensuring accountability and rejecting false claims.
c) Electronic Fund Transfer (EFT)
Digital transfer of money between bank accounts without paper documents or bank employees.
Simple, fast, and direct method replacing paper checks.
Widely used in business transactions due to cost-effectiveness and speed.
d) e-Governance
Delivery of government services using IT across government-to-people (G2P), government-to-
business (G2B), government-to-employee (G2E), and government-to-government (G2G).
Depends on IT infrastructure, internet/mobile coverage, and user capability.
Improves service efficiency, transparency, and reduces revenue leakage.
In Nepal, examples include the Nagarik App for service applications and payments.
Still evolving due to infrastructure and adoption challenges.
e) Liabilities of Network Service Provider (Electronic Transaction Act, 2063)
Liabilities as per subscriber agreements and provider licenses.
Other prescribed liabilities by law.
Not liable for breaches caused by third-party data using their network service or connectivity.
a) Fuzzy Logic
Deals with reasoning that is approximate rather than fixed and exact.
Unlike Boolean logic (true = 1, false = 0), fuzzy logic allows intermediate truth values (partially
true/false).
Useful for handling uncertainty and vagueness in real-world scenarios.
Applied in controlling machines and consumer products.
Provides acceptable (not always precise) reasoning useful in engineering.
b) Functions, Duties and Powers of Controller under Electronic Transaction Act, 2063
Appointed by Government of Nepal with qualified personnel and support staff.
Issues licenses to Certifying Authorities (CAs).
Supervises and monitors Certifying Authorities’ activities.
Sets standards for digital signature verification by CAs.
Specifies operational conditions and certificate formats for CAs.
Maintains public database of certified information.
Performs other prescribed functions under the Act.
c) Customization of Website
Tailors user experience based on visitor’s past behavior, location, and preferences.
Aims to increase customer satisfaction, visit duration, and conversion rates.
Personalization mimics in-person retail experience online.
Helps businesses retain visitors, boost sales, and enhance brand reputation.
Increasingly important with growth of online retail.
d) C2C E-commerce
Consumer-to-consumer transactions facilitated via electronic platforms.
Transactions occur directly between individuals using third-party platforms (e.g., Facebook).
Third parties (digital wallets, courier services) provide support but do not engage in the sale itself.
Growth driven by social media, digital payments, and delivery services.
Enables peer-to-peer buying and selling without organizational involvement.
e) XML Standard for Digital Data Exchange
Extensible Markup Language (XML) is a universal standard for data exchange.
Enables different systems to communicate via APIs with a clear, structured format.
Supports flexible, secure data exchange over public networks.
Compatible with many devices, including handheld and portable ones.
XML schemas define standardized data structures for interoperability.
Extensible design allows creation of new tags and data flows.
Widely adopted for modern cross-platform data exchange.
a) Information System Audit
Examines management controls within IT infrastructure.
Evaluates if systems safeguard assets, maintain data integrity, and operate effectively.
Often part of financial or internal audits.
Focuses on system availability, security/confidentiality, and data integrity.
Ensures controls are effective, prevents breaches, and supports organizational goals.
Important for reducing risks like data loss, tampering, service disruption, and poor IT
management.
b) Business to Customer (B2C) e-Commerce
Online business transactions between companies and individual customers.
Businesses provide product/service info on websites.
Customers browse, order, pay, and receive products remotely.
Enables convenient shopping without physical store visits.
Common in retail, increasing accessibility for customers.
c) Mobile Computing
Technology enabling data, voice, and video transmission via wireless devices without fixed
connections.
Key components:
o Mobile Communication: Wireless networks, protocols, data formats, bandwidths.
o Mobile Hardware: Devices like smartphones, laptops with network connectivity.
o Mobile Software: Operating systems (Android, iOS, Windows, Linux), and applications
running on devices.
Supports seamless, on-the-go computing and communication.
d) Dimensions of Feasibility Study of Information System
Technical Feasibility: Availability and capability of technology, system scalability, security, and
reliability.
Economic Feasibility: Cost-benefit analysis including technology costs and expected savings.
Operational Feasibility: Practicality of system usage within the organization (implied in general
feasibility).
Schedule Feasibility: Time required to develop and implement the system; timely service
delivery.
Legal Feasibility: Compliance with laws, regulations, and contractual obligations.
e) Importance of Patents for IT Industry
Protect intellectual property of inventions and innovations from unauthorized copying.
Ensure creators receive recognition and rewards for their work.
Crucial in IT due to ease of copying technology and ideas.
Patents encourage ongoing innovation by securing legal rights for creators.
Acts as a catalyst for continued development and improvement in IT and other industries.
a) Executive Information System (EIS)
Supports top-level executives in long-term policy, strategy, and decision-making.
Focuses on unstructured decision processes and organizational goals.
Provides summary reports with ability to drill down into detailed data.
Enables analysis of business factors affecting performance (e.g., profit changes based on pricing
or incentives).
Integrates data inputs from operational, supervisory, and middle management systems.
b) Strategic E-Business Planning
Evaluates benefits and risks of adopting e-business strategies for competitive advantage.
Uses models to guide planning:
o Competitive Forces Model: competitors, customers, suppliers, new entrants, substitutes.
o Competitive Strategies Model: cost leadership, differentiation, growth, innovation,
alliances.
o Value Chain Model: primary and support activities adding value to products/services.
o Strategic Opportunities Matrix: assesses risk and payoff of e-business initiatives.
c) Business Continuity Plan (BCP)
Aims to prevent and recover systems from potential threats/disasters.
Ensures quick system functionality post-disaster (natural or man-made risks).
Involves risk identification, impact analysis, safeguards implementation, and rigorous testing.
Integral to organizational risk management strategy.
d) Software as a Service (SaaS)
Delivers software applications over the Internet as a service.
Eliminates need for installation or maintenance on user devices.
Provider manages security, availability, and performance.
Can be hosted by independent vendors or software vendors themselves (e.g., Microsoft).
Used by businesses and individuals for various applications, from entertainment (Netflix) to
advanced IT tools.
e) Disk Mirroring (RAID 1)
Data replication on two or more disks for high availability and performance.
Read operations are fast as data can be read simultaneously from multiple disks.
Write operations slower as data must be written twice.
Provides instant failover if one disk fails, ensuring continuous data access.
Part of RAID (Redundant Array of Independent Disks) technology; RAID 1 prioritizes reliability.
Other RAID levels include RAID 0 (fastest) and RAID 5 (balance of speed and reliability).