25-Comp-A6 Software Engineering · December 2019
Nivaar worked solution (AI-drafted; not reviewed by a licensed engineer)
National Exams — December 2019 — 17-Comp-A6 Software Engineering. Three-hour, closed-book, no-calculator exam. Format: eight questions, candidates answer any five of the eight (all questions equal weight — each of the five counted questions is worth 20%; only the first five questions as they appear in the answer book are marked). All eight questions are solved below for completeness.
Reference texts: Sommerville, Software Engineering (10th ed., Pearson) — software process models, object-oriented and function-oriented design, requirements engineering, software testing, software reuse, formal methods, dependable/critical systems, real-time software engineering, distributed software systems; Pressman, Software Engineering: A Practitioner's Approach (9th ed.) — supplementary process, testing and architecture coverage.
Question text not reproduced: the examination questions are © Engineers and Geoscientists BC. Open the official past paper (linked at the top of this page) to read the question, then follow the worked solution below.
Deploying software as a service (SaaS) reduces a customer company's IT support costs primarily because the software is installed, configured, patched, scaled, and operated once, centrally, by the provider, instead of being separately installed and maintained on every desktop across the customer's organization. This eliminates the customer's own need for local installation media/licence management, per-machine version-compatibility troubleshooting, local server/database administration for that application, and much of the local help-desk load for "it won't start / it needs an update" issues — all of that support burden shifts to the provider, who amortizes it across every customer.
Additional costs that can arise, however, include: ongoing subscription fees that, over a long enough time horizon, may exceed the amortized cost of a perpetual on-premises licence; a new, non-trivial dependency on network/internet connectivity and bandwidth, since the service is unusable when connectivity is down or degraded, which is a failure mode a desktop application never had; integration cost to connect the SaaS system with the company's other internal systems and data (APIs, data export/import, authentication integration), which is now cross-organizational rather than purely internal; and new costs around data governance, security, and compliance — the company's data now resides on infrastructure it does not control, which can require additional contractual, auditing, and regulatory-compliance effort (particularly for regulated data) that a purely on-premises deployment did not need.
| # | Risk | Mitigation |
|---|---|---|
| 1 | Availability/connectivity risk: functionality that used to work offline on the desktop becomes entirely dependent on network connectivity to the remote service; any outage, at the provider or on the company's own network, now stops work that previously would have continued uninterrupted. | Negotiate a service-level agreement (SLA) with defined uptime guarantees and penalties; where the workflow permits, retain a local caching/offline mode that can operate on the last-synchronized data during short outages and reconcile once connectivity returns; and consider a secondary/backup connectivity path for business-critical functions. |
| 2 | Data security and confidentiality risk: company (and potentially customer) data now leaves the company's own infrastructure and is processed/stored by a third party, increasing exposure to breach, unauthorized access, or the provider's own security failures, and potentially crossing jurisdictional boundaries with different data-protection law. | Require contractual data-protection and security commitments from the provider (encryption in transit and at rest, access controls, breach-notification terms, data residency/jurisdiction guarantees), verify the provider's security posture via independent audit/certification (e.g. SOC 2), and classify data so the most sensitive categories are excluded from the remote service if the residual risk is unacceptable. |
| 3 | Vendor lock-in and continuity risk: once workflows, data formats, and integrations are built around one provider's remote service, switching provider or reverting to an in-house solution becomes costly and disruptive, and the company is exposed if the provider changes pricing terms, is acquired, discontinues the service, or fails as a business. | Favour providers exposing data in open, well-documented formats/APIs and negotiate contractual data-portability and export rights up front; maintain periodic exports of the company's own data outside the provider's system as an independent backup; and evaluate exit/transition costs as part of the initial vendor-selection decision, not as an afterthought once already committed. |