NivaarExam PrepOfficial exam papers ↗

23-Ind-B4 Design of Information Systems · December 2017

Question 1 of 13: Information Systems Terminology — Select-20 Glossary

Nivaar worked solution (AI-drafted; not reviewed by a licensed engineer)

Notes on this paper

National Exams — December 2017 — 98-Ind-B4, Design of Information Systems. 3 hours; closed book, no calculator permitted. The exam comprises four parts: Part A (select 20 terms from the list given and explain each in a sentence or two, no more than 50 words, 2 marks each = 40 marks), Parts B and C (select 2 of 5 questions in each part, 11 marks each = 22 marks per part), and Part D (select 1 of 2 questions, 16 marks). Complete answers to every term and every question in all four parts follow below, not only the minimum selection a candidate would submit on exam day.

Reference texts: Laudon & Laudon, Management Information Systems: Managing the Digital Firm, 15th ed.; Schwalbe, Information Technology Project Management, 9th ed.

Question 1 (Part A): Information Systems Terminology — Select-20 Glossary (40 marks: 20 × 2)

Question text not reproduced: the examination questions are © Engineers and Geoscientists BC. Open the official past paper (linked at the top of this page) to read the question, then follow the worked solution below.

All 36 listed terms are defined below, not only the 20 a candidate would select on exam day; each entry targets the depth a 2-mark, 50-word answer supports.

Affiliate Revenue Model

An e-commerce revenue model in which a company earns income by referring visitors or customers to another company's website or product, receiving a fee or a percentage of the resulting sale in return — e.g., a blog embedding a retailer's affiliate link. One of several distinct ways an internet business can monetize traffic.

Information Systems Audit

A formal, independent examination of an organization's information systems, controls, and processes to verify the accuracy of data, the effectiveness of security controls, compliance with policy and regulation, and efficient use of IT resources. A post-implementation audit (term 18) is one specific instance of this broader practice, run shortly after a system goes live.

Application Server

Software, and often the dedicated hardware running it, that hosts and executes an application's business-logic layer, sitting between the web server (which handles HTTP requests) and the database server (which stores data) in a multitiered architecture (term 12).

JavaScript

A scripting language executed primarily in the browser (client-side), and increasingly on the server via platforms like Node.js, that makes web pages interactive and dynamic — form validation, animation, asynchronous data loading — without requiring a full page reload for every user action.

Balanced Scorecard Method

A strategic performance-measurement framework that evaluates an organization, and its IT investments, across four linked perspectives — financial, customer, internal business process, and learning/growth — instead of financial metrics alone, so an investment's contribution to non-financial strategic goals is also captured and tracked.

Keylogger

A form of spyware that covertly records every keystroke a user types — passwords, credit-card numbers, private messages — and transmits the captured data to an attacker, typically installed alongside other malware without the victim's knowledge.

Blockchain

A distributed, cryptographically linked ledger of transactions replicated across many participating nodes, where each new block references the cryptographic hash of the block before it, making the recorded history extremely costly to alter retroactively without controlling a majority of the network.

Location Analytics

The analysis of data enriched with geographic or positional information — GPS coordinates, mobile-device location, IP geolocation — to reveal spatial patterns in customer behaviour, operations, or logistics, e.g., identifying where mobile customers cluster in order to target a nearby promotion.

Business Processes

The set of logically related, structured activities and tasks an organization performs, in a defined sequence and using defined resources, to produce a specific product or service for a particular customer or market. Spans one or more functional areas and is developed with concrete cross-functional examples in Question 7.

Long Tail Marketing

A strategy of profitably selling a very large number of low-demand, niche items in small individual quantities — the "long tail" of the demand curve — rather than relying only on a few high-demand "hits." Made economically viable online because near-zero incremental inventory and shelf-space cost removes the physical-retail penalty for stocking niche titles.

Crowdsourcing

Obtaining input, content, ideas, funding, or work — product ratings, translations, problem-solving, capital — from a large, open group of external contributors, typically coordinated through an internet platform, rather than from employees or a designated supplier.

Multitiered Architecture

A software architecture that splits an application into logically distinct layers — typically a presentation/client tier, an application/logic tier (term 3), and a data tier — each capable of running on its own server, so each layer can be developed, scaled, and secured independently of the others.

Churn Rate

The percentage of customers or subscribers who discontinue using a company's product or service over a given period. A key metric for evaluating customer-retention effectiveness and the underlying health of a subscription-based or membership-based business model.

Neural Network

A machine-learning model loosely inspired by the brain's structure, composed of interconnected layers of nodes that learn to recognize patterns in data through iterative adjustment of connection weights during training. Widely used for classification, prediction, and pattern-recognition tasks such as fraud detection or image recognition.

Computer Forensics

The scientific collection, preservation, examination, and analysis of data held on or retrieved from computer storage media, carried out in a manner that maintains the data's integrity and its admissibility as legal evidence, typically following a suspected crime, breach, or policy violation.

Operational CRM

The customer-facing component of customer relationship management — applications that support front-line customer-contact points such as sales-force automation, call-centre and customer-service systems, and marketing automation — distinguished from analytical CRM, which mines the resulting customer data for patterns rather than executing the interaction itself.

Data Cleansing

The process of detecting and correcting, or removing, inaccurate, incomplete, duplicate, or inconsistent records in a database, typically performed before loading data into a data warehouse, since poor input data quality undermines every downstream analysis built on top of it.

Post-Implementation Audit

A formal review conducted after a system has gone into production to assess whether it met its original objectives and delivered the projected costs and benefits, and to capture lessons learned for future projects — a specific, time-bound application of the broader information systems audit of term 2.

Deep Packet Inspection (DPI)

A network-traffic-filtering technique that examines the actual data payload of each packet crossing a checkpoint, not just its header, allowing far finer-grained detection of malware, policy violations, or prioritization decisions than header-only inspection can achieve.

Program-Data Dependence

The tight coupling, characteristic of traditional file-processing systems, between data's physical structure and the specific application programs written to access it, so a change to the file structure breaks every program that reads it. A core problem the DBMS approach (Question B1) was designed specifically to eliminate.

Digital Certificate

An electronic document, issued and digitally signed by a trusted Certificate Authority, that binds a specific public key to a verified identity — a person, organization, or server — letting a recipient trust that the key genuinely belongs to the claimed owner. The identity-verification building block of the public key infrastructure developed in Question B4.

Risk Assessment

The process of identifying an organization's information assets and the threats and vulnerabilities each faces, then estimating the probability and business impact of each threat materializing, so security investment can be prioritized toward the highest-value, highest-risk exposures rather than spread evenly across everything.

Entity-Relationship Diagram

A graphical modelling technique that documents a database's entities, their attributes, and the relationships (one-to-one, one-to-many, many-to-many) among them, forming the conceptual schema from which the physical database design is derived and validated.

Social Shopping

An e-commerce approach that embeds social-network tools — sharing, peer reviews, friend recommendations, group buying — directly into the shopping experience, so a buyer's purchase decisions are shaped by their social connections rather than made in isolation from a static product page.

Enterprise Applications

Large-scale, cross-functional software systems — ERP, supply-chain management, CRM, knowledge-management systems — that integrate data and processes across an entire organization, and often its suppliers and customers too, rather than serving a single department's needs in isolation.

SQL Injection Attack

A code-injection technique in which an attacker submits malicious SQL statements through a web application's input fields (e.g., a login form) that, if not properly sanitized or parameterized, execute directly against the backend database — exposing, modifying, or destroying data the attacker was never authorized to touch.

Fair Information Practices

A set of internationally recognized principles — notice, choice/consent, access, security, enforcement — governing how organizations collect, use, and protect personal information. Forms the basis of most modern privacy law and of an organization's own privacy policy.

Switching Costs

The cost, in money, time, or effort, a customer incurs when changing from one product, supplier, or system to a competing one. Information systems can raise switching costs, locking customers in, or lower them, making a market more competitive — a strategic lever developed in Question C1.

Green Computing

Practices and technologies aimed at minimizing the environmental impact of computing — energy-efficient hardware and data-centre design, virtualization to reduce the physical server count, responsible e-waste disposal and recycling — pursued both to cut operating cost and to meet regulatory and sustainability expectations.

TCP/IP

The foundational suite of communication protocols (Transmission Control Protocol/Internet Protocol) governing how data is broken into packets, addressed, routed across interconnected networks, and reassembled correctly at the destination. The common language that makes the internet, and most private corporate networks, interoperable regardless of vendor or underlying hardware.

Hadoop

An open-source framework, based on Google's MapReduce and file-system research, that enables distributed storage (via HDFS) and parallel processing of very large datasets across clusters of low-cost commodity servers — a foundational Big Data technology.

Value Web

A networked system of independent firms — a company together with its suppliers, distribution partners, and customers — that uses information technology to coordinate their individual value chains and collectively produce a product or service for a market, more flexibly than any single firm's internal value chain acting alone (Question 9).

Hybrid Cloud

A cloud-deployment model combining private cloud, or on-premises infrastructure, with public cloud, with workloads and data able to move between the two — letting an organization keep sensitive data and processes under tighter direct control while still gaining public cloud's cost and scale benefits for less-sensitive workloads (developed in Question B5).

Web Beacons

Tiny, often invisible embedded graphic files, typically a single-pixel image, placed on a web page or in an email that silently report back to a server when the page or email is opened. Used to track visitor behaviour and email open rates across sites the user may not realize are cooperating with each other.

Identity Management

The business processes and supporting technology for identifying valid system users and controlling their access to system resources — provisioning and deprovisioning accounts, authentication, and enforcing that each user holds appropriate, and no more than appropriate, access rights.

Web Mining

The application of data-mining techniques to discover patterns from data generated by the World Wide Web, spanning content mining (extracting knowledge from page content), structure mining (analyzing hyperlink patterns between sites), and usage mining (analyzing user click-stream and behaviour logs).

← Paper overview