Educause Security Discussion mailing list archives

Taking the exams in students' laptops


From: Uday Kiran <ukiran () HCT AC AE>
Date: Thu, 27 Feb 2020 05:44:02 +0000

We have been facing this issue since long time, but thought of putting it here to have your valuable feedback. We have 
BYOD policy for students in general and for the semester exams they are using the same laptops.

A few students are misusing this privilege and trying to cheat the exam in various ways,

a)       Someone in their friends list will take TeamViewer or any such similar technologies to take the exam remotely, 
proctor sees only if the students is moving mouse or not.

b)      Concurrent logins, our LMS (Blackboard) keeps the session active since the exam attempt has to be active for 
certain time, which is for a genuine reason and we will not be disable it (Bb Learn as well did not recommend it); 
students login to LMS portal before the exam and keep it active with one of their friends, they will be in the exam 
hall with their laptops and attempt the exam as normal. The exam password will be shared to the remote friend either 
through iCalendar or any other means, now the remote friend has access and can attempt the exam. Also in Macbooks it is 
very easy to bypass the Respondus Lock Down Browser and many students bring Macbooks for the exams remaining times it 
is normal Lenovo or whatever.

Limitations we have;

a)       We will not be able to conduct the exams on our owned devices since we have 25,000 students and assigning 
everyone a device is not only difficult to manage but also the huge budget.

b)      Enabling the MFA, we should issue hard tokens which is again over head to the local IT Support teams and of 
course the cost, soft tokens cannot be used since mobiles are not allowed in the exam hall.

c)       Multiple logins cannot be disabled, even Blackboard as well did not recommend.

Regards,

Uday Kiran
Senior Specialist –Information Security
Higher Colleges of Technology - UAE
















Uday Kiran
Snr Spl – Information Security
Office of Dir. Digital Technologies
اوداي كيران
أخصائي أول - أمن المعلومات
تكنولوجيا المعلومات


[Main logo]     Direct.: 9712 206 1182
Mobile: +971 56 501 1182
Email: ukiran () hct ac ae<mailto:ukiran () hct ac ae>
P.O.Box: 25026, Abu Dhabi, United Arab Emirates

        www.hct.ac.ae<http://www.hct.ac.ae>
[Facebook]<https://www.facebook.com/hctuae>     [Twitter] <https://twitter.com/HCT_UAE>         [Instagram] 
<https://www.instagram.com/HCT_UAE/>        [YouTube] <https://www.youtube.com/user/hctuae>



[Enviromental]  Please consider the environment before printing this email
This Email and any attachments may contain HCT confidential and privileged information.If you are not the intended 
recipient, please notify the sender immediately by return email, delete this email and destroy any copies. Any 
dissemination or use of this information by a person other than the intended recipient is unauthorized and may be 
illegal. Unless otherwise stated, opinions expressed in this email are those of the author and are not endorsed by the 
author's employer.


________________________________

The information in this email and any attachments are confidential and solely for the use of the individual or entity 
to whom it is addressed to and authorized to receive it. If you are not the intended recipient, be advised that you 
have received this email in error and that any use, disclosure, copying, distribution or taking any action in reliance 
on the content of this information is strictly prohibited and may be unlawful. If you have received this email in 
error, please delete along with any attachments and inform the Higher Colleges of Technology immediately at disclaimer 
() hct ac ae. We do not guarantee the integrity of any emails or attachments and are not responsible for any changes 
made to them by any other person.

تعتبر المعلومات الواردة في هذا البريد الإلكتروني وأياً من مرفقاته سرية وتخص المستلم المعني أو الاشخاص المصرح لهم 
باستلامه، فإذا لم تكن المستلم المقصود، فيرجى العلم بأنك قد استلمت هذا البريد الإلكتروني عن طريق الخطأ ويمنع منعاً باتاً 
الاستفادة منه أو افشاء محتواه أو توزيعه. وفي حال استلام بريد إلكتروني عن طريق الخطأ، يرجى حذفه مع مرفقاته وإخطار كليات 
التقنية العليا فوراً على البريد الإلكتروني التالي: disclaimer () hct ac ae. كما أننا لا نضمن سلامة أي بريد إلكتروني أو 
مرفقاته، ولسنا مسؤولين عن أية تعديلات عليها من قبل أي شخص آخر.

________________________________

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

Current thread: