Cybersecurity Risks in DMZ-Hosted Examination Systems and Their Implications for Assessment Integrity: A Passive Cyber-Exposure Analysis

Authors

Christine Simfukwe

Copperbelt University (Zambia)

Dennis Mulendema

Copperbelt University (Zambia)

Alice P. Shemi

Copperbelt University (Zambia)

Maybin Lengwe

Copperbelt University (Zambia)

Nchimunya Chaamwe

Copperbelt University (Zambia)

Article Information

DOI: 10.47772/IJRISS.2026.100800386

Subject Category: Management

Volume/Issue: 10/8 | Page No: 5908-5933

Publication Timeline

Submitted: 2026-07-25

Accepted: 2026-07-30

Published: 2026-09-06

Abstract

The digital transformation of national examination systems has significantly improved service delivery across the education assessment sector. However, the increasing reliance on publicly accessible digital infrastructure has expanded the cyberattack surface, exposing examination systems to threats that jeopardize the integrity, confidentiality, and availability of assessment processes. This aim of the study was to assess the external cybersecurity exposure of national examination systems across Africa by identifying publicly observable vulnerabilities affecting examination infrastructure.

Keywords

Cybersecurity; Examination Systems; Cybersecurity Governance

Downloads

References

1. L. Moccozet, A. Camacho, A. Bowman, O. Benkacem and P. Roth, "A Study of the Evolution of E-Assessment Practices Following the COVID-19 Pandemic in Higher Education," 2024 21st International Conference on Information Technology Based Higher Education and Training (ITHET), Paris, France, 2024, pp. 1-8, doi: 10.1109/ITHET61869.2024.10837598. [Google Scholar] [Crossref]

2. B. Taruberekera, "ZIMSEC Online Results Checking System: A Parent-Guardian Perception Survey," Institute of Education Conference. [Online]. Available: https://ojs.zou.ac.zw/index.php/iec/article/view/157 [Google Scholar] [Crossref]

3. Scarfone, K., Jansen, W., & Tracy, M. (2008). Guide to general server security (NIST Special Publication 800-123). National Institute of Standards and Technology. Available: https://csrc.nist.gov/publications/detail/sp/800-123/final [Google Scholar] [Crossref]

4. Lallie, H. S., Thompson, A., Titis, E., & Stephens, P. (2024). Understanding cyber threats against universities, colleges, and schools. Computers, 14(2), 49. https://doi.org/10.3390/computers14020049 [Google Scholar] [Crossref]

5. Newton, P., & Essex, K. (2022). How common is cheating in online exams and did it increase during the COVID-19 pandemic? A Systematic Review. Research Square [preprint]. https://doi.org/10.21203/rs.3.rs-2187710/v1 [Google Scholar] [Crossref]

6. Noorbehbahani, F., Mohammadi, A., & Aminazadeh, M. (2022). A systematic review of research on cheating in online exams from 2010 to 2021. Education and Information Technologies, 27, 8413–8460. https://doi.org/10.1007/s10639-022-10927-7 [Google Scholar] [Crossref]

7. Barut Tuğtekin, E. (2023). Scrutinizing Learning Management Systems in Practice: An Applied Time Series Research in Higher Education. The International Review of Research in Open and Distributed Learning, 24(2), 53–71. https://doi.org/10.19173/irrodl.v24i2.6905 [Google Scholar] [Crossref]

8. Namatende-Sakwa, L., Lewinger, K., & Langsford, D. (Eds.). (2023). COVID-19 and education in Africa: Challenges, possibilities and opportunities. Routledge. [Google Scholar] [Crossref]

9. Mahlangu, G., & Makwasha, L. (2023). Factors affecting the adoption and use of online assessment for learning at Polytechnics in Zimbabwe. Cogent Education, 10(1), 2177475. https://doi.org/10.1080/2331186X.2023.2177475 [Google Scholar] [Crossref]

10. Cremer, F., Sheehan, B., Fortmann, M., Kia, A. N., Mullins, M., Murphy, F., & Materne, S. (2022). Cyber risk and cybersecurity: A systematic review of data availability and cyber risk management. The Geneva Papers on Risk and Insurance — Issues and Practice, 47, 698–736. https://doi.org/10.1057/s41288-022-00266-6 [Google Scholar] [Crossref]

11. Garg, M., & Goel, A. (2022). A systematic literature review on online assessment security: Current challenges and integrity strategies. Computers & Security, 113, 102544. https://doi.org/10.1016/j.cose.2021.102544 Garg, M., et al. (2022). Online assessment security: A systematic review. Computers & Security. [Google Scholar] [Crossref]

12. Guillen-Gamez, F. D., Tomczyk, Ł., Ruiz-Palmero, J., & Connolly, C. (2024). Digital security in educational contexts: Digital competence and challenges for good practice. *Computers in the Schools, 41*(2). https://doi.org/10.1080/07380569.2024.2390319 [Google Scholar] [Crossref]

13. Yusuf Lawal, Modupeola Adepoju, & Ademeso Tosin Success. (2025). E-Examinations and national security: Challenges and prospects. IOSR Journal of Business and Management, 27(8), 09–16. doi: 10.9790/487X-2708050916 [Google Scholar] [Crossref]

14. Oguguo, B. C., & Ocheni, C. A. (2023). Cybersecurity: A tool for curbing examination breaches and improvement of the quality of large-scale educational assessments. *Information Security Journal: A Global Perspective, 33*(2), 1–15. https://doi.org/10.1080/19393555.2023.2284761 [Google Scholar] [Crossref]

15. A. Nuraeni, Y. Nugraha, and M. E. Aminanto, "Revisiting Cyber Threats in Government Sectors: A Systematic Review of Attacks, Challenges, and Policy-Level Defenses," International Journal of Advances in Data and Information Systems, vol. 6, no. 2, pp. 447–459, Aug. 2025. doi: 10.59395/ijadis.v6i2.1404. [Google Scholar] [Crossref]

16. Bwiino, K., Mayoka, G. K., Nkamwesiga, L., Nyamadi, M., & Musenze, I. A. (2025). Information security behavior in higher education institutions. Journal of Information Security and Cybercrimes Research, 8(1), 01-16, DOI: 10.26735/YQBX3351 [Google Scholar] [Crossref]

17. Omotunde, H., & Ahmed, M. (2023). A comprehensive review of security measures in database systems: Assessing authentication, access control, and beyond. Mesopotamian Journal of CyberSecurity, 2023, 115–133. https://doi.org/10.58496/MJCSC/2023/016 [Google Scholar] [Crossref]

18. Dadheech, K., Choudhary, A., & Bhatia, G. (2018). De-militarized zone: A next level to network security. In Proceedings of the 2018 Second International Conference on Inventive Communication and Computational Technologies (ICICCT). https://doi.org/10.1109/ICICCT.2018.8473328 [Google Scholar] [Crossref]

19. National Institute of Standards and Technology. (2023). Cybersecurity framework (Version 2.0). NIST. Available: https://www.nist.gov/cyberframework [Google Scholar] [Crossref]

20. Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture (NIST Special Publication 800-207). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-207 [Google Scholar] [Crossref]

21. Scarfone, K., & Hoffman, P. (2009). Guidelines on firewalls and firewall policy (NIST Special Publication 800-41, Rev. 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-41r1 [Google Scholar] [Crossref]

22. Whitman, M. E., & Mattord, H. J. (2022). Principles of information security (7th ed.). Cengage Learning. [Google Scholar] [Crossref]

23. Yang, J., Liang, L., & Qi, J. (2023). A practical non-intrusive cyber security vulnerability assessment method for cyber-insurance. In Proceedings of the 2023 IEEE International Conference on Data Science and Cybersecurity (DSC), pp. 261–269. doi: 10.1109/DSC59305.2023.00045 [Google Scholar] [Crossref]

24. Hutchins, E. M., Cloppert, M. J., & Amin, R. M. (2011). Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains. Leading Issues in Information Warfare & Security Research, 1(1), 80. Lockheed Martin. Available: https://www.lockheedmartin.com/content/dam/lockheed-martin/rms/documents/cyber/LM-White-Paper-Intel-Driven-Defense.pdf [Google Scholar] [Crossref]

25. Matherly, J. (2016). Complete guide to Shodan: Collect. Analyze. Visualize. Shodan LLC / Leanpub. Available: https://leanpub.com/shodan [Google Scholar] [Crossref]

26. Durumeric, Z., Adrian, D., Mirian, A., Bailey, M., & Halderman, J. A. (2015). A search engine backed by Internet-wide scanning. In Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security (CCS '15), pp. 542–553. ACM. https://doi.org/10.1145/2810103.2813703 [Google Scholar] [Crossref]

27. Check Point Research. (2024). A closer look at Q3 2024: 75% surge in cyber attacks worldwide. Check Point Blog. Available: https://blog.checkpoint.com/research/a-closer-look-at-q3-2024-75-surge-in-cyber-attacks-worldwide/ [Google Scholar] [Crossref]

28. Syed, N. F., Shah, S. W., Shaghaghi, A., Anwar, A., Baig, Z., & Doss, R. (2022). Zero Trust Architecture (ZTA): A comprehensive survey. IEEE Access, 10, 57143–57179. https://doi.org/10.1109/ACCESS.2022.3174679 [Google Scholar] [Crossref]

29. Teerakanok, S., Uehara, T., & Inomata, A. (2021). Migrating to zero trust architecture: Reviews and challenges. Security and Communication Networks, 2021, Article 9947347. https://doi.org/10.1155/2021/9947347 [Google Scholar] [Crossref]

30. Bitsight TRACE. (2023). Top cyber threats facing the education sector. Bitsight Research. Available: https://www.bitsight.com/blog/top-10-cyber-threats-facing-education-sector [Google Scholar] [Crossref]

31. Verizon. (2024). 2024 Data Breach Investigations Report (DBIR). Verizon Business. Available: https://www.verizon.com/business/resources/reports/dbir/ [Google Scholar] [Crossref]

Metrics

Views & Downloads

Similar Articles