Implementation of Zero Trust Architecture in Online Examination Systems to Prevent Cheating
Keywords:
Zero Trust Architecture, Online Exams, Academic Integrity, CybersecurityAbstract
The increasing use of online exam systems (e-exams) in the post-pandemic cyberlearning ecosystem presents critical challenges to academic integrity, particularly related to vulnerabilities to increasingly sophisticated technical fraud such as the use of virtual machines, remote desktops, and even artificial intelligence-based identity manipulation. Traditional perimeter-based security models—verifying only the initial login—have proven inadequate in detecting dynamic threats that occur during exam sessions. This research proposes the implementation of Zero Trust Architecture (ZTA) with the core principle of “Never Trust, Always Verify” as a comprehensive solution for securing online exams. The methodology used is Research and Development (R&D), which includes designing a security architecture based on the five main pillars of Zero Trust: identity, device, network, application, and data. The developed system integrates continuous identity verification, device-posture attestation, micro-segmented network sessions, least-privilege application access, and encrypted, integrity-checked data handling into a single risk-scoring policy engine. Expert validation of the proposed architecture indicates that the design is feasible for institutional adoption, with the strongest gains expected in device-level fraud detection and in the continuous re-verification of identity throughout the exam session. The study concludes that ZTA offers a materially more resilient alternative to perimeter-based e-exam security and outlines a staged adoption roadmap for higher-education institutions.
References
[1]. S. Rose, O. Borchert, S. Mitchell, and S. Connelly, “Zero Trust Architecture,” NIST Special Publication 800-207, National Institute of Standards and Technology, Gaithersburg, MD, USA, Aug. 2020.
[2] National Institute of Standards and Technology, “Zero Trust Architecture: NIST Publishes SP 800-207,” NIST News, Aug. 2020. [Online]. Available: https://www.nist.gov/news-events/news/2020/08/zero-trust-architecture-nist-publishes-sp-800-207
[3] National Institute of Standards and Technology, “SP 800-207A: A Zero Trust Architecture Model for Access Control in Cloud-Native Applications in Multi-Cloud Environments,” NIST Special Publication 800-207A, Gaithersburg, MD, USA, 2023.
[4] Cloud Security Alliance, “Zero Trust Architecture (SP 800-207),” Cloud Security Alliance Resource Library, 2020.
[5] Palo Alto Networks, “What Is NIST SP 800-207? Zero Trust Architecture Framework,” Palo Alto Networks Cyberpedia, 2025.
[6] RiskRecon, “Understanding NIST 800-207,” RiskRecon Blog, 2023.
[7] Entro Security, “NIST SP 800-207,” Entro Security Glossary, 2025.
[8] NextLabs, “NIST 800-207: Zero Trust Architecture — An Overview,” NextLabs White Paper, 2024.
[9] Secureframe, “What Is Zero Trust Architecture & Why Does It Matter for CMMC Compliance?,” Secureframe Blog, 2026.
[10] “Application of Artificial Intelligence (AI) in Detecting and Preventing Cheating During Online and Physical Exams,” research paper, 2025.
[11] “ProctorEdge: Advanced AI Examination Monitoring and Security System,” in Proc. Int. Conf. on Computer Supported Education, SciTePress, 2025.
[12] “Detecting AI-Assisted Cheating in Online Exams through Behavior Analytics,” preprint, arXiv:2510.18881, 2025.
[13] “Deep Learning Models for Detecting Cheating in Online Exams,” ScienceDirect, 2025.
[14] “Ensuring Academic Integrity through Automated Online Exam Proctoring: A Decade-Long Systematic Review,” Discover Education, Springer Nature, 2026.
[15] “Smart Online Exam Proctoring Assist for Cheating Detection,” ResearchGate preprint, 2022.
[16] “The Accuracy of AI-Based Automatic Proctoring in Online Exams,” European Journal of e-Learning, 2024.
[17] “Hidden Monitoring Based on Keystroke Dynamics in Online Examination System,” PMC, National Library of Medicine, 2022.
[18] A. A. E. Ahmed and I. Traoré, “Ensuring Online Exam Integrity Through Continuous Biometric Authentication,” in Proc. Int. Conf. on Information Systems Security and Privacy, 2014.
[19] Chen et al., “Keystroke Dynamics Based User Authentication and its Application in Online Examination,” in Proc. IEEE Int. Conf. on Dependable, Autonomic and Secure Computing, IEEE, 2021.
[20] “Keystroke Dynamics: Concepts, Techniques, and Applications,” preprint, arXiv:2303.04605, 2023.
[21] “Identity Verification in Virtual Education Using Biometric Analysis Based on Keystroke Dynamics,” research paper, 2025.
[22] M. H. O. Rashid et al., “Adoption of Zero Trust Architecture in Higher Education Institutions in Bangladesh (ZTA-HEIs): Strategies, Challenges, and Readiness,” Journal of King Saud University – Computer and Information Sciences, Springer Nature, 2026.
[23] EDUCAUSE, “A Pathway to Zero-Trust Security Architecture in Higher Education,” EDUCAUSE Cybersecurity and Privacy Professionals Conf., 2021.
[24] “Applying Transparent Shaping for Zero Trust Architecture Implementation in AWS: A Case Study,” preprint, arXiv:2405.01412, 2024.
[25] “Towards Zero Trust Architecture: A Pilot Study on Information Systems Security Readiness amongst Small and Medium Enterprises,” preprint, arXiv:2605.18901, 2026.
[26] “A Systematic Literature Review on the Implementation and Challenges of Zero Trust Architecture Across Domains,” PMC, National Library of Medicine, 2025.
[27] “Toward a Zero Trust Architecture Implementation in a University Environment,” ResearchGate preprint, 2021.
[28] NewEraTech, “Implementing Zero Trust Architecture in Higher Education,” White Paper, 2021.
[29] Digiexam, “Secure Exam Browser — Prevent Cheating,” Digiexam Blog, 2025.
[30] Think Exam, “Secure Lockdown Browser for Online Exams,” Think Exam product documentation, n.d.
[31] Respondus, “Prevent Cheating in Higher Ed with Respondus LockDown Browser,” Respondus product documentation, 2019.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 CyTEd: Journal of Cyber Learning, Teknolinguistics and Educational Games

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
CC Attribution-NonCommercial-ShareAlike 4.0 (CC BY-NC-SA 4.0)
By submitting their work, Authors agree to license it under the CC BY-NC-SA 4.0 International License.
1. User Permissions
Readers are free to Share (copy/redistribute) and Adapt (remix/build upon) the material, provided they follow these conditions:
2. Required Conditions
-
Attribution (BY): Users must credit the original author and source (the journal) and provide a link to the license.
-
NonCommercial (NC): The work may not be used for primary commercial purposes or monetary gain.
-
ShareAlike (SA): Any derivative work created must be distributed under the same CC BY-NC-SA 4.0 license.
3. Copyright and Publishing
-
Copyright: Remains with the Author(s).
-
Journal Right: The Journal is granted the First Non-Exclusive Publishing Right under the CC BY-NC-SA 4.0 license.
-
Self-Archiving: Authors may re-use or deposit the final published version elsewhere, provided they maintain the original license and link back to the journal.



