Mumbai University Solved Question Papers
Penal Laws
Previous Year Question Paper with Solution
LLM · Group 5 Criminal Law and Criminal Administration
2018 Examination
munotes.in
Mumbai
Mumbai University Solved Question Papers
Penal Laws
Previous Year Question Paper with Solution
LLM · Group 5 Criminal Law and Criminal Administration
2018 Examination
munotes.in
Mumbai
First published on munotes.in on 13 August 2026.
Published by munotes.in, Mumbai.
Model answers written and edited by the munotes.in editorial desk.
Passages from this volume may be quoted, in print, online or by an AI system, with credit: name munotes.in and link to this volume's page. The volume may not be reproduced as a whole. Full terms at munotes.in/content-license.
munotes.in is an independent study resource for students of the University of Mumbai. It is not affiliated with the University of Mumbai, and is not endorsed by it.
The University does not publish an official answer key for this paper. The answers in this volume are model answers, written to show how a full-mark answer is built. They are a study aid, not an authority on what an examiner marked.
The question paper reproduced here is the paper as set by the University of Mumbai at the 2018 examination.
The law in these answers is stated as at August 2026, and four changes date most textbooks on this subject. The Indian Penal Code was repealed on 1 July 2024 by the Bharatiya Nyaya Sanhita, 2023, which replaced sedition with section 152; section 124A has been in abeyance since 11 May 2022 and the Supreme Court agreed on 8 August 2025 to examine section 152 itself. Section 66A of the Information Technology Act was finally omitted from the statute book by the Jan Vishwas (Amendment of Provisions) Act, 2023 on 30 November 2023, eight years after Shreya Singhal struck it down, and sections 72 and 72A were decriminalised the same day. The Cyber Appellate Tribunal was abolished by the Finance Act, 2017 on 26 May 2017 and appeals now lie to the Telecom Disputes Settlement and Appellate Tribunal. And section 2(54) of the Juvenile Justice Act, 2015 was substituted on 1 September 2022 to enact Shilpa Mittal.
The questions below are the paper as the University of Mumbai set it at the 2018 examination, in the order it was set.
MarksPage
MarksPage
The questions in this volume are the questions asked at the 2018 examination, reproduced as the University of Mumbai set them, in the order it set them. Nothing has been reworded, added or left out. Only the answers are ours. See the original question paper.
Duration 3 hours · Total marks 100 · 14 questions answered
How to use this volume
Solve the paper first, under exam conditions and against the clock. Then read the answers here and mark your own. Reading a solution before attempting the question feels productive and teaches very little, because recognising an answer is not the same as being able to write one.
the first paper in this scan, which prints no code
attempt any four of seven · 100 Marks
Answer
For full marks, cover: two limbs, and the second is the larger. Do not treat this as a question about an official; treat it as a question about why a signature scheme needs a regulator at all, and the answer writes itself. Give the appointment provisions, then the functions in section 18 in full, then the powers that are not in section 18, which is where most answers stop short.
The Information Technology Act, 2000 gives legal effect to an electronic signature. Section 5 provides that where any law requires information to be authenticated by a signature, that requirement is satisfied by an electronic signature affixed in the prescribed manner. Section 3 provides that a digital signature is effected by an asymmetric crypto system and hash function, verified by the public key of the subscriber.
That scheme has a gap at its centre. A public key is a string of characters. Nothing in it says whose key it is. A stranger relying on a signature must be able to obtain, from a source he can trust, an assurance that this public key belongs to that person. That assurance is the Electronic Signature Certificate, issued under section 35 by a Certifying Authority.
The Certifying Authority is therefore the pivot of the whole statute, and the question immediately arises who licenses and supervises it. That is the Controller.
Section 17(1) provides that the Central Government may, by notification in the Official Gazette, appoint a Controller of Certifying Authorities for the purposes of the Act, and may also appoint such number of Deputy Controllers, Assistant Controllers, other officers and employees as it thinks fit.
Section 17(2) provides that the Controller shall discharge his functions subject to the general control and directions of the Central Government. Section 17(3) provides that the Deputy Controllers and Assistant Controllers shall perform the functions assigned to them by the Controller under his general superintendence and control. Section 17(4) requires the qualifications, experience and terms and conditions of service to be as prescribed. Section 17(5) requires the Central Government to prescribe the Head Office and Branch Offices, and section 17(6) provides that the Controller shall have a seal.
The office is therefore an executive regulator within the Central Government, not an independent statutory authority, and section 17(2) makes that subordination explicit.
Section 18 provides that the Controller may perform all or any of the following functions:
Two of those clauses deserve emphasis in an answer. Clause (b), certifying the public keys of the Certifying Authorities, is what makes the Controller the root of trust: every certificate a Certifying Authority issues is ultimately verifiable against a key the Controller has certified. Clause (n) is the public accountability provision, because a disclosure database that anyone may inspect is what allows a relying party to check the standing of the authority whose certificate he is trusting.
An answer that stops at section 18 misses half the office.
Licensing, sections 21 to 26. Section 21 provides that a person may apply to the Controller for a licence to issue electronic signature certificates, and that no licence shall be granted unless the applicant fulfils the prescribed requirements of qualification, expertise, manpower, financial resources and infrastructure. Section 22 governs the application, section 23 renewal, section 24 the grant or rejection after giving the applicant a reasonable opportunity, section 25 suspension of a licence on the grounds stated, and section 26 the publication of notice of suspension or revocation in the database and, where appropriate, in the Official Gazette.
Recognition of foreign authorities, section 19. With the previous approval of the Central Government and by notification, the Controller may recognise any foreign Certifying Authority for the purposes of the Act, and may revoke the recognition for recorded reasons if the conditions of recognition are not complied with.
Delegation, section 27. The Controller may, in writing, authorise a Deputy Controller, an Assistant Controller or any officer to exercise any of his powers.
Investigation, section 28. The Controller or any officer authorised by him shall take up for investigation any contravention of the provisions of the Act, rules or regulations, and shall exercise the like powers as are conferred on income tax authorities under Chapter XIII of the Income-tax Act, 1961, subject to the limitations of that Chapter.
Access to computers and data, section 29. Where the Controller or a person authorised by him has reasonable cause to suspect a contravention, he may access any computer system, apparatus, data or other material connected with that system for the purpose of searching for or obtaining information, and may by order direct any person in charge of that system to provide reasonable technical and other assistance.
Directions, section 68. The Controller may by order direct a Certifying Authority or any employee of such Authority to take such measures or to cease carrying on such activities as are specified in the order, if those are necessary to ensure compliance with the Act. Failure to comply was formerly an offence; the Jan Vishwas (Amendment of Provisions) Act, 2023, with effect from 30 November 2023, converted it into a penalty which may extend to twenty five lakh rupees.
Interception, section 69. The power to issue directions for interception, monitoring or decryption is vested in the Central or a State Government or an officer specially authorised, not in the Controller as such.
Three offences protect the certification scheme the Controller regulates. Section 71 punishes a person who makes any misrepresentation to, or suppresses any material fact from, the Controller or a Certifying Authority for obtaining a licence or a certificate, with two years or fine up to one lakh rupees or both. Section 73 punishes publishing an electronic signature certificate knowing that the Certifying Authority listed has not issued it, or that the subscriber listed has not accepted it, or that it has been revoked or suspended, on the same scale. Section 74 punishes knowingly creating, publishing or making available such a certificate for a fraudulent or unlawful purpose, again with two years or one lakh or both.
Section 34 requires every Certifying Authority to disclose its certificate containing the public key, its certification practice statement, notice of any revocation or suspension, and any occurrence which materially and adversely affects its operation. Section 30 requires it to follow certain procedures, section 31 to ensure compliance, section 32 to display its licence, and section 33 to surrender it on suspension or revocation.
Two criticisms are standard. The first is subordination: section 17(2) makes the Controller subject to the general control and directions of the Central Government, so the regulator of a trust infrastructure is an arm of the executive rather than an independent authority. The second is that the appellate structure behind the office collapsed. The Cyber Appellate Tribunal established under section 48, to which appeals from orders of the Controller and adjudicating officers lay under section 57, had no Chairperson from 2011, and the Finance Act, 2017 omitted sections 49 to 56 with effect from 26 May 2017, transferring the jurisdiction to the Telecom Disputes Settlement and Appellate Tribunal.
Shreya Singhal v. Union of India, (2015) 5 SCC 1, though decided on other provisions, is instructive by analogy. The Supreme Court upheld section 69A, the blocking power, precisely because it is confined to identified grounds, requires reasons in writing and is subject to procedural safeguards in rules, while striking down section 66A for vagueness. The Controller's powers under sections 28 and 29 are of the same kind, exercisable on a stated suspicion of contravention and for a stated purpose, which is what keeps them defensible.
The Controller's functions are only half of the arrangement. The other half is the duties he enforces, and an answer that sets them out shows why the office exists.
On the Certifying Authority, Chapter VI. Section 30 requires it to make use of hardware, software and procedures secure from intrusion and misuse, to provide a reasonable level of reliability in its services, to adhere to security procedures, and to observe the standards the Controller lays down. Section 31 requires it to ensure that every person employed by it complies with the Act, the rules and the regulations. Section 32 requires it to display its licence at the conspicuous place of its business premises, and section 33 to surrender the licence immediately on suspension or revocation, failure to do so being an offence. Section 34 requires it to disclose its own certificate containing the public key, its certification practice statement, notice of any revocation or suspension of its certificate, and any other fact that materially and adversely affects either the reliability of a certificate it has issued or its ability to perform its services.
On the subscriber, Chapter VIII. Section 40 requires a subscriber whose certificate lists a public key to generate the key pair by the applicable security procedure. Section 40A imposes the corresponding duty in respect of an electronic signature certificate. Section 41 governs acceptance of a certificate and provides that a subscriber who accepts one certifies to all who reasonably rely on it that he holds the private key and that all representations in the certificate are true. Section 42 is the operative duty: the subscriber shall exercise reasonable care to retain control of the private key and take all steps to prevent its disclosure, and if the key has been compromised he shall communicate the fact without any delay to the Certifying Authority, remaining liable until he does so.
What a court makes of the chain. The presumptions in the law of evidence attach only where the chain has been observed. Section 87 of the Bharatiya Sakshya Adhiniyam, 2023, replacing section 85C of the Indian Evidence Act, 1872, presumes that the information listed in an Electronic Signature Certificate is correct, except for information marked as unverified subscriber information, where the subscriber accepted the certificate.
The chain does not, however, answer admissibility. Anvar P.V. v. P.K. Basheer, (2014) 10 SCC 473, held that an electronic record produced as secondary evidence is inadmissible without the certificate then required by section 65B(4) of the Evidence Act, and overruled the contrary observations in State (NCT of Delhi) v. Navjot Sandhu, (2005) 11 SCC 600. Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1, held the certificate to be a mandatory condition precedent and overruled Shafhi Mohammad v. State of Himachal Pradesh, (2018) 2 SCC 801. The requirement is now section 63(4) of the Bharatiya Sakshya Adhiniyam, 2023.
Conclusion. The Controller of Certifying Authorities is an officer appointed by the Central Government under section 17, working under its general control, who sits at the root of the Act's trust infrastructure. His functions under section 18 are supervisory and regulatory: supervising Certifying Authorities, certifying their public keys, laying down standards, qualifications, conditions, forms, accounts and duties, resolving conflicts with subscribers, and maintaining a publicly accessible database of disclosure records. Beyond section 18 he licenses, renews, suspends and revokes under sections 21 to 26, recognises foreign authorities under section 19, investigates contraventions under section 28 with income tax powers, accesses computer systems under section 29 and issues binding directions under section 68, and sections 71, 73 and 74 punish those who deceive him or misuse the certificates his licensees issue.
The rest of the answers
You have read the question paper and its first answer in full. Buy the solved papers once and you can read every answer of every solved paper in this semester.
Notes + Solved papers: ₹798 Already bought it? Sign in
Or solved papers only: ₹499
Or notes only: ₹499
The question paper itself stays free, as does the syllabus and module one of every subject.
Found an error in this volume? Report it and we will check it against the paper.