IGNOU MCS-220 solved assignment 2026-27
Updated 1 October 2026 · Applies to the July 2026 and January 2027 sessions
Looking for the IGNOU MCS-220 solved assignment 2026-27? This page gives you the assignment details, the topic behind each of the 9 questions, and worked answers with code for Servlets, JSP, JDBC, Spring and a Library Management design. It is written for MCA_NEW and MCAOL Semester 2 students.
Note: the questions below were copied from the 2026-27 assignment set as published by study sites. Compare them with your own IGNOU booklet before you start.
MCS-220 assignment details 2026-27
| Item | Details |
|---|---|
| Course | MCS-220 Web Technologies |
| Assignment no. | MCA_NEW/MCAOL(II)/220/Assign/2026-27 |
| Marks | 100 (80 written + 20 viva voce), weightage 30% |
| Questions | 9 questions, answer all |
| Last date, July 2026 session | 31 October 2026 |
| Last date, January 2027 session | 15 April 2027 |
| Submission | Study Centre Coordinator (MCA_NEW) or as instructed for MCAOL; viva voce is compulsory |
Question-wise topics
| Q | Marks | Topic |
|---|---|---|
| 1 | 5 + 5 | (a) Design pattern, web application, servlet container, JSP, dependency injection. (b) Layered architecture of a Java web application |
| 2 | 5 + 5 | (a) Servlet life cycle with diagram. (b) HTTP request-response cycle, parameters, headers and cookies |
| 3 | 5 + 5 | (a) JSP program for GCD. (b) Servlet that shows employee details submitted from a form |
| 4 | 5 | JDBC steps for a student registration system |
| 5 | 5 | Spring MVC vs Spring Boot |
| 6 | 5 + 5 | (a) Hibernate vs JDBC. (b) Spring Data JPA vs traditional DAO |
| 7 | 10 | Spring Security for a banking application, with a recommended strategy |
| 8 | 5 + 5 | (a) Software testing in web applications. (b) Exception handling and logging |
| 9 | 10 | Design of a Library Management web application using Spring Boot |
Get Full Solution PDF File
Worked answers
Q1 (a). Define the terms with examples (5 marks)
| Term | Meaning | Example |
|---|---|---|
| Design pattern | A proven, reusable solution to a common design problem | Singleton: one shared database connection manager |
| Web application | A program that runs on a server and is used through a browser | An online banking portal |
| Servlet container | Software that loads servlets, manages their life cycle and maps requests to them | Apache Tomcat, Jetty |
| JSP | JavaServer Pages: HTML with embedded Java that is compiled into a servlet | A page that lists products from the database |
| Dependency injection | Objects receive the objects they depend on from outside instead of creating them | Spring injects a StudentService into a controller with @Autowired |
Q1 (b). Layered architecture of a Java web application (5 marks)
Browser
|
Presentation layer (JSP / Thymeleaf, Servlets / Controllers)
|
Business layer (Service classes: rules, validation, transactions)
|
Persistence layer (DAO / Repository, Hibernate / JPA)
|
Database layer (MySQL, Oracle, PostgreSQL)
- Presentation layer: receives requests, shows pages and never contains business rules.
- Business layer: applies the rules of the application, such as checking a balance before a transfer.
- Persistence layer: hides how data is stored, so the business layer calls methods instead of writing SQL.
- Database layer: stores the data permanently and keeps it consistent.
Layers make the code easier to test, change and reuse, because each layer talks only to the one next to it.
Q2 (a). Servlet life cycle (5 marks)
Request arrives
|
Container loads class and creates ONE instance
|
init(ServletConfig) <- called once
|
service(req, res) -> doGet() / doPost() <- called for every request
| (repeats)
destroy() <- called once, before removal
- init(): runs once after the servlet is created. Use it for one-time setup such as opening resources.
- service(): runs for every request, each in its own thread. It calls
doGet()ordoPost()depending on the HTTP method. - destroy(): runs once when the container removes the servlet. Use it to release resources.
Q2 (b). HTTP request-response cycle (5 marks)
- The browser opens a connection and sends a request: a request line (
GET /login HTTP/1.1), headers and, for POST, a body. - The web server passes the request to the container, which calls the matching servlet.
- The servlet processes the request and builds a response: a status line (200, 404 and so on), headers and the body (HTML, JSON).
- The server returns the response and the browser displays it.
- Request parameters: sent in the query string for GET (
?id=5) or in the body for POST. Read withrequest.getParameter("id"). - Headers: extra information such as
Content-Type,User-AgentandCookie. Read withrequest.getHeader(), set withresponse.setHeader(). - Cookies: the server sends a
Set-Cookieheader (response.addCookie()). The browser sends the cookie back in theCookieheader on later requests (request.getCookies()).
Q3 (a). JSP program for GCD (5 marks)
<%@ page language="java" contentType="text/html; charset=UTF-8" %>
<html>
<head><title>GCD Calculator</title></head>
<body>
<form method="post">
Number 1: <input type="number" name="a" required>
Number 2: <input type="number" name="b" required>
<input type="submit" value="Find GCD">
</form>
<%
String sa = request.getParameter("a");
String sb = request.getParameter("b");
if (sa != null && sb != null) {
try {
int m = Math.abs(Integer.parseInt(sa.trim()));
int n = Math.abs(Integer.parseInt(sb.trim()));
while (n != 0) { /* Euclid's algorithm */
int t = n;
n = m % n;
m = t;
}
out.println("<p>GCD = " + m + "</p>");
} catch (NumberFormatException e) {
out.println("<p>Please enter valid integers.</p>");
}
}
%>
</body>
</html>
Execution: the form posts two numbers to the same page. The scriptlet reads them with request.getParameter(), converts them to integers, applies Euclid's algorithm (replace the pair (m, n) by (n, m mod n) until n is 0) and prints m as the GCD. For 48 and 18 the steps are (48, 18), (18, 12), (12, 6), (6, 0), so the GCD is 6.
Q3 (b). Servlet to display employee details (5 marks)
index.html
<form action="EmployeeServlet" method="post">
Employee ID: <input type="text" name="empId"><br>
Name: <input type="text" name="empName"><br>
Department: <input type="text" name="dept"><br>
Salary: <input type="text" name="salary"><br>
<input type="submit" value="Submit">
</form>
EmployeeServlet.java
import java.io.*;
import javax.servlet.*; // use jakarta.servlet.* on Tomcat 10 and later
import javax.servlet.annotation.WebServlet;
import javax.servlet.http.*;
@WebServlet("/EmployeeServlet")
public class EmployeeServlet extends HttpServlet {
protected void doPost(HttpServletRequest req, HttpServletResponse res)
throws ServletException, IOException {
res.setContentType("text/html;charset=UTF-8");
PrintWriter out = res.getWriter();
out.println("<html><body><h2>Employee Details</h2><table border='1'>");
out.println("<tr><td>ID</td><td>" + esc(req.getParameter("empId")) + "</td></tr>");
out.println("<tr><td>Name</td><td>" + esc(req.getParameter("empName")) + "</td></tr>");
out.println("<tr><td>Department</td><td>" + esc(req.getParameter("dept")) + "</td></tr>");
out.println("<tr><td>Salary</td><td>" + esc(req.getParameter("salary")) + "</td></tr>");
out.println("</table></body></html>");
}
/* escape user input before printing it, to prevent script injection */
private String esc(String s) {
if (s == null) return "";
return s.replace("&", "&").replace("<", "<").replace(">", ">");
}
}
Q4. JDBC for a student registration system (5 marks)
- Load the driver: add the database driver JAR. Modern JDBC loads it automatically.
- Connect:
DriverManager.getConnection(url, user, password). - Create a statement: use
PreparedStatementwith?placeholders. It is faster to reuse and prevents SQL injection. - Execute:
executeUpdate()for INSERT, UPDATE and DELETE, andexecuteQuery()for SELECT. - Process results: loop through the
ResultSetwithrs.next(). - Handle exceptions and close: catch
SQLExceptionand close resources, preferably with try-with-resources.
import java.sql.*;
public class RegisterStudent {
public static void main(String[] args) {
String url = "jdbc:mysql://localhost:3306/university";
String user = "root";
String pass = "password";
String sql = "INSERT INTO student(roll_no, name, course) VALUES (?, ?, ?)";
// try-with-resources closes the statement and connection automatically
try (Connection con = DriverManager.getConnection(url, user, pass);
PreparedStatement ps = con.prepareStatement(sql)) {
ps.setInt(1, 101);
ps.setString(2, "Asha");
ps.setString(3, "MCA");
int rows = ps.executeUpdate();
System.out.println(rows + " student registered");
// reading data back
try (PreparedStatement q = con.prepareStatement("SELECT roll_no, name FROM student");
ResultSet rs = q.executeQuery()) {
while (rs.next())
System.out.println(rs.getInt("roll_no") + " " + rs.getString("name"));
}
} catch (SQLException e) {
System.out.println("Database error: " + e.getMessage());
}
}
}
For registrations that touch more than one table, call con.setAutoCommit(false), then commit() on success and rollback() in the catch block.
Q5. Spring MVC vs Spring Boot (5 marks)
| Point | Spring MVC | Spring Boot |
|---|---|---|
| Architecture | Web module of Spring that follows Model-View-Controller | Builds on Spring (including MVC) and adds auto-configuration and starters |
| Configuration | Manual: XML or Java config for view resolver, dispatcher servlet and so on | Mostly automatic, with defaults you can override in application.properties |
| Deployment | Packaged as a WAR and deployed to an external Tomcat | Runnable JAR with embedded Tomcat (java -jar) |
| Scalability | Scales well but needs more setup | Same scaling plus easy microservices, health checks and containers |
| Development effort | Higher: more boilerplate | Lower: project starts in minutes |
When to use: choose Spring MVC to maintain an existing application that is already on an app server, or when you need full manual control. Choose Spring Boot for new applications, REST APIs and microservices.
Q6 (a). Hibernate vs JDBC (5 marks)
| Point | JDBC | Hibernate |
|---|---|---|
| Approach | You write SQL and map rows to objects yourself | ORM: maps classes to tables automatically |
| Code | Lots of boilerplate (connection, statement, result set) | Much less code |
| Portability | SQL may be database-specific | Dialects make switching databases easier |
| Features | None built in | Caching, lazy loading, transactions, HQL |
| Limitation | Error-prone and hard to maintain | Learning curve and some overhead |
Scenarios: JDBC suits small utilities and very performance-critical, hand-tuned queries. Hibernate suits large applications with many related entities.
Q6 (b). Spring Data JPA vs a traditional DAO (5 marks)
In a traditional DAO you write an interface, an implementation class, and the code for every operation (save, find, delete) using EntityManager or JDBC. With Spring Data JPA you only declare an interface that extends JpaRepository, and Spring generates the implementation at runtime, including queries derived from method names.
@Entity
public class Student {
@Id @GeneratedValue(strategy = GenerationType.IDENTITY)
private Long id;
private String name;
private String course;
// getters and setters
}
public interface StudentRepository extends JpaRepository<Student, Long> {
List<Student> findByCourse(String course); // query generated from the method name
}
// usage in a service class
repo.save(student); // INSERT or UPDATE
repo.findById(1L); // SELECT by id
repo.findAll(); // SELECT all
repo.deleteById(1L); // DELETE
Q7. Spring Security for a banking application (10 marks)
| Mechanism | What it does in the banking application |
|---|---|
| Authentication | Proves who the user is. A UserDetailsService loads the user from the database and the framework checks the credentials. |
| Authorization | Decides what the user may do. Roles such as CUSTOMER and ADMIN restrict URLs and methods (hasRole, @PreAuthorize). |
| Password encoding | Passwords are stored as BCrypt hashes (salted and slow), never as plain text. |
| Session management | Session fixation protection, a limit on concurrent sessions, session timeout and secure logout. |
Recommended strategy, with justification:
- Use form login over HTTPS with BCrypt password hashes, because a bank cannot risk leaked or guessable passwords.
- Use role-based access control with least privilege, so customers see only their own accounts and only admins reach admin pages.
- Add a second factor (an OTP) for high-risk actions such as new payees or large transfers.
- Keep CSRF protection on, migrate the session on login, allow one session per user and use a short timeout.
- Lock the account after repeated failed logins and log security events for audit.
@Configuration
@EnableWebSecurity
@EnableMethodSecurity
public class SecurityConfig {
@Bean
SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
http
.authorizeHttpRequests(a -> a
.requestMatchers("/login", "/css/**").permitAll()
.requestMatchers("/admin/**").hasRole("ADMIN")
.requestMatchers("/accounts/**").hasAnyRole("CUSTOMER", "ADMIN")
.anyRequest().authenticated())
.formLogin(f -> f.loginPage("/login").defaultSuccessUrl("/dashboard", true))
.logout(l -> l.logoutSuccessUrl("/login?logout"))
.sessionManagement(s -> s
.sessionFixation().migrateSession()
.maximumSessions(1));
return http.build();
}
@Bean
PasswordEncoder passwordEncoder() {
return new BCryptPasswordEncoder(); // salted, slow hash
}
}
Q8 (a). Software testing in web applications (5 marks)
- Unit testing: tests one class or method alone (JUnit, Mockito). It is fast and finds logic errors early.
- Integration testing: tests that layers work together, such as a controller, service and database (
@SpringBootTest, MockMvc). - Security testing: checks login, role restrictions, SQL injection, XSS and CSRF defences so that attackers cannot misuse the application.
Together they catch defects at different levels, make later changes safe and raise the quality of the application.
Q8 (b). Exception handling and logging (5 marks)
Exception handling keeps the application running and shows users a clear message instead of a stack trace. In Spring, a @ControllerAdvice class with @ExceptionHandler methods handles errors in one place.
Logging (SLF4J with Logback) records what the application did, using levels such as DEBUG, INFO, WARN and ERROR. Good logs show who did what and when, which makes bugs easier to find, supports audits and helps monitor production. Never log passwords or card numbers.
Q9. Library Management Web Application with Spring Boot (10 marks)
MVC architecture
Browser
|
Spring Security filter chain (login, roles)
|
Controller (BookController, LoanController) --> View (Thymeleaf pages)
|
Service (BookService, LoanService)
|
Repository (Spring Data JPA)
|
Database (MySQL)
Entities and relationships
- One user can have many loans (AppUser 1 — * Loan).
- One book can appear in many loans over time (Book 1 — * Loan).
- Loan connects a user to a book with issue, due and return dates.
@Entity
public class Book {
@Id @GeneratedValue(strategy = GenerationType.IDENTITY)
private Long id;
private String title;
private String author;
private String isbn;
private boolean available = true;
// getters and setters
}
@Entity
public class AppUser {
@Id @GeneratedValue(strategy = GenerationType.IDENTITY)
private Long id;
private String name;
@Column(unique = true)
private String email;
private String password; // stored as a BCrypt hash
private String role; // ADMIN or MEMBER
// getters and setters
}
@Entity
public class Loan {
@Id @GeneratedValue(strategy = GenerationType.IDENTITY)
private Long id;
@ManyToOne private Book book;
@ManyToOne private AppUser user;
private LocalDate issueDate;
private LocalDate dueDate;
private LocalDate returnDate;
// getters and setters
}
Repository, Service and Controller
// Repository
public interface BookRepository extends JpaRepository<Book, Long> {
List<Book> findByTitleContainingIgnoreCase(String title);
}
public interface UserRepository extends JpaRepository<AppUser, Long> {
Optional<AppUser> findByEmail(String email);
}
// Service
@Service
public class BookService {
private final BookRepository repo;
public BookService(BookRepository repo) { this.repo = repo; }
public List<Book> findAll() { return repo.findAll(); }
public Book save(Book b) { return repo.save(b); }
public void delete(Long id) { repo.deleteById(id); }
}
// Controller
@Controller
@RequestMapping("/books")
public class BookController {
private final BookService service;
public BookController(BookService service) { this.service = service; }
@GetMapping
public String list(Model model) {
model.addAttribute("books", service.findAll());
return "books"; // books.html (Thymeleaf)
}
@PostMapping
public String save(@ModelAttribute Book book) {
service.save(book); // Create and Update
return "redirect:/books";
}
@PostMapping("/{id}/delete")
public String delete(@PathVariable Long id) {
service.delete(id); // Delete
return "redirect:/books";
}
}
| Operation | Request | Method |
|---|---|---|
| Create | POST /books | service.save(book) |
| Read | GET /books | service.findAll() |
| Update | POST /books (with the id filled in) | service.save(book) |
| Delete | POST /books/{id}/delete | service.delete(id) |
The same pattern is repeated for users and loans.
Login module using Spring Security: load users from the database with UserDetailsService, and reuse the SecurityConfig from Q7 with roles ADMIN (manage books and users) and MEMBER (search and borrow).
@Service
public class AppUserDetailsService implements UserDetailsService {
private final UserRepository users;
public AppUserDetailsService(UserRepository users) { this.users = users; }
@Override
public UserDetails loadUserByUsername(String email) {
AppUser u = users.findByEmail(email)
.orElseThrow(() -> new UsernameNotFoundException("User not found"));
return org.springframework.security.core.userdetails.User
.withUsername(u.getEmail())
.password(u.getPassword()) // BCrypt hash from the database
.roles(u.getRole())
.build();
}
}
Application workflow
- The user opens the site and is redirected to the login page.
- Spring Security checks the email and BCrypt password, then opens the dashboard for the user's role.
- An admin adds, edits or deletes books. A member searches for a book.
- When a member borrows a book,
LoanServicecreates a Loan with a due date and sets the book as not available. - On return, the return date is stored and the book becomes available again. Overdue loans can be listed for the admin.
Submission and viva tips
- Submit the assignment to the Coordinator of your Study Centre on or before the last date. Keep a photocopy and the receipt.
- Write the final copy in your own words and your own handwriting where handwritten work is required. Use this page to understand the answer, not to copy it line by line.
- Put your name, enrolment number, course code (MCS-220), assignment number and study centre code on the first page.
- The viva voce is compulsory. IGNOU states that if you submit the assignment but do not attend the viva, the assignment is marked ZERO.
- Practise explaining every program or answer aloud. The 20 viva marks are the easiest marks to lose.
Get the full solution
This page gives worked answers so you can understand each question. If you need help preparing the final copy of the MCS-220 assignment, ask us from the Contact page. Always compare the questions with your own booklet first.
Frequently asked questions
Is the MCS-220 assignment the same for MCA_NEW and MCAOL?
Both use the same course. The assignment code in the 2026-27 set covers MCA_NEW and MCAOL, but always check your own booklet.
Do I need to build the full Library Management project?
Question 9 asks for a design with diagrams and code snippets, so a full running project is not needed. Show the architecture, entities, key classes and the workflow.
Which Java and Spring versions should I mention?
Use the versions in your course material. The examples here use Java 17 or later and Spring Boot 3 style, which uses the jakarta package names.
How many marks come from the viva?
20 marks. Be ready to explain every diagram and code snippet you submit.
Back to IGNOU MCA Solved Assignments 2026-27 (All Semesters).
etutor12 is an independent study blog and is not affiliated with IGNOU. Questions and dates are taken from IGNOU assignment booklets and public notices; always confirm them on ignou.ac.in and in your own booklet.
