How to conduct a secure online exam
Exam security covers two things that are easy to conflate: verifying the student, and protecting the exam content. What an institution decides and sets up.

In short
Identity, content and environment. The administrative side of exam security, what you decide and set up, rather than what the software does.
Conducting a secure online exam means confirming the right student is taking it, protecting the exam questions from being leaked or shared, and having a clear policy in place before anything goes wrong, not relying on any single tool to cover all three at once. Security here isn't one setting you switch on; it's a set of decisions made at the design and policy level, before the exam window even opens.
This guide walks through those decisions in order: identity, content protection, policy, and incident response, so you can build a secure exam process appropriate to your specific exam's stakes. For the broader picture of running online exams well, see our complete guide to online exams.
What "Secure" Actually Means for an Online Exam
"Secure" gets used as a single catch-all word, but it's really covering three separate concerns that call for different solutions.
Identity verification
- confirming the person taking the exam is actually the enrolled student, not someone elseContent protection
- making sure exam questions themselves don't leak, get shared in advance, or circulate after the factEnvironment integrity
- some level of assurance that the exam is being taken under fair conditions, without unauthorized help
Treating these as one problem is a common mistake. A platform can verify identity perfectly and still leak exam content through a poorly managed question bank, or protect content well while doing nothing to confirm who's actually answering. Each piece needs its own deliberate decision, not a single checkbox.
Verify Identity Before the Exam Starts
Identity verification is the foundation everything else builds on - a perfectly secure exam is worthless if you can't confirm who actually took it.

- Require a unique login tied to the student's institutional account, not a shared or generic access link that could be forwarded
- Add a verification step at the start of the exam, such as a one-time code sent to the student's registered email, so access is tied to something only that student can receive
- Use a photo check for higher-stakes exams, where confirming a live match against an enrolled student's photo matters more than for a low-stakes weekly quiz
- Match the verification level to the exam's stakes - a final exam or licensing-adjacent test warrants more rigor than a formative quiz
TunnelQuiz builds email OTP verification and periodic face photo checks directly into the exam flow, so identity confirmation happens automatically at the point of access rather than as a separate manual step your team has to manage.
Protect the Exam Content Itself
Content security is a different problem from identity - even with perfect identity verification, a leaked question bank undermines the whole exam for everyone who takes it after the leak.
- Use a large enough question bank that no two students reliably see an identical exam, reducing the value of any single leaked question
- Randomize question and answer order per student, so even shared answers by position ("number 3 is B") don't transfer between students
- Release exam content only within the testing window, not in advance, and avoid distributing a full question set by email or shared document beforehand
- Retire and refresh questions periodically, especially for any exam reused across multiple terms or cohorts, since older questions are more likely to have circulated
Randomization and reusable, refreshable test templates are two of the more practical tools here. TunnelQuiz's template and shuffling features let you build a question bank once, reuse it across cohorts, and have both question and answer order shuffle automatically per student without manual setup each time.
Decide on Environment and Monitoring Proportionate to Stakes
Beyond identity and content, some exams call for a layer of environment monitoring, confirming the conditions the exam is being taken under. This is where AI-based behavioral detection, webcam monitoring, and tab-switching alerts come in, and it's a deep enough topic to deserve its own dedicated treatment rather than a few bullet points here.
The short version: monitoring intensity should scale with exam stakes, not apply uniformly by default. For the full technical breakdown of how this technology works, what it can and can't catch, and how to evaluate whether a specific monitoring setup is genuinely secure, read Are Online Proctored Exams Secure?
Build a Clear Policy Before Exam Day
A lot of what people call a "security failure" is actually a policy gap, students genuinely unsure what's allowed, or an institution with no clear plan for handling an ambiguous situation.
- Publish the rules explicitly, not buried in a syllabus: what materials are permitted, what counts as unauthorized help, and what verification steps will occur
- Explain the consequences of a violation in advance, so nothing feels like a surprise introduced after the fact
- Communicate what identity verification and monitoring will actually involve, so students aren't caught off guard by a step they weren't told about
- Give students a real appeals process, with a defined timeline, rather than leaving disputes to an informal email exchange
Institutions that communicate this clearly before exam day consistently see fewer disputes afterward - most complaints trace back to a communication gap, not an actual security failure.
What to Do If Something Goes Wrong
Even a well-designed process needs a plan for when something goes sideways - deciding your response in the moment, under time pressure, tends to produce worse outcomes than having a plan set in advance.

Suspected impersonation
- have a defined process for pausing the exam, verifying identity through a secondary method, and documenting the incident, rather than making an ad hoc callSuspected content leak
- know in advance whether you can swap to a backup question set quickly, and have a process for identifying how widely the leak spread before deciding next stepsTechnical failure mid-exam
- a clear, published policy for what happens if a student's connection drops (extended time, a retake, a grace period) removes ambiguity for both the student and the instructor in the momentA flagged but likely innocent incident
- route it through human review before treating it as a violation, since automatic penalties for ambiguous situations tend to create the most disputes
Having these plans written down before an exam, even briefly, turns an incident from a crisis into a known procedure.
The Short Version
Conducting a secure online exam means treating identity verification, content protection, and monitoring as three separate decisions, each proportionate to the exam's actual stakes, backed by a clear policy and a plan for when something goes wrong. No single tool covers all of this - it's a layered process, built deliberately rather than assembled after the first problem shows up.
If you're setting this up for the first time, TunnelQuiz handles the identity and content-protection layers directly, OTP and photo verification, shuffled questions, and reusable templates, so you can build a secure exam process without stitching together several separate tools.
Frequently asked questions
What does it mean for an online exam to be secure?
A secure online exam confirms the right student is taking it, protects the exam content from leaking or being shared, and has a clear policy in place for handling problems - it's a combination of identity verification, content protection, and process, not a single feature. No one measure alone makes an exam fully secure.
How do you verify student identity in an online exam?
Common methods include requiring login through a unique institutional account, sending a one-time verification code to a registered email, and for higher-stakes exams, a live photo check matched against an enrolled student's record. The right level of verification should scale with how much is riding on the exam result.
Can online exam content be leaked or shared?
Yes, this is a genuine risk, particularly for exams reused across multiple terms or cohorts, which is why randomizing questions per student and maintaining a large enough question bank matters. Releasing content only within the testing window, rather than distributing it in advance, also reduces this risk significantly.
Is proctoring the same thing as exam security?
No, proctoring, specifically AI or human monitoring during the exam session, is one layer of exam security, alongside identity verification and content protection, which are separate concerns. A secure exam needs attention to all of these, not just monitoring technology alone.
Do all online exams need the same level of security?
No, security measures should be proportionate to the exam's stakes, with a low-stakes formative quiz needing far less rigor than a final exam or licensing-adjacent test. Applying maximum security measures to every assessment regardless of stakes tends to create unnecessary friction without a matching benefit.