Safe Exam Browser (SEB) is a third-party application designed to enable digital assessment events to be delivered in a locked-down environment. This can be useful if you want to establish an additional security layer for the exam so that, for example, candidates cannot have access to the internet or other applications on the machine.
To implement SEB you will need to use a combination of the SEB application and a configuration file to achieve the desired security settings.
There are generally two common scenarios in which SEB might be configured:
- Dedicated exam devices (e.g. an on-campus computer cluster): If you have one or several devices that are regularly used to deliver exams, you will likely set them up and not change their configuration very often. In these cases, every time Safe Exam Browser is started, it will default to your installed settings. Although we recommend setting up a configuration file, it is also possible to use Safe Exam Browser to set up a single device without a configuration file.
- Bring your own device (BYOD): In this case, candidates will install Safe Exam Browser on their own devices and must run your exam configuration file to apply the appropriate settings. Safe Exam Browser will only use those settings temporarily and default back to the original settings when it closes (which can be helpful if candidates need to use the SEB software to take exams at other organisations).
The risr/ assess system also offers a native enhanced SEB integration whereby information about the candidate's SEB configuration is appended to the responses they submit during the exam and can be used to check the compliance of the candidate's machine. For further information, see the section in this article on using browser and header keys.
Setup and configuration
The general process involves four key steps:
-
For both dedicated setups and BYOD exams, the first step is to download the SEB application to the machine(s) that will be used to take the exams.
The most up-to-date version of SEB (in Windows, MacOS and iOS formats) can be downloaded from here: https://safeexambrowser.org/download_en.html.
Once you have downloaded and opened the file, follow the on screen instructions specific to your operating system to install the application on the machine.
-
The route to the configuration options differs slightly between Mac and Windows.
- On Mac, open the SEB application and click on Settings.
- On Windows, select the Safe Exam Browser folder within Applications and the SEB Configuration Tool.
From this point, there are some very slight differences between Windows and MacOS, although they look broadly the same. The instructions below detail the process on Mac OS, but you can refer to the separate SEB user manuals for MacOS and Windows.
Go to the General tab.
- In the Start URL field, you will need to enter the URL for your instance of assess for browser (e.g.
https://<your_domain>.assess.risr.global/html5) - SEB can use up to three different sets of passwords, 2 of which are set in the General tab:
- "Administrator" password. Setting this password keeps the configuration protected from unauthorised editing, so it should only be used by the person setting up Safe Exam Browser.
- "Quit/unlock" password. If a quit password is set, it won't be possible for anyone to close or restart SEB during the exam without the password. This password is usually used by the Invigilator or exam administrator should they need to access the device's operating system for diagnosing problems or to unlock and close SEB at the end of an exam. You might not need a password if you feel that the environment in which the exam is being run is sufficiently secure.
Go to the Config File tab.
-
Use config file for...: By default, this is set to "configuring clients".
- For dedicated exam devices: You can leave this setting at Configuring clients. This means that if the configuration file is run on a machine with SEB, the application will be updated to always use these same settings every time it is launched.
- For BYOD: If you only want the settings to be temporary, as may be the case for BYOD, change this setting to Starting exams.
- Settings Password: If you intend on creating a settings file that will be stored or distributed, you might wish to create a password so it can't be read without authorisation. This password will be used each time the file is opened, so it will be needed by anyone who is installing the configuration on a dedicated device or by candidates on their own devices.
The settings described here are only the minimum settings needed for setup. SEB gives you lots of control over what candidates can see and use during an exam, so we would encourage you to take the opportunity to look through and customise it to your own specific needs by checking the manuals for Windows and MacOS.
Finally, you will need to save the settings. Still, within the Config File tab, you have two options:
- If you ONLY want to set up the device you are currently working on, click the Use Current Settings to ... Configure Client. In most cases, the other option will apply.
- If you want to create a configuration file, select Config File Editing ... Save Settings As, and then save the file to anywhere you can access later.
Once you have completed the steps, close the application.
To make use of the risr/ assess integration that checks the responses are being sent from a valid instance of SEB, you will also need to enable header keys during configuration. Please see the section on Using browser and header keys for full information.
-
How you use the configuration file will depend on whether you are setting up dedicated devices or distributing the file to candidates to use on their device.
-
If you set up a single device to Use Current Settings to ... Configure Client, then there is nothing else to do - Safe Exam Browser has been set up with your settings.
However, if you created a configuration file, you will now need to run the configuration file on any machines you wish to set up.
- Make sure that Safe Exam Browser is installed on the device.
- Save the configuration file on the machine.
- Double click on the file to run it. If you added a settings password, you will be prompted to enter it.
- You will see a confirmation message saying that the configuration has been applied. You can either open Safe Exam Browser or quit.
- Each time the main Safe Exam Browser application is opened, it will now use the default settings you have created
Within managed environments, it is also possible to deploy the files directly to devices, which you may find more efficient. For more information, please check the Safe Exam Browser user manual.
-
If you will asking candidates to use their own devices, you will need to give them instructions and inform them how to install the configuration file. Below are some example instructions which may need to be amended depending on how you have set up the configuration file.
-
-
For dedicated devices, every time you launch Safe Exam Browser, it will navigate to the available exams that you have published to risr/ assess for browser. In the case of BYOD, clicking the file will open Safe Exam Browser with the settings you have provided.
Candidates will login as normal but will not be able to exit risr/ assess or perform any other actions other than those permitted by SEB.
Once the exam is finished, you should ensure that the candidate has logged out of assess for browser. To shut down SEB, it might be necessary for the candidates to enter the quit passcode if one has been set.
For dedicated devices, it depends on your set up, as you may wish to leave Safe Exam Browser running. Otherwise, the quit password will need to be entered if you have created one.
Using browser and header keys
To ensure that SEB is both being used and is correctly configured and secured, it is possible to check that the candidate is using the correct SEB settings for the exam. This is achieved by using header keys appended to the candidate's responses, which risr/ assess can then validate. Responses that do not have the expected validation keys appended will be held for review in the system.
A Header Key is an alphanumeric code used to verify which version of Safe Exam Browser is being used by a candidate. There are three possible levels of security:
| Configuration | Description |
| SEB with no listed keys | This is the simplest version that checks only that SEB is being used during an exam but has the disadvantage that the candidate may not be using SEB with your configured settings. |
| SEB with configuration keys (CK) | This checks that SEB is being used with the correct configuration. More complex but also more secure. |
| SEB with browser exam keys (BEK) | This checks that a specific version of SEB is being used with the correct configuration. The most effort is because a key is required for each version of SEB on each operating system. |
It is possible to use SEB without any key checks (i.e. SEB with no listed keys). For example, if you are using an exam suite where all exam devices are centrally managed. The options chosen will depend on the specific requirements of your college and staff: balancing security, effort (of the exam administrators and candidates) and risk of human error in set up.
Once a SEB configuration file has been created, it is possible to reuse the same configuration file and keys for any future exams to reduce administration time. The key will still need to be added to each exam in risr/ assess.
-
Once SEB has been configured as required, go to Settings, then Exam ensure to check the box Use Browser & Config Keys. The Browser Exam Key (BEK) and Config Key (CK) should be copied at this point.
The keys change every time that the configuration file is changed and saved. This means that if you make a change to the config file, you must paste the new keys into risr/ assess every time. If you do not do so, all of the responses will be marked as invalid when you run the exam.
The CK will be the same across all versions of SEB and operating systems, but the BEK will be unique for each version and operating system.
Even if specific config or browser keys aren’t checked, the setting to use keys will still be required if Practique is to check that SEB is being used.
-
When creating an Exam, the Require Safe Exam Browser option needs to be set to Enable. This is located in the initial Exam Settings Page. Once selected, this will display the SEB Configuration Key list (CK) and SEB Browser Exam Key list (BEK) fields.
Depending on the required setup, either no or several keys will need to be entered into these boxes. Each key should be entered on its own line.
-
During an Exam, responses received by risr/ assess will be checked for the presence of the SEB Header Keys. If the system determines that a response is missing a required header or the header is incorrect, it will mark the candidate's response as invalid with the warning Failed: SEB Check. The responses will then need to be rejected or accepted as appropriate by the exam administrator. Details of the response can be seen using the ‘Toggle details’ link below the error.
For further details, see the article on dealing with invalid responses.
For security reasons, the SEB Header Key will not match the CK or the BEK entered in the Edit Exam Details screen. Practique uses the Header Key and the exam address to generate the expected header and compares it to the Header Key that SEB sends to the candidate. Response Header Keys will also be unique to each candidate.
Suggested candidate instructions
If you will asking candidates to use their own devices, you will need to give them instructions and inform them how to install the configuration file. Below are some suggested instructions which may need to be amended depending on how you have set up the configuration file.
Candidate instructions
To take the exam in a secure environment, you will need to install Safe Exam Browser (SEB) and run the Exam configuration file (supplied by the exam provider). risr/ assess can run on any device that has a modern browser but does not support lockdown functionality on Android Tablets.
Candidates will need a device that:
- Supports a modern browser (Firefox, Chrome)
- Has sufficient battery life for the duration of the exam
- At a minimum has an internet connection to download and start the exam
- At a minimum has an internet connection to upload the exam responses at the end of the exam.
Follow the steps below to set up your device and start the exam:
At least one week before the scheduled exam
- Download Safe Exam Browser from by clicking on the link, depending on which device you own. Windows PC or Laptop, Mac or iPad. Your download should start automatically if it does not, follow the instructions to download Safe Exam Browser.
- When the download is complete, follow the instructions to install it on your device. You will only have to do this for your exams, and you can delete the file once the exam is over.
On the day of the exam
- Separately, you will have received an exam configuration file from your assessment provider.
- When instructed, open this file. If necessary, it may also be necessary to enter a password which the assessment provide will give you. You will be taken to your exam (You will need to be connected to the internet for this to work)
- Candidates will login to the exam as instructed by the invigilator or exam administrator.
- Candidates will not be able to exit Practique, perform any other actions than permitted by Safe Exam Browser or exit Safe Exam Browser.
- To exit the exam and Safe Exam Browser, you can click "Quit SEB" in the top right hand corner. Candidates will need the Quit passcode to exit, and this will be provided by the invigilator or exam administrator at the end of the exam.
Comments
0 comments
Please sign in to leave a comment.