HSC Software Engineering exam 2026Exam: Tue 27 Oct · NESA timetable
Your HSC Software Engineering exam:
When and how long
- Software Engineering9.50 am to 12.20 pm2 h 20 min plus 10 min reading time
NESA: the exam start time shown on your timetable is when reading time begins, and you must arrive well before it. Finishing times marked approximate are shown as approx.
Source: 2026 HSC written exam timetable (NESA), checked Wednesday 23 September 2026. Where a start time, reading time or duration isn't shown, the timetable doesn't publish it: check your personal timetable and the front of your paper.
Paper format
Higher School Certificate Examination - Software Engineering: 80 marks, 2 h 20 min writing time plus 10 minutes reading time.
- Objective response20 marks
- Short answer60 marks
NESA HSC exam specification for Software Engineering 11-12 (2022): an online exam of 2 hours 30 minutes including 10 minutes reading time, 80 marks. About 20 marks of objective-response items (14 to 18 items, each worth 1 to 4 marks) and about 60 marks of short-answer items (16 to 18 items). This desk mock uses 1-mark multiple choice for the objective items.
From the official specification: source.
What the exam covers
We don't have past-paper frequency data for this exam, so here is the course, module by module. Make sure every module is covered.
Night-before and exam-morning checklists
The night before
- Check your personalised timetable on Students Online: the start time shown is when reading time begins.[2]
- Confirm your venue and the start time.[1]
- Pack a clear bag: several black pens (no erasable ink), 2B pencils, sharpener, eraser and a ruler.[1]
- Pack an approved calculator (check NESA's list) and a compass or protractor if the exam needs them.[1]
- Fill a clear, label-free water bottle.[1]
- A plain watch only if you want one (no smart or programmable watch); it goes on the desk.[1]
- Stop revising around 7 to 8 pm, set two alarms and sleep.[1]
Exam morning
- Eat a real breakfast.[1]
- Arrive well before the start time to allow for seating and checks.[2]
- Leave your phone and other electronic devices outside the exam room.[1]
- Use the bathroom before you go in.[1]
- In reading time, read and plan only: no writing, marking or annotating.[1]
- You can't leave in the first hour or the last 15 minutes.[1]
Exam-week survival kit: The last 7 days · The night before and exam morning · What to bring, and what's banned · How to use reading time · If you're sick or something goes wrong · Handling exam-week stress.
Last-week revision
HSC Software Engineering cram sheet
Key formulas, definitions and facts copied from our Software Engineering syllabus pages. One page when printed.
Module 2: Programming for the Web
SQL injection: attacker input changes the STRUCTURE of a SQL query. Fixed with parameterised queries.
Browser (client): on the user's device; renders the UI; sends HTTP requests.
200 OK: successful GET/PUT/DELETE with a body to return.
CREATE TABLE: defines the columns, primary key and constraints for a new table (structure only, no data).
Module 1: Secure Software Architecture
- Signup: password + unique salt -> slow hash function (bcrypt/Argon2) -> store only the hash (and salt).
- Login: submitted password + stored salt -> same hash function -> compare to stored hash. Match = success.
- The original password is never stored anywhere, at any point, after the initial hashing step.
Authentication answers "who are you?" and happens first. Authorisation answers "what are you allowed to do?" and depends on the identity authentication produces.
Symmetric (AES): one shared key, very fast (roughly 950 MB/s for AES-256 on typical hardware), the key itself must be exchanged securely before use.
Confidentiality: only authorised users can READ sensitive data (defended by encryption, access control).
Module 3: Software Automation
Ask: "does each training example already carry a correct answer?"
No industrial system uses only one learning type; markers reward naming the DOMINANT type plus recognising the others in play.
Module 4: Software Engineering Project
Waterfall: sequential phase gates, requirements locked up front, one release at the end. Best when requirements are stable and traceability/sign-off matters.
Unit: one function/class, dependencies mocked, milliseconds, run on every commit.
Continuous integration: every change is automatically built and tested. No claim about release.