Academic Model Answers
Library for UK Postgraduates

Browse tutor-verified model answers across MBA, Law, Finance, Research Methods and more. Use as study references for your own work.

200 model answers 30+ subjects covered 50+ UK universities
Find your assignment

Search the Library

Filter by keyword, subject, or both. Updates live as new model answers are added to our portal.

Filtering by “Authentication” Clear filters

Available Model Answers (9)

Real-time Database Sync
Cyber Security / Applied Cryptography / Secure Systems Design 2,500 words

Secure Property Contract Exchange: Cryptographic Protocol Design, Threat Modelling and Post-Quantum Readiness

This Applied Theory of Cyber Security and Secure Design coursework places students in the role of a cyber security consultant engaged by Hackit & Run LLP, a legal firm specialising in UK and international property transactions. The firm wishes to implement a secure digital system for handling, exchanging and legally signing property contracts. Students must design and evaluate a secure communication protocol supporting interactions between the buyer’s solicitor, the seller’s solicitor and the buyer while addressing both first-time communications and previously established secure relationships. 11b17febb9eeb4570f76f6ca95a831a… Section A – Cryptographic Protocol Design, worth 45%, requires a complete secure communication protocol. Students must explain how trust is initially established, how later communications can be simplified without weakening confidentiality, integrity or availability, and how the buyer can digitally sign a contract in a manner enforceable under UK law. The design must justify specific cryptographic algorithms for functions such as key exchange, bulk encryption, digital signatures and hashing. The protocol must be presented through both a sequence diagram showing message flows and cryptographic operations and pseudocode explaining the key algorithmic stages. 11b17febb9eeb4570f76f6ca95a831a… Section B – Threat Modelling, worth 20%, requires a focused analysis using the STRIDE methodology. Students identify three realistic threats from different STRIDE categories and analyse the attack vector, asset at risk and potential effect on the legal transaction. Each threat must then be connected back to specific protocol defences, with residual risks acknowledged where controls cannot provide complete mitigation. The guidance encourages consideration of issues such as social engineering, insider threats, key-management failures and availability risks in addition to purely cryptographic attacks. 11b17febb9eeb4570f76f6ca95a831a… Section C – Security Evaluation Against Standards, worth 15%, requires students to evaluate the proposed system against a recognised cybersecurity standard or framework. Options include ISO/IEC 27001:2022, Common Criteria (ISO/IEC 15408) and the OWASP Application Security Verification Standard. Students select three or four directly relevant controls or requirements, assess whether the proposed design satisfies them, identify gaps and recommend specific improvements. 11b17febb9eeb4570f76f6ca95a831a… Section D – Post-Quantum Readiness and Critical Reflection, worth 15%, examines how a future quantum-capable adversary could affect the protocol. Students identify vulnerable cryptographic components, discuss the NIST Post-Quantum Cryptography standardisation programme, and examine replacement algorithms such as ML-KEM for key establishment and ML-DSA for digital signatures. They must also evaluate a hybrid migration strategy combining classical and post-quantum algorithms, considering performance overhead, backward compatibility and the legal admissibility of post-quantum digital signatures. 11b17febb9eeb4570f76f6ca95a831a… The remaining 5% evaluates professional report quality, logical structure, technical language, integration of diagrams and consistent CUHarvard referencing. Higher-quality work is expected to demonstrate a sophisticated trust model, clear traceability between threats and controls, precise standards mapping, practical security recommendations and well-evidenced analysis of post-quantum migration. 11b17febb9eeb4570f76f6ca95a831a… Important for the public Reference Library: the brief states that the assessment document is intended only for Coventry University Group students and must not be passed to third parties or posted on any website. Therefore, publish only an original high-level description such as the overview above; do not upload or reproduce the original assignment brief publicly. 11b17febb9eeb4570f76f6ca95a831a…

Read Model Answer →
Cybersecurity / Security Operations

Catnip Games International: SOC Automation and Incident Response Platform

This cybersecurity project presents the design and implementation of a prototype Security Operations Centre (SOC) automation and incident-response platform for Catnip Games International. The scenario addresses security challenges affecting a gaming organisation operating more than 300 Linux servers across two data centres, including credential-stuffing bot attacks, compromised player accounts, phishing campaigns and delayed coordination during security incidents. Catnip_Games_SOC_Complete Catnip_Games_SOC_Complete The proposed solution integrates TheHive 5, Cortex 3, Elasticsearch, Cassandra and Python-based automation, with MISP explored for threat-intelligence integration. TheHive functions as the central incident and case-management platform, Cortex provides automated observable analysis, Elasticsearch supports search and log storage, Cassandra provides persistent case and alert storage, and Python scripts automate alert ingestion and workflow activities through REST APIs. Catnip_Games_SOC_Complete Catnip_Games_SOC_Complete Implementation includes environment configuration, Docker deployment, API integration, automated alert generation, incident-response playbooks, KPI monitoring and backup procedures. Three attack scenarios are modelled: bot attacks, account takeover and phishing. Alerts are automatically ingested into TheHive, converted into cases and processed through analyst triage, investigation and resolution workflows. Catnip_Games_SOC_Complete Catnip_Games_SOC_Complete The project also develops structured response playbooks covering triage, containment, investigation, recovery and post-incident actions for each security scenario. Operational metrics are visualised through a KPI dashboard measuring alert volumes, response times, Mean Time to Detect (MTTD), Mean Time to Respond/Resolve (MTTR) and platform availability. Catnip_Games_SOC_Complete Catnip_Games_SOC_Complete Overall, the work demonstrates practical application of SOC architecture, security automation, incident management, threat analysis, containerised infrastructure, API-based integration, operational metrics and cyber-response procedures within a realistic gaming-industry security scenario. Catnip_Games_SOC_Complete Overview word count: approximately 330 words. Important before putting the presentation on a public Reference Library: redact any API keys/authentication tokens and other live credentials shown in the technical slides. The presentation includes API-key material in the Cortex and Python automation sections, so those credentials should also be revoked/rotated if they were ever active. Catnip_Games_SOC_Complete Catnip_Games_SOC_Complete

Read Model Answer →
Operating Systems and Networks 2,000 words

Security of Operating Systems and Networks – Individual Assignment

This individual assignment focuses on the security of operating systems and computer networks. Students are required to produce a professional technical report of approximately 2,000 words demonstrating a deep and systematic understanding of operating-system security, networking functions, security threats, vulnerabilities and practical security testing. The assessment carries 50% and forms 100% of the module assessment. Students are expected to support their work with appropriate technical evidence, images showing practical steps and relevant sources. The assignment uses a business scenario involving Net-Tech, a small and medium-sized technology-services enterprise. The organisation is concerned about the security of its proposed system, including operating-system attacks such as buffer overflow and network threats such as hacking and phishing. Students are required to investigate, design and experiment with the features and functions of a web server used to serve the company's website, while assessing the security landscape and presenting findings that can support appropriate organisational security decisions. As part of the practical work, students must create a prototype Net-Tech network test rig. This includes creating two users, with one configured as a superuser and another as a standard user, applying appropriate baseline security measures, installing suitable software and identifying vulnerabilities, using appropriate tools to conduct security tests, and writing scripts to automate repetitive tasks. Students must document assumptions and parameters used within the project, including further security implementations and recommendations such as the use of a suitable database for a database-driven website. The report is structured around introduction, background research, pre-engagement, engagement and post-engagement activities. The introduction should explain the business scenario, assumptions, aims, objectives, deliverables, available skills and resources, constraints and project plan. The background research should address common vulnerabilities, threats, risk models, security-testing approaches, relevant attack and testing tools, legal and organisational requirements, and ethical, social, professional and sustainability considerations. The pre-engagement section covers the test-rig setup and testing strategy. The engagement section requires practical comparison and demonstration of operating-system and network security, including user authentication, file and directory permissions, protection against stack-overflow attacks, network weaknesses, operating-system discovery, firewalls, listening ports, network statistics, prevention of denial-of-service attacks and scripting for automation. The post-engagement section requires a summary of the work, deductions and limitations, mitigation measures and recommendations, and personal reflection. The assessment requires students to use relevant sources, provide a bibliography and demonstrate appropriate analysis, evaluation and reflection. The assignment is designed to assess learning outcomes relating to knowledge of network security threats and the development of complex software and scripts relevant to operating systems and computer networks.

Read Model Answer →
Networking and Security Practice

Networking and Security Practice – Recorded Demonstration

This assessment for the MSc Cyber Security module Networking and Security Practice is a practical recorded-demonstration coursework designed to assess students' ability to configure, secure, troubleshoot and monitor a virtualised sandbox network. The assessment contributes 60% of the module mark and consists of four recorded demonstration videos, with each video limited to a maximum of five minutes. The completed videos are submitted through a Moodle quiz as video files or accessible links. The practical environment uses virtual machines running Ubuntu Server and Ubuntu Desktop on VirtualBox or UTM. Students deploy a four-machine architecture consisting of a Gateway, Webserver, Workstation and Zabbix-Server. The Gateway acts as the router, firewall and NAT gateway; the Webserver hosts an Nginx web server; the Workstation is used for administration and testing; and the Zabbix-Server provides network monitoring. The architecture requires appropriate network interfaces, IP addresses, routing and communication between the different internal networks. The coursework develops practical networking and system administration skills through several phases. Students install and configure operating systems, allocate virtual machine resources, configure static IP addresses, enable IP forwarding and NAT masquerading, and implement firewall rules using iptables. They also develop command-line proficiency using networking, DNS, security, remote-access and web tools including ping, traceroute, ss, nslookup, dig, nmap, Wireshark, netcat, SSH, SCP, rsync, curl and wget. Students must also configure secure remote access and deploy an Nginx web server. SSH must be hardened by disabling password authentication and root login, while key-based authentication is used for secure access. The Webserver must contain a customised landing page showing the student's name and student ID, which is accessed from the Workstation. The monitoring component requires installation and configuration of Zabbix, deployment of agents across the virtual machines, host monitoring, a customised dashboard containing at least five live-data widgets and configured alerts or triggers. Students must explain what their selected monitoring elements measure and why they are operationally useful. The traffic-analysis component uses Wireshark to capture and examine HTTP, ICMP and DNS traffic. Students apply appropriate filters, identify protocols using the Protocol Hierarchy and discuss the security implications of unencrypted HTTP traffic, including secure alternatives such as HTTPS and DNS over TLS. The security-evaluation component uses Nmap within the isolated virtualised sandbox to identify open ports and services, assess vulnerabilities and recommend mitigations. Students must also demonstrate iptables forwarding and NAT masquerading rules. The four videos cover Network Infrastructure, Network Monitoring, Traffic Analysis and Security Evaluation. The assessment is marked out of 100, with 35 marks allocated to Network Infrastructure, 25 to Network Monitoring, 20 to Traffic Analysis and 20 to Security Evaluation. Students are expected to provide clear voice narration, explain commands and outputs, demonstrate technical understanding and critically relate their work to network security. The assessment develops employability skills in Linux administration, remote system management, network troubleshooting, security hardening, packet analysis, port and service scanning, virtualisation and network monitoring. It also requires students to conduct security testing ethically within their own isolated virtualised environment and prohibits unauthorised scanning of university networks, public websites or other systems.

Read Model Answer →
Cryptography 2,500 words

Cryptography – Secure Land Transaction Contract Exchange Protocol

This 2,500-word Cryptography coursework for Coventry University examines the design of a secure communication protocol for the remote exchange and signing of legal property transaction contracts. The assignment is based on a scenario involving Hackit & Run LLP (H&R), a firm of solicitors specialising in property transactions in the UK and overseas. Because property transactions are increasingly conducted through remote communications, H&R intends to establish a comprehensive system for secure document handling, exchange and digital signing that complies with legal requirements and remains enforceable under UK law. The scenario concerns a land transaction between Mrs. Harvey, the buyer, and Mr L.M. Facey, the seller. Students must devise a communication protocol involving three parties: H&R, the seller’s solicitor and Mrs. Harvey. H&R communicates with the seller through the seller’s solicitor rather than directly with the seller. The seller’s solicitor sends the contract to H&R, H&R forwards it to Mrs. Harvey, Mrs. Harvey digitally signs the contract and returns it to H&R, and H&R then sends the signed contract to the seller’s solicitor. The assignment requires students to consider two communication scenarios between H&R and the seller’s solicitor: a situation where the two parties have previously communicated securely and a situation where they are communicating securely for the first time. Students must identify suitable encryption algorithms for the different stages of the contract exchange protocol and justify their algorithm choices. The work should demonstrate an understanding of appropriate cryptographic approaches for maintaining confidentiality, integrity and availability during secure communication. Students must clearly illustrate their proposed protocol using suitable graphics and pseudocode. A full functioning implementation using a programming language may be provided as a higher-level approach. The report must identify the strengths and limitations of the proposed protocol and discuss the findings. This requires students to connect cryptographic theory with a practical security protocol designed for a real-world legal transaction. The coursework assesses knowledge of modern cryptography, including symmetric-key cryptography, key exchange, asymmetric cryptography, digital signatures, digital certificates and authentication. Students are also expected to model, test and assess the suitability of cryptographic protocols and algorithms for different practical requirements and critically evaluate current research and technological developments in cryptography and its applications. The final submission is a written report of 2,500 words, excluding appendices and tables, with properly formatted references. The assignment is categorised as a report and is a normal coursework attempt. The brief does not specify a particular referencing style or academic level, so these fields should not be guessed when entering the assignment into the Reference Library.

Read Model Answer →
Cryptography 2,500 words

Cryptography – Secure Contract Exchange Protocol

This 2,500-word Cryptography assignment for Coventry University examines the design of a secure communication protocol for the digital exchange and signing of property contracts. The scenario is based on Lauren Order & Cashgrab LLP (LO&C), a UK and overseas property law firm seeking to establish a comprehensive document handling, exchange and signing system that supports remote property transactions while remaining consistent with legal requirements and enforceable under UK law. The assignment requires students to consider the exchange of contracts using the extended CIA model and to devise a secure communication protocol involving three parties: LO&C, the buyer's solicitor Hackit & Run (H&R), and the seller. The scenario specifies that LO&C communicates with the buyer through H&R, that LO&C and the seller collaborate on initial contract drafts, and that LO&C prepares and sends the final contract to the seller for approval and digital signing before forwarding the signed contract to H&R for the buyer's signature. LO&C and H&R have an existing secure communication relationship. A central requirement is the identification and justification of suitable encryption algorithms for the different stages of the contract exchange protocol. Students may select algorithms covered in lectures or undertake additional research to identify alternative algorithms. The report must explain why particular algorithms are appropriate at different stages of the protocol and demonstrate how the selected cryptographic techniques address the practical security requirements of the scenario. The protocol must be clearly illustrated using suitable graphics and pseudocode, with functioning code being an optional higher-level approach. Students are required to identify the strengths and limitations of their proposed protocol and discuss their findings. The assignment therefore combines theoretical knowledge of modern cryptography with practical protocol design and evaluation. Generative AI may be used to create suitable code where permitted, but students must demonstrate their understanding of the code. The assessed learning outcomes cover modern cryptographic concepts and techniques, including symmetric-key cryptography, key exchange, asymmetric cryptography, digital signatures, digital certificates and authentication. Students are also expected to model, test and assess the suitability of cryptographic protocols and algorithms for practical requirements and critically evaluate current research and technological developments in cryptography and its applications.

Read Model Answer →
Secure Design and Development 2,000 words

Secure Design and Development – PixelForge Nexus (UITS)

This assessment for Coventry University’s Secure Design and Development module requires students to design and develop a functional secure online system with the aid of a Large Language Model (LLM). The assignment is based on a practical scenario involving Creative SkillZ LLC and its proposed “PixelForge Nexus” system. The submission combines a functional prototype, an individual 2,000-word report, source code hosted in the Coventry University GitHub environment, and a video report demonstrating the completed prototype. The PixelForge Nexus prototype is intended to provide secure project management and basic asset and resource management for a game-development environment. Core functionality includes adding and removing projects, viewing active projects, assigning developers to projects, allowing developers to view their assigned projects, uploading project documents, and allowing authorised users to access documents associated with their projects. The system must implement privilege separation between Admin, Project Lead and Developer roles. Security is a central requirement of the assignment. Administrators are responsible for managing projects and user accounts, Project Leads can assign developers and upload project documents, while Developers can view assigned projects and associated documents. The system must include a robust login mechanism with secure password hashing and storage, with Multi-Factor Authentication recommended as an additional security measure. Proposed pages include Sign In/Register, a role-based User Dashboard, Account Settings and a Project Details page. The practical assessment evaluates four major areas: System Design, Security Testing and Analysis, System Development, and Formal Methods. System design requires consideration of secure design principles and their application to the development lifecycle. Security testing requires critical evaluation of security techniques, identification of issues and proposed mitigation measures. System development requires a functional prototype that follows the proposed design and considers legal and ethical requirements. Formal methods require a behavioural model and appropriate verification techniques to establish whether the system meets its specification. The individual report must document the methods and techniques used to develop the prototype and discuss the stages of the development lifecycle, including specification, design and development. It must also explain the deployment and testing approach, limitations of the prototype, possible improvements, security techniques and the formal model used. The submission must include links to the Coventry University GitHub repository and Microsoft OneDrive video, while the required appendix contains the LLM prompt history and other resources used with APA-style referencing.

Read Model Answer →
Cyber Security / Penetration Testing 2,400 words

Grey-Box Penetration Testing: Vulnerability Assessment, Exploitation and Mitigation

This technical cyber-security project presents an authorised grey-box penetration test conducted within a controlled virtual laboratory environment. The objective is to assess the security posture of a deliberately vulnerable target system, identify weaknesses in exposed network services, demonstrate how those weaknesses could be exploited, evaluate their security and organisational impact, and recommend appropriate mitigation measures. The assessment follows a practical penetration-testing workflow supported by technical evidence, screenshots, activity records and academic research. The project begins with laboratory configuration, network discovery, service enumeration and vulnerability analysis. Tools including Kali Linux, Metasploitable, VMware, Nmap, Netcat and Metasploit are used across the testing lifecycle. Identified services are mapped to known vulnerabilities before controlled exploitation is undertaken and the resulting access is documented. The activity log records the progression from environment setup and network scanning through vulnerability identification, exploitation, evidence collection and final reporting. Five principal attack vectors are examined. These include the vsftpd 2.3.4 FTP backdoor, Samba username-map-script exploitation, an UnrealIRCd backdoor, insecure Java Remote Method Invocation and a misconfigured DistCC service. The practical demonstrations show how vulnerable or incorrectly configured services can permit unauthorised command execution and, in several cases, privileged shell access. For each vulnerability, the report explains the weakness, exploitation process, observed result, security impact and proposed mitigation. Recommended controls include patching or upgrading obsolete services, disabling unnecessary services, implementing firewall restrictions, strengthening authentication and input validation, restricting access to authorised systems, applying least privilege and monitoring suspicious activity. The project also incorporates group management and reflective practice. Team members perform specialised roles covering laboratory configuration, reconnaissance, vulnerability analysis, exploitation and documentation. Individual reflection considers technical performance, teamwork, evidence management and future skills development, demonstrating how structured collaboration contributes to an effective penetration-testing engagement. Important: unlike the earlier assignment briefs, these uploads appear to be completed student/project materials rather than the official 7COM1068 assessment brief. Therefore I would not invent the university, academic level or academic year. If you upload the actual 7COM1068 assignment guideline, I can fill those fields exactly.

Read Model Answer →
Cloud Computing / Big Data Technologies / Cyber Security 2,500 words

Cloud and Big Data Security Application: Design, Implementation and Evaluation

This assessment for the Cloud and Big Data Technologies module requires students to design, implement and evaluate an individual cloud-based or distributed data application. The project focuses on practical solutions involving the complex transformation, processing, storage and security of big data within cloud environments. Students are expected to demonstrate how distributed data can be organised in the cloud, how data pipelines can be used to access or process distributed databases, and how appropriate security controls can be incorporated into the resulting architecture. Students have considerable freedom when selecting their application. Suggested project directions include developing a data-science solution using SQL or MongoDB with cloud storage and an appropriate security policy; implementing privacy-preserving distributed processing using techniques such as Differential Privacy; creating multi-party authentication and group-based access-control mechanisms; or designing Multi-Level Security, Attribute-Based Encryption or Role-Based Access Control solutions. Projects may also examine distributed or cloud applications using security protocols such as SSH, SSL or IPsec. Creativity and originality are explicitly encouraged. The written component is a Design and Implementation Document of no more than approximately 2,500 words. It should present the project aims and objectives, application concept, cloud and security technologies, functional and security requirements, architecture and design decisions, protocols, access-control mechanisms, implementation process, achievements, problems encountered and overall evaluation. Relevant diagrams, such as interaction or sequence diagrams, may be used to explain system behaviour and architecture. The assessment also requires submission of the functioning Cloud and Big Data Security application and a 7-minute highlight demonstration video. The video should demonstrate the application's major features, implementation details, security functionality and, where appropriate, attack scenarios. Assessment places strong emphasis on the quality of the design and implementation documentation, originality, use of advanced features, and the overall effort and technical quality of the completed application. Students are therefore expected to demonstrate independent development rather than simply reproduce an existing tutorial.

Read Model Answer →