Filter by keyword, subject, or both. Updates live as new model answers are added to our portal.
Cyber Security / Penetration Testing
2,400 words
Grey-Box Penetration Testing: Vulnerability Assessment, Exploitation and Mitigation
This technical cyber-security project presents an authorised grey-box penetration test conducted within a controlled virtual laboratory environment. The objective is to assess the security posture of a deliberately vulnerable target system, identify weaknesses in exposed network services, demonstrate how those weaknesses could be exploited, evaluate their security and organisational impact, and recommend appropriate mitigation measures. The assessment follows a practical penetration-testing workflow supported by technical evidence, screenshots, activity records and academic research. The project begins with laboratory configuration, network discovery, service enumeration and vulnerability analysis. Tools including Kali Linux, Metasploitable, VMware, Nmap, Netcat and Metasploit are used across the testing lifecycle. Identified services are mapped to known vulnerabilities before controlled exploitation is undertaken and the resulting access is documented. The activity log records the progression from environment setup and network scanning through vulnerability identification, exploitation, evidence collection and final reporting. Five principal attack vectors are examined. These include the vsftpd 2.3.4 FTP backdoor, Samba username-map-script exploitation, an UnrealIRCd backdoor, insecure Java Remote Method Invocation and a misconfigured DistCC service. The practical demonstrations show how vulnerable or incorrectly configured services can permit unauthorised command execution and, in several cases, privileged shell access. For each vulnerability, the report explains the weakness, exploitation process, observed result, security impact and proposed mitigation. Recommended controls include patching or upgrading obsolete services, disabling unnecessary services, implementing firewall restrictions, strengthening authentication and input validation, restricting access to authorised systems, applying least privilege and monitoring suspicious activity. The project also incorporates group management and reflective practice. Team members perform specialised roles covering laboratory configuration, reconnaissance, vulnerability analysis, exploitation and documentation. Individual reflection considers technical performance, teamwork, evidence management and future skills development, demonstrating how structured collaboration contributes to an effective penetration-testing engagement. Important: unlike the earlier assignment briefs, these uploads appear to be completed student/project materials rather than the official 7COM1068 assessment brief. Therefore I would not invent the university, academic level or academic year. If you upload the actual 7COM1068 assignment guideline, I can fill those fields exactly.
Read Model Answer →
Cloud Computing / Big Data Technologies / Cyber Security
2,500 words
Cloud and Big Data Security Application: Design, Implementation and Evaluation
This assessment for the Cloud and Big Data Technologies module requires students to design, implement and evaluate an individual cloud-based or distributed data application. The project focuses on practical solutions involving the complex transformation, processing, storage and security of big data within cloud environments. Students are expected to demonstrate how distributed data can be organised in the cloud, how data pipelines can be used to access or process distributed databases, and how appropriate security controls can be incorporated into the resulting architecture. Students have considerable freedom when selecting their application. Suggested project directions include developing a data-science solution using SQL or MongoDB with cloud storage and an appropriate security policy; implementing privacy-preserving distributed processing using techniques such as Differential Privacy; creating multi-party authentication and group-based access-control mechanisms; or designing Multi-Level Security, Attribute-Based Encryption or Role-Based Access Control solutions. Projects may also examine distributed or cloud applications using security protocols such as SSH, SSL or IPsec. Creativity and originality are explicitly encouraged. The written component is a Design and Implementation Document of no more than approximately 2,500 words. It should present the project aims and objectives, application concept, cloud and security technologies, functional and security requirements, architecture and design decisions, protocols, access-control mechanisms, implementation process, achievements, problems encountered and overall evaluation. Relevant diagrams, such as interaction or sequence diagrams, may be used to explain system behaviour and architecture. The assessment also requires submission of the functioning Cloud and Big Data Security application and a 7-minute highlight demonstration video. The video should demonstrate the application's major features, implementation details, security functionality and, where appropriate, attack scenarios. Assessment places strong emphasis on the quality of the design and implementation documentation, originality, use of advanced features, and the overall effort and technical quality of the completed application. Students are therefore expected to demonstrate independent development rather than simply reproduce an existing tutorial.
Read Model Answer →
Cyber Security / Digital Forensics
3,500 words
Digital Forensics Portfolio: Disk Image, Memory and Windows Registry Investigation
This Level 7 Digital Forensics portfolio requires students to conduct a structured forensic investigation across disk, memory and Windows Registry evidence. The assessment develops practical investigative skills alongside professional forensic reporting and requires students to preserve evidence integrity, document methodology, interpret technical artefacts and communicate findings clearly. The portfolio is equivalent to 3,500 words and forms 60% of the module assessment. The first part involves analysing a seized USB forensic image in the context of a suspected insider involved in video piracy and potentially more serious criminal activity. Students must follow ACPO digital forensic best practice, verify image integrity before and after examination, maintain a clear chain of custody, identify significant device properties and artefacts, and justify conclusions using evidence. Tools such as FTK Imager and Autopsy may be used, alongside other appropriate forensic utilities. The scenario also requires examination of an encrypted VeraCrypt container discovered within the evidence. The second part focuses on memory forensics using a Windows memory dump. Students are expected to reconstruct process execution timelines, examine suspicious processes including PowerShell, Notepad and AtomicService, identify process owners and SIDs, extract relevant memory artefacts and produce an executive summary suitable for a non-technical audience. The third part requires an extensive Windows Registry and system artefact investigation. Students examine operating-system information, users, network configuration, login activity, suspicious files, executable and DLL creation, BAM records, Prefetch artefacts, scheduled tasks, persistence mechanisms and evidence of potentially malicious activity. Findings must be supported with screenshots, extracted artefacts or other appropriate evidence. The assignment must use the university's official portfolio template and be submitted as a PDF. The template organises the work into forensic image analysis, memory investigation and Windows Registry investigation sections. For a public Reference Library entry, this title is better than simply “Digital Forensics Coursework” because it clearly communicates the three major technical components of the work.
Read Model Answer →
Cyber Security for Business and Cloud Management
This activity aims to assess your comprehension of the diverse concepts discussed in this module. You must use the frameworks and concepts covered in this module's delivery to respond to all the tasks below. Scenario ShieldSafe Analytics Ltd. is a fast-growing health analytics company specialising in AI-driven patient diagnostics and telehealth platforms. Operating across multiple countries, the company processes high volumes of real-time patient data, including biometric and genomic records. Due to the increased reliance on remote healthcare and IoT-enabled medical devices, their infrastructure has expanded into hybrid cloud environments. Recently, ShieldSafe experienced a suspected data exfiltration incident involving anomalous traffic from one of its diagnostic platforms integrated with third-party cloud APIs. As a result, executive leadership has raised concerns about the company’s vulnerability to adversarial information operations, particularly in relation to data manipulation, misinformation, and insider threats. As a Junior Cybersecurity Strategist, you’ve been recruited to support the lead cyber intelligence consultant in reviewing vulnerabilities within their information environment, exploring offensive and defensive Information Operations (IO) concepts, and crafting robust cyber defence mechanisms. The leadership also wants to migrate a legacy electronic health record (EHR) system used across its African operations to a more scalable and secure cloud infrastructure. However, concerns exist regarding cross-border data protection laws, insider threats, and the strategic use of information in potential cyber warfare scenarios.
Read Model Answer →
L7 Cyber Security for Business and Cloud Management
This activity aims to assess your comprehension of the diverse concepts discussed in this module. You must use the frameworks and concepts covered in this module's delivery to respond to all the tasks below. Scenario ShieldSafe Analytics Ltd. is a fast-growing health analytics company specialising in AI-driven patient diagnostics and telehealth platforms. Operating across multiple countries, the company processes high volumes of real-time patient data, including biometric and genomic records. Due to the increased reliance on remote healthcare and IoT-enabled medical devices, their infrastructure has expanded into hybrid cloud environments. Recently, ShieldSafe experienced a suspected data exfiltration incident involving anomalous traffic from one of its diagnostic platforms integrated with third-party cloud APIs. As a result, executive leadership has raised concerns about the company’s vulnerability to adversarial information operations, particularly in relation to data manipulation, misinformation, and insider threats. As a Junior Cybersecurity Strategist, you’ve been recruited to support the lead cyber intelligence consultant in reviewing vulnerabilities within their information environment, exploring offensive and defensive Information Operations (IO) concepts, and crafting robust cyber defence mechanisms. The leadership also wants to migrate a legacy electronic health record (EHR) system used across its African operations to a more scalable and secure cloud infrastructure. However, concerns exist regarding cross-border data protection laws, insider threats, and the strategic use of information in potential cyber warfare scenarios.
Read Model Answer →