Academic Model Answers
Library for UK Postgraduates

Browse tutor-verified model answers across MBA, Law, Finance, Research Methods and more. Use as study references for your own work.

201 model answers 30+ subjects covered 50+ UK universities
Find your assignment

Search the Library

Filter by keyword, subject, or both. Updates live as new model answers are added to our portal.

Filtering by “Enumeration” Clear filters

Available Model Answers (4)

Real-time Database Sync
Cyber Security / Digital Forensics 3,877 words

Digital Forensics Investigation: USB, Memory and Windows Registry Analysis

This Digital Forensics Investigation Report presents a multi-source forensic examination involving removable media, volatile memory and a Windows disk image. The work is undertaken within an MSc Cyber Security context and demonstrates the application of forensic procedures, specialist analysis tools and evidential reasoning to investigate suspected criminal and malicious activity. The report places particular emphasis on maintaining evidence integrity, reconstructing activity across different forensic sources and correlating artefacts to produce defensible investigative findings. DF_Report_Sathiyaprakash The first part investigates a FAT32 USB forensic image associated with suspected video piracy and other potentially criminal activity. The examination uses tools including FTK Imager, Autopsy, Sleuth Kit, ewfmount, cryptographic hashing utilities and VeraCrypt. The methodology includes pre- and post-examination hash verification, read-only mounting, filesystem enumeration, deleted-file analysis and low-level sector examination. The investigation identifies deleted artefacts, portable anti-forensic utilities, browser evidence and an encrypted VeraCrypt container concealed within unallocated disk space. DF_Report_Sathiyaprakash The USB investigation also demonstrates the importance of evidence integrity and chain of custody. MD5 and SHA-256 hashes are used to establish and later confirm the integrity of forensic copies, while analysis is conducted without modifying the original evidence. The report examines filesystem structures, deleted files, anti-forensic tooling and encrypted data and records evidence handling through a formal chain-of-custody process. DF_Report_Sathiyaprakash DF_Report_Sathiyaprakash The second part focuses on volatile-memory forensics using a Windows memory image. Volatility 3 is used to identify the operating-system profile, reconstruct process hierarchies, inspect process ownership and security identifiers, and extract suspicious process memory. Particular attention is given to AtomicService.exe, which is observed running with SYSTEM privileges and associated with the Atomic Red Team framework and MITRE ATT&CK technique T1543.003 – Windows Service. The investigation also considers PowerShell activity, process execution timelines and indicators of suspicious behaviour. DF_Report_Sathiyaprakash DF_Report_Sathiyaprakash The third part conducts Windows Registry forensic analysis on the WinRegEvidenceP3.vhd image. Registry artefacts are examined using RegRipper, with analysis covering SYSTEM, SOFTWARE, SAM and NTUSER.DAT hives. The investigation evaluates system configuration, user accounts, application execution and persistence evidence using artefacts such as Run keys, BAM, Prefetch and scheduled tasks. These findings are then correlated with evidence recovered from volatile memory to reconstruct the sequence of suspicious activity. DF_Report_Sathiyaprakash Across the report, evidence from disk, memory and the Windows Registry is combined to reconstruct malicious activity and identify persistence mechanisms, elevated processes, suspicious user accounts and adversary-simulation tools. The analysis maps relevant behaviour to the MITRE ATT&CK framework and considers both technical findings and their evidential significance. The report therefore demonstrates practical competence in forensic acquisition principles, artefact analysis, timeline reconstruction, malware and process investigation, evidence correlation and professional reporting. Important for the Reference Library: this upload contains an actual student name on the cover page and detailed case evidence. Since your Reference Library says there is no student record behind uploaded past work, I would use the generic title and overview above rather than copying the student-identifying cover-page information into the public metadata. DF_Report_Sathiyaprakash

Read Model Answer →
Cyber Security / Penetration Testing

Web Application Penetration Testing and Security Vulnerability Assessment Portfolio

This postgraduate cyber security portfolio requires students to conduct a structured penetration test of a controlled web application and document the technical findings in a professional security-testing format. The assessment develops practical competence in identifying, validating and communicating security vulnerabilities while maintaining appropriate legal, ethical and professional boundaries. Assessment Brief CMP-L021 (PG) … Students begin by performing network and service enumeration, identifying open ports and the services running on the target host. They are expected to interpret the security implications of the findings and provide appropriate recommendations to a hypothetical client. The assessment then progresses into web-application vulnerability testing using tools such as a web browser, Burp Suite Community, Nmap and student-developed scripts. Assessment Brief CMP-L021 (PG) … A major part of the portfolio examines common web-security weaknesses including SQL Injection and Cross-Site Scripting. Students must demonstrate how they tested the application, capture relevant requests and responses, and explain the evidence supporting their conclusions. Additional tasks involve application and server reconnaissance, including identification of technologies, server versions, publicly exposed files and other information that may create security risks. Assessment Brief CMP-L021 (PG) … The higher-level reporting component requires students to document significant vulnerabilities using the conventions of a professional penetration-test report. This includes assigning CVSS scores, relating identified weaknesses to the OWASP Top 10 and NIST classifications, and supporting findings with appropriate technical evidence. Assessment Brief CMP-L021 (PG) … Students must also produce an executive summary for a non-technical audience, considering security, privacy, regulatory exposure and budget implications. A vulnerability table linking technical weaknesses with relevant regulatory concerns is also required. Overall, the assessment integrates technical penetration testing with risk communication, vulnerability classification, evidence collection and professional security reporting. Assessment Brief CMP-L021 (PG) … Overview word count: approximately 320 words. AI-use note: AI can be used in this assessment, but any use must be acknowledged and AI-generated outputs must be appropriately cited. Assessment Brief CMP-L021 (PG) …

Read Model Answer →
1,500 words

Network Security Evaluation and Monitoring – Reconnaissance, Incident Response and APTs

This coursework assesses the research and analytical abilities required to design and evaluate an effective network security evaluation and monitoring solution. The scenario places the student in the role of a network security evaluation specialist responsible for helping a client design and build a monitoring solution for a complex client network. The client operates in the defence and security sector, works with government departments, multinational organisations and foreign agencies, and handles sensitive information. The network includes several server farms, gateway nodes, hundreds of client nodes, internal application services, externally accessible services and wireless access points. The organisation is considered vulnerable to threats such as sabotage and intellectual property theft. The coursework requires all questions to be answered in the given order within a single report. An abstract is not required, and students are expected to use technical terminology precisely. Relevant and clearly labelled illustrations are encouraged. Where assumptions are required about security software, hardware or services already deployed on the network, these assumptions must be clearly identified in a dedicated “Assumptions” section at the beginning of the report. Question 1 focuses on detecting network reconnaissance originating from inside the organisation. Students must explain how an insider could collect and use reconnaissance information for malicious purposes, identify the types of data that should be collected and the appropriate network locations for collection, and justify the selection of monitoring data. The question also requires recommendations for suitable tools and configurations to detect reconnaissance activity, together with strategies for dealing with the scale and high traffic volume of the client network. This section carries 30 marks and has a suggested length of 500 words. Question 2 focuses on incident response following a confirmed security incident. The scenario involves suspicious out-of-hours activity and an external flash drive connected to a workstation at gateway 10, a large number of files being opened on a file server at gateway 9, and significant traffic between the workstation and a database server at gateway 5. Students must determine which previously collected data would be relevant, explain the evidence expected from that data, and recommend additional network and endpoint data that should be collected. The proposed approach must be forensically sound so that evidence can potentially be used in court. This section carries 50 marks and has a suggested length of 700 words. Question 3 addresses Advanced Persistent Threats (APTs) and evaluates the effectiveness of the proposed monitoring solution. Students must recommend appropriate testing to determine whether the monitoring system operates according to its specifications and objectives, explain the types, timing and location of testing, and identify suitable qualifications, certifications, knowledge and tool experience for security testers. The section also requires discussion of APT behaviour and how the proposed monitoring mechanisms could detect or prevent such activity. This section carries 20 marks and has a suggested length of 300 words. Overall, the coursework develops skills in network security monitoring, reconnaissance detection, incident response, digital forensics, security testing and APT detection. It requires students to connect technical monitoring strategies with practical security, legal and operational considerations within a complex organisational network environment.

Read Model Answer →
Cyber Security / Penetration Testing 2,400 words

Grey-Box Penetration Testing: Vulnerability Assessment, Exploitation and Mitigation

This technical cyber-security project presents an authorised grey-box penetration test conducted within a controlled virtual laboratory environment. The objective is to assess the security posture of a deliberately vulnerable target system, identify weaknesses in exposed network services, demonstrate how those weaknesses could be exploited, evaluate their security and organisational impact, and recommend appropriate mitigation measures. The assessment follows a practical penetration-testing workflow supported by technical evidence, screenshots, activity records and academic research. The project begins with laboratory configuration, network discovery, service enumeration and vulnerability analysis. Tools including Kali Linux, Metasploitable, VMware, Nmap, Netcat and Metasploit are used across the testing lifecycle. Identified services are mapped to known vulnerabilities before controlled exploitation is undertaken and the resulting access is documented. The activity log records the progression from environment setup and network scanning through vulnerability identification, exploitation, evidence collection and final reporting. Five principal attack vectors are examined. These include the vsftpd 2.3.4 FTP backdoor, Samba username-map-script exploitation, an UnrealIRCd backdoor, insecure Java Remote Method Invocation and a misconfigured DistCC service. The practical demonstrations show how vulnerable or incorrectly configured services can permit unauthorised command execution and, in several cases, privileged shell access. For each vulnerability, the report explains the weakness, exploitation process, observed result, security impact and proposed mitigation. Recommended controls include patching or upgrading obsolete services, disabling unnecessary services, implementing firewall restrictions, strengthening authentication and input validation, restricting access to authorised systems, applying least privilege and monitoring suspicious activity. The project also incorporates group management and reflective practice. Team members perform specialised roles covering laboratory configuration, reconnaissance, vulnerability analysis, exploitation and documentation. Individual reflection considers technical performance, teamwork, evidence management and future skills development, demonstrating how structured collaboration contributes to an effective penetration-testing engagement. Important: unlike the earlier assignment briefs, these uploads appear to be completed student/project materials rather than the official 7COM1068 assessment brief. Therefore I would not invent the university, academic level or academic year. If you upload the actual 7COM1068 assignment guideline, I can fill those fields exactly.

Read Model Answer →