Filter by keyword, subject, or both. Updates live as new model answers are added to our portal.
Digital Forensics / Cyber Security
3,000 words
Digital Forensics Investigation of a USB Device: Evidence Acquisition, Analysis and Reporting
This Digital Forensics assessment requires students to undertake a simulated professional investigation of a USB storage device while acting as a digital forensic trainee for a fictional forensic-services organisation. The nature of the suspected wrongdoing is initially unknown, requiring the investigator to apply appropriate forensic methodologies, tools and analytical techniques to identify suspicious activity, recover relevant artefacts and determine whether evidence of malicious or unauthorised behaviour exists. 7070SCN_Assessment Brief_2526MA… The investigation begins with authorisation, evidence handling and chain of custody. Students must demonstrate secure receipt and management of the USB device, operate within the authorised scope of the investigation and maintain records covering each stage of the evidence lifecycle. Forensic acquisition requires use and validation of a software write blocker, creation of bit-for-bit forensic images and cryptographic hashing to demonstrate that working and evidential copies maintain integrity. 7070SCN_Assessment Brief_2526MA… The analytical stage involves examination of the working forensic image using appropriate digital-forensic tools. Students investigate file-signature mismatches, password-protected files, registry artefacts, USB history, user activity, metadata and timeline relationships. Where suspicious executable files are discovered, static and/or dynamic malware analysis may be undertaken. The investigation can therefore span documents, images, applications, executables and registry hives. 7070SCN_Assessment Brief_2526MA… Students must maintain objective and chronological forensic case notes documenting evidence acquisition, preservation, analysis and interpretation. These records should support reproducibility and potential evidential admissibility. The final forensic report summarises findings, explains and justifies the tools and methodologies used, records integrity-verification results, discusses relevant legal, ethical and professional principles and provides appropriate recommendations for further action. 7070SCN_Assessment Brief_2526MA… The assessment also encourages advanced forensic analysis where relevant, including OSINT, password recovery or decryption, data carving, regular-expression searching, advanced registry analysis and static or dynamic malware investigation. Professional practice is assessed through adherence to recognised forensic methodologies, industry best practice, legal and ethical obligations, chain-of-custody records and evidence-handling procedures. 7070SCN_Assessment Brief_2526MA… Overall, the coursework integrates forensic acquisition, evidence preservation, artefact analysis, advanced investigation techniques, professional documentation and legally defensible reporting within a realistic digital-forensics case-study environment. Important for your public Reference Library: this brief explicitly states that it is for Coventry University Group students' own use and must not be passed to third parties or posted on any website. 7070SCN_Assessment Brief_2526MA… So use the metadata and an original high-level overview like the one above, but do not upload or publicly reproduce the assessment brief itself.
Read Model Answer →
Digital Data Acquisition, Recovery and Analysis
1,500 words
Digital Data Acquisition, Recovery and Analysis – Autonomous Vehicle Forensics
This individual coursework for the Digital Data Acquisition, Recovery and Analysis module requires students to produce a 1,500-word technical research paper critically investigating autonomous vehicle (AV) forensics. The assignment focuses on the challenges, methodologies and tools involved in extracting, preserving, analysing and interpreting digital evidence from autonomous vehicles and their associated systems. The work specifically considers how forensic evidence can be used to reconstruct events and establish accountability following accidents, security breaches or system malfunctions. The assignment examines the increasing importance of digital evidence generated by intelligent transportation systems and smart vehicles. Students are expected to consider data produced by different sources within an autonomous vehicle ecosystem, including LiDAR, radar and GPS sensors, vehicle control units and connected infrastructure. The report should explore how these different forms of information can be collected and forensically preserved while maintaining their evidential value for subsequent investigation and analysis. The coursework requires a detailed technical analysis rather than a general overview of autonomous vehicles or digital forensics. Students are expected to engage with academic literature, industry frameworks and technical examples, while providing critical insights into the subject. The report should analyse the practical challenges associated with AV forensics and critically examine the tools and methodologies that can be applied to obtain and interpret evidence from autonomous vehicle environments. Legal, ethical and privacy considerations form an important part of the assignment. The report should examine issues surrounding the use of autonomous vehicle evidence, including legal responsibility, regulatory considerations, privacy implications and ethical challenges associated with collecting and analysing potentially sensitive vehicle and user data. These considerations should be connected to the wider forensic investigation process and the reliability and admissibility of digital evidence. The required report should follow an academic research-paper structure, including a cover page, abstract, keywords, table of contents, clearly organised sections and subsections, references and an appendix where required. The brief requires APA referencing and a reference list at the end of the paper. Students are expected to use their own words and critically analyse the literature rather than simply summarising existing research. The assessment evaluates five equally weighted areas: structure and presentation with supporting references; balance, objectivity, critical evaluation and original insight; identification of AV-forensics challenges and quality of analysis; analysis of tools and methodologies used in AV forensics; and understanding of AV forensics together with its legal, professional and ethical considerations. Each area contributes 20% to the assessment.
Read Model Answer →
Digital Forensics / Cybersecurity
2,000 words
AI-Augmented Digital Forensics Workflow Audit: Feasibility and Risk Assessment of ForensiScan AI
This digital forensics assessment examines the feasibility, reliability and legal risks associated with introducing AI-assisted analysis into a conventional forensic investigation workflow. Students act as a Lead Forensic Consultant assessing a proposed black-box system called ForensiScan AI, which claims to automatically classify illicit images and identify suspicious intent within encrypted messaging applications using Large Language Models. The central objective is to determine whether the efficiency benefits of AI can be achieved without compromising evidential integrity, transparency or legal defensibility. The report maps the proposed AI system across the four stages of the NIST forensic process: Collection, Examination, Analysis and Reporting. For each phase, students identify the data entering and leaving the AI system and determine whether the technology should be used for preliminary triage or as part of final forensic analysis. A major component concerns verification and validation. Because AI systems may hallucinate or misclassify evidence, students must design a ground-truth protocol involving human verification, statistical sampling and known datasets. The assessment also investigates whether AI-generated results can be reproduced reliably when identical evidence is processed again. The report further addresses chain of custody and data integrity, particularly whether AI processing could alter timestamps, metadata or other forensic artefacts. Ethical and legal analysis covers potential model bias, language and contextual limitations, and whether AI-generated outputs could satisfy the requirements of the Daubert Test for expert evidence. Overall, the assessment combines digital-forensic architecture, AI governance, evidential integrity, model validation, legal admissibility and professional accountability. The grading criteria place particular emphasis on forensic soundness, protection against evidence alteration, critical analysis of AI limitations such as hallucination and non-determinism, and professional technical communication. Overview word count: approximately 340 words. AI-use note: the brief permits AI only for limited assistance such as brainstorming risks, structural feedback and grammar refinement. It explicitly prohibits full report generation, unverified forensic claims and using AI to substitute for the student's own final recommendation or verification protocol. Any AI use requires an appendix containing the tool, exact prompts and a human verification log.
Read Model Answer →
Cyber Security / Digital Forensics
3,500 words
Digital Forensics Portfolio: Disk Image, Memory and Windows Registry Investigation
This Level 7 Digital Forensics portfolio requires students to conduct a structured forensic investigation across disk, memory and Windows Registry evidence. The assessment develops practical investigative skills alongside professional forensic reporting and requires students to preserve evidence integrity, document methodology, interpret technical artefacts and communicate findings clearly. The portfolio is equivalent to 3,500 words and forms 60% of the module assessment. The first part involves analysing a seized USB forensic image in the context of a suspected insider involved in video piracy and potentially more serious criminal activity. Students must follow ACPO digital forensic best practice, verify image integrity before and after examination, maintain a clear chain of custody, identify significant device properties and artefacts, and justify conclusions using evidence. Tools such as FTK Imager and Autopsy may be used, alongside other appropriate forensic utilities. The scenario also requires examination of an encrypted VeraCrypt container discovered within the evidence. The second part focuses on memory forensics using a Windows memory dump. Students are expected to reconstruct process execution timelines, examine suspicious processes including PowerShell, Notepad and AtomicService, identify process owners and SIDs, extract relevant memory artefacts and produce an executive summary suitable for a non-technical audience. The third part requires an extensive Windows Registry and system artefact investigation. Students examine operating-system information, users, network configuration, login activity, suspicious files, executable and DLL creation, BAM records, Prefetch artefacts, scheduled tasks, persistence mechanisms and evidence of potentially malicious activity. Findings must be supported with screenshots, extracted artefacts or other appropriate evidence. The assignment must use the university's official portfolio template and be submitted as a PDF. The template organises the work into forensic image analysis, memory investigation and Windows Registry investigation sections. For a public Reference Library entry, this title is better than simply “Digital Forensics Coursework” because it clearly communicates the three major technical components of the work.
Read Model Answer →