Academic Model Answers
Library for UK Postgraduates

Browse tutor-verified model answers across MBA, Law, Finance, Research Methods and more. Use as study references for your own work.

230 model answers 30+ subjects covered 50+ UK universities
Find your assignment

Search the Library

Filter by keyword, subject, or both. Updates live as new model answers are added to our portal.

Filtering by “ISMS” Clear filters

Available Model Answers (13)

Real-time Database Sync
Cloud and Big Data Technologies 2,500 words

Cloud and Big Data Technologies – Summative Assessment: Cloud and Big Data Security Application

This summative assessment for the CST4067 Cloud and Big Data Technologies module requires students to design, implement and evaluate an individual cloud and big data security application. The assessment focuses on applying techniques for the complex transformation and processing of data within distributed and cloud-based environments, while considering security, privacy and access-control requirements. Students are expected to develop a practical application and document its design, implementation and evaluation through a technical report and a short demonstration video. Students are given flexibility to select their own project idea, provided that the proposed application is appropriately scoped for the available development period and demonstrates relevant cloud, big data and security technologies. Suggested project areas include data science applications using SQL, MongoDB and cloud storage, privacy-preserving data processing such as Differential Privacy, multi-party authentication, group-based security and access control, Multi-Level Security, Attribute-Based Encryption, and distributed or cloud-based applications incorporating security protocols such as SSH, SSL or IPSEC and access-control mechanisms such as RBAC. The Design and Implementation Document should be no longer than 2,500 words and should explain the major design and implementation aspects of the project. Expected content includes an introduction covering the aims, objectives, project concept, security concepts and cloud technologies used; a requirements specification addressing programme behaviour and security requirements; analysis and design covering protocols, access control and interaction, sequence diagrams or process specifications; implementation details explaining what was achieved and how it was developed; and an evaluation and conclusion discussing successful and unsuccessful aspects, problems encountered and lessons learned. Relevant references, including tutorials, books and academic articles, should also be provided using Harvard or IEEE referencing. The assessment also requires students to submit the implemented Cloud and Big Data Security application together with a highlight demonstration video. The video must be no longer than seven minutes and should demonstrate the main features of the application, including relevant interactions, implementation highlights, security features and, where appropriate, attack scenarios. Assessment is based on the Design and Implementation Document, originality, advanced features, and the effort and quality demonstrated in the application. The assessment specification places particular importance on original development, clear documentation of any tutorials or existing resources used, and evidence that the student understands the technologies implemented. Suggested technologies and project ideas include Google Cloud, Hadoop, Spark, cloud storage, data pipelines, security protocols, access control and privacy-preserving techniques.

Read Model Answer →
information Governance and Cyber Security 2,500 words

Information Governance Policy for Healthcare Assistant (HCA)

This assessment is the group component of the Information Governance and Cyber Security module and requires a 2,500-word report for the fictional Healthcare Assistant (HCA) organisation. HCA is presented as a large private hospital group operating across the UK, with specialist healthcare services, intensive care facilities and a wide network of GPs, departments, partner hospitals, medical centres and third parties. The organisation processes highly sensitive information including patient personal information, admission details, health records, staff information and other organisational data. These data are shared across different sites and partners and are also used for analytical purposes, treatment planning and marketing activities. The assessment requires students to develop an Information Governance Policy for HCA and provide an accompanying report that justifies the policy contents, selected framework, risk assessment methodology and implementation strategy. The objective is to establish a robust information governance structure capable of protecting HCA's information assets while supporting legal, regulatory and contractual compliance. The first component of the report focuses on the introduction, purpose and scope of the Information Security Policy. Students should establish the organisational context, explain why information governance is important to HCA and define the people, processes, technologies and information assets covered by the policy. Particular attention should be given to the confidentiality, integrity and availability of sensitive healthcare and organisational information. The second component focuses on the identification and allocation of roles and responsibilities. The report should establish appropriate accountability for information governance and information security and consider responsibilities relating to legal, regulatory and contractual obligations. Relevant roles may include senior management, information security leadership, data protection personnel, information asset owners, information asset administrators, employees, contractors and third parties. The third component requires the development of an Information Governance Policy Framework and recommendations for a minimum of eight controls to establish an effective Information Security Management System. The assessment brief identifies ISO/IEC 27001:2022 as an appropriate framework within the developed policy and requires the framework and controls to be justified in relation to HCA's organisational context and security requirements. The fourth component focuses on implementation and monitoring. Students should develop an implementation plan explaining how the information governance policy and security controls can be introduced and maintained. Appropriate monitoring mechanisms should be considered to identify security threats, mitigate vulnerabilities, maintain accountability and support continuous improvement. Overall, the assessment requires a practical and critically justified approach to information governance within a healthcare environment. The report should demonstrate how an effective information governance policy can protect sensitive patient information, support regulatory compliance, establish accountability and strengthen HCA's ability to manage evolving cyber security threats.

Read Model Answer →
Cyber Security / Digital Forensics 3,877 words

Digital Forensics Investigation: USB, Memory and Windows Registry Analysis

This Digital Forensics Investigation Report presents a multi-source forensic examination involving removable media, volatile memory and a Windows disk image. The work is undertaken within an MSc Cyber Security context and demonstrates the application of forensic procedures, specialist analysis tools and evidential reasoning to investigate suspected criminal and malicious activity. The report places particular emphasis on maintaining evidence integrity, reconstructing activity across different forensic sources and correlating artefacts to produce defensible investigative findings. DF_Report_Sathiyaprakash The first part investigates a FAT32 USB forensic image associated with suspected video piracy and other potentially criminal activity. The examination uses tools including FTK Imager, Autopsy, Sleuth Kit, ewfmount, cryptographic hashing utilities and VeraCrypt. The methodology includes pre- and post-examination hash verification, read-only mounting, filesystem enumeration, deleted-file analysis and low-level sector examination. The investigation identifies deleted artefacts, portable anti-forensic utilities, browser evidence and an encrypted VeraCrypt container concealed within unallocated disk space. DF_Report_Sathiyaprakash The USB investigation also demonstrates the importance of evidence integrity and chain of custody. MD5 and SHA-256 hashes are used to establish and later confirm the integrity of forensic copies, while analysis is conducted without modifying the original evidence. The report examines filesystem structures, deleted files, anti-forensic tooling and encrypted data and records evidence handling through a formal chain-of-custody process. DF_Report_Sathiyaprakash DF_Report_Sathiyaprakash The second part focuses on volatile-memory forensics using a Windows memory image. Volatility 3 is used to identify the operating-system profile, reconstruct process hierarchies, inspect process ownership and security identifiers, and extract suspicious process memory. Particular attention is given to AtomicService.exe, which is observed running with SYSTEM privileges and associated with the Atomic Red Team framework and MITRE ATT&CK technique T1543.003 – Windows Service. The investigation also considers PowerShell activity, process execution timelines and indicators of suspicious behaviour. DF_Report_Sathiyaprakash DF_Report_Sathiyaprakash The third part conducts Windows Registry forensic analysis on the WinRegEvidenceP3.vhd image. Registry artefacts are examined using RegRipper, with analysis covering SYSTEM, SOFTWARE, SAM and NTUSER.DAT hives. The investigation evaluates system configuration, user accounts, application execution and persistence evidence using artefacts such as Run keys, BAM, Prefetch and scheduled tasks. These findings are then correlated with evidence recovered from volatile memory to reconstruct the sequence of suspicious activity. DF_Report_Sathiyaprakash Across the report, evidence from disk, memory and the Windows Registry is combined to reconstruct malicious activity and identify persistence mechanisms, elevated processes, suspicious user accounts and adversary-simulation tools. The analysis maps relevant behaviour to the MITRE ATT&CK framework and considers both technical findings and their evidential significance. The report therefore demonstrates practical competence in forensic acquisition principles, artefact analysis, timeline reconstruction, malware and process investigation, evidence correlation and professional reporting. Important for the Reference Library: this upload contains an actual student name on the cover page and detailed case evidence. Since your Reference Library says there is no student record behind uploaded past work, I would use the generic title and overview above rather than copying the student-identifying cover-page information into the public metadata. DF_Report_Sathiyaprakash

Read Model Answer →
Computer Science / Research Methods / Specialist Research 2,800 words

Research Specialism Report: Critical Review of Open Research Questions in Computer Science

This Advanced Research Topics in Computer Science assessment requires students to critically examine a research paper associated with their chosen MSc specialism and demonstrate an understanding of how established research techniques are used to create and extend knowledge in computer science. Eligible specialisms include Artificial Intelligence, Networking, Cyber Security, Software Engineering and Data Science. The assessment is intended to prepare students for deeper independent research as part of their Master's project. 7COM1084+Research+specialism+re… Students begin by providing a clear introduction to their selected research specialism and explaining the broader research area in a way that is accessible to readers with general computer-science knowledge. The report then identifies the open research question presented in the relevant 7COM1084 specialist lecture paper, explains the problem in detail and evaluates why it is scientifically significant or relevant to a real-world application. 7COM1084+Research+specialism+re… A substantial literature-review section requires students to examine existing and related research beyond the specialist lecture paper. The aim is to identify what previous work has achieved, explain why existing approaches do not fully solve the research problem and identify further unresolved questions. 7COM1084+Research+specialism+re… The research-methods section focuses on the approaches used in the selected specialist paper. Students are expected to describe and critically evaluate those methods, considering both their strengths and limitations. They must then propose an alternative or extended research approach that could build on the published work and investigate related open problems, drawing on principles of experimental design and theoretical or practical research. 7COM1084+Research+specialism+re… The final reflective component asks students to explain their personal investment in the research area, including why the selected question interests them and how their own strengths and prior experience would support future research in that domain. 7COM1084+Research+specialism+re… The report must not exceed 2,800 words ±10%, must use the Harvard referencing system, and must include at least 20 references, one of which must be the relevant 7COM1084 specialist paper. 7COM1084+Research+specialism+re… 7COM1084+Research+specialism+re… 7COM1084+Research+specialism+re… Overall, the assessment integrates research specialism knowledge, literature review, open-problem identification, methodological critique, research design, future-work development and scholarly communication within a Level 7 computer-science research context.

Read Model Answer →
Computer Science 2,800 words

Specialism Research Report

The Specialism Research Report is an individual assessment for the Advanced Research Topics in Computer Science module. The assignment provides students with an opportunity to develop a deeper understanding of a selected computer science research specialism and to investigate an open research question within that area. The available research specialisms are Artificial Intelligence, Networking, Cyber Security, Software Engineering and Data Science. Students are expected to examine the research specialism associated with their degree route and develop their understanding of current research challenges, established techniques and potential future research directions. The report requires students to provide an overview of the research paper presented in the relevant 7COM1084 Research Specialism Lecture. The report must identify and explain the research question addressed by the specialist paper, consider why the research problem is scientifically interesting or relevant to a real-world application, and investigate possible approaches for addressing the question. Students must also identify further research that could build upon the existing work and consider their own personal strengths, interests and experience in relation to the proposed research. The report is structured into five main sections. The first section, Introduction of Research Specialism, provides a general overview of the selected research area and is intended to be accessible to readers with broad computer science knowledge. The second section, Open Research Question, identifies and explains the research problem discussed in the specialist lecture paper and considers its scientific or practical significance. The third section, Existing and Related Work, provides a literature review of research beyond the specialist paper, identifies limitations in existing approaches and discusses related open research problems. The fourth section, Research Approach, examines the methods used in the specialist paper, evaluates their strengths and weaknesses, and proposes an approach for extending the research. The fifth section, Personal Investment, explains the student's interest in the research question and evaluates their personal strengths and experience relevant to conducting the proposed research. Students are expected to use module reading materials and secondary research to support their discussion. The report must use Harvard referencing and include at least 20 references, including the 7COM1084 specialist paper. The references are excluded from the word count. The submission must not exceed 2,800 words, with a permitted range of ±10%. The assessment develops students' ability to understand established research techniques, identify research problems from relevant literature, propose alternative solutions, critically evaluate research literature, develop approaches for future research and communicate research knowledge effectively in a scholarly manner.

Read Model Answer →
1,500 words

Network Security Evaluation and Monitoring – Reconnaissance, Incident Response and APTs

This coursework assesses the research and analytical abilities required to design and evaluate an effective network security evaluation and monitoring solution. The scenario places the student in the role of a network security evaluation specialist responsible for helping a client design and build a monitoring solution for a complex client network. The client operates in the defence and security sector, works with government departments, multinational organisations and foreign agencies, and handles sensitive information. The network includes several server farms, gateway nodes, hundreds of client nodes, internal application services, externally accessible services and wireless access points. The organisation is considered vulnerable to threats such as sabotage and intellectual property theft. The coursework requires all questions to be answered in the given order within a single report. An abstract is not required, and students are expected to use technical terminology precisely. Relevant and clearly labelled illustrations are encouraged. Where assumptions are required about security software, hardware or services already deployed on the network, these assumptions must be clearly identified in a dedicated “Assumptions” section at the beginning of the report. Question 1 focuses on detecting network reconnaissance originating from inside the organisation. Students must explain how an insider could collect and use reconnaissance information for malicious purposes, identify the types of data that should be collected and the appropriate network locations for collection, and justify the selection of monitoring data. The question also requires recommendations for suitable tools and configurations to detect reconnaissance activity, together with strategies for dealing with the scale and high traffic volume of the client network. This section carries 30 marks and has a suggested length of 500 words. Question 2 focuses on incident response following a confirmed security incident. The scenario involves suspicious out-of-hours activity and an external flash drive connected to a workstation at gateway 10, a large number of files being opened on a file server at gateway 9, and significant traffic between the workstation and a database server at gateway 5. Students must determine which previously collected data would be relevant, explain the evidence expected from that data, and recommend additional network and endpoint data that should be collected. The proposed approach must be forensically sound so that evidence can potentially be used in court. This section carries 50 marks and has a suggested length of 700 words. Question 3 addresses Advanced Persistent Threats (APTs) and evaluates the effectiveness of the proposed monitoring solution. Students must recommend appropriate testing to determine whether the monitoring system operates according to its specifications and objectives, explain the types, timing and location of testing, and identify suitable qualifications, certifications, knowledge and tool experience for security testers. The section also requires discussion of APT behaviour and how the proposed monitoring mechanisms could detect or prevent such activity. This section carries 20 marks and has a suggested length of 300 words. Overall, the coursework develops skills in network security monitoring, reconnaissance detection, incident response, digital forensics, security testing and APT detection. It requires students to connect technical monitoring strategies with practical security, legal and operational considerations within a complex organisational network environment.

Read Model Answer →
Entrepreneurship / Entrepreneurial Marketing 1,200 words

Reflective Analysis of Entrepreneurial Capabilities and Development: The GymBuddy Venture

This reflective Entrepreneurial Marketing assessment evaluates the development of the student's entrepreneurial capabilities through the GymBuddy business concept, a proposed fitness application designed to improve motivation and accountability among beginner gym users. The reflection examines how entrepreneurial learning, customer research and creativity frameworks changed the student's original approach from developing a highly complex product toward a more focused and testable business proposition. Entrepreneurial_Marketing_Refle… A central theme of the report is entrepreneurial self-assessment. Opportunity recognition is identified as an important strength, supported by interviews with beginner gym users and competitor analysis involving platforms such as Strava, MyFitnessPal and Nike Training Club. At the same time, the reflection identifies areas requiring development, particularly financial understanding, customer acquisition cost, lifetime value, conversion-rate analysis and negotiation capability. These strengths and weaknesses are used to establish priorities for future entrepreneurial development. Entrepreneurial_Marketing_Refle… The report also evaluates the evolution of the GymBuddy product using SCAMPER, Design Thinking and Lean Startup principles. Rather than pursuing a feature-heavy application, customer feedback leads to greater emphasis on simplicity, peer accountability, social competition and iterative validation. SCAMPER is applied to eliminate unnecessary features, substitute complex recommendations with simpler motivational mechanisms, combine useful functionality and adapt gamification to the needs of beginner users. Entrepreneurial_Marketing_Refle… Another major area of reflection concerns teams, networks and collaborative innovation. The student considers how group creativity exercises challenged the assumption that a venture should be developed independently and highlights the importance of mentors, developers, industry professionals and potential investors. The report links entrepreneurial networks with access to resources, opportunity identification, legitimacy and emotional support and proposes deliberate networking activities as part of future venture development. Entrepreneurial_Marketing_Refle… The visual development framework on page 3 summarises the entrepreneurial journey in five stages: GymBuddy concept and market research, capability assessment, product development and validation, teams and networks, and a time-based action plan. The reflection is structured using the Gibbs Reflective Cycle, linking experience with evaluation, analysis and future action. Entrepreneurial_Marketing_Refle… Overall, the assessment demonstrates reflective learning through the application of entrepreneurial theory to a practical start-up concept. It shows a shift from perfectionism toward rapid validation, customer-centred development, collaborative working and concrete action planning, while identifying financial management, negotiation and network development as important areas for continued improvement. Entrepreneurial_Marketing_Refle… Note: this file is a completed reflective submission rather than the original university assessment guideline, so the university, academic level and academic year should remain Not specified unless you also upload the official brief.

Read Model Answer →
Cloud Computing / Big Data Technologies / Cyber Security 2,500 words

Cloud and Big Data Security Application: Design, Implementation and Evaluation

This assessment for the Cloud and Big Data Technologies module requires students to design, implement and evaluate an individual cloud-based or distributed data application. The project focuses on practical solutions involving the complex transformation, processing, storage and security of big data within cloud environments. Students are expected to demonstrate how distributed data can be organised in the cloud, how data pipelines can be used to access or process distributed databases, and how appropriate security controls can be incorporated into the resulting architecture. Students have considerable freedom when selecting their application. Suggested project directions include developing a data-science solution using SQL or MongoDB with cloud storage and an appropriate security policy; implementing privacy-preserving distributed processing using techniques such as Differential Privacy; creating multi-party authentication and group-based access-control mechanisms; or designing Multi-Level Security, Attribute-Based Encryption or Role-Based Access Control solutions. Projects may also examine distributed or cloud applications using security protocols such as SSH, SSL or IPsec. Creativity and originality are explicitly encouraged. The written component is a Design and Implementation Document of no more than approximately 2,500 words. It should present the project aims and objectives, application concept, cloud and security technologies, functional and security requirements, architecture and design decisions, protocols, access-control mechanisms, implementation process, achievements, problems encountered and overall evaluation. Relevant diagrams, such as interaction or sequence diagrams, may be used to explain system behaviour and architecture. The assessment also requires submission of the functioning Cloud and Big Data Security application and a 7-minute highlight demonstration video. The video should demonstrate the application's major features, implementation details, security functionality and, where appropriate, attack scenarios. Assessment places strong emphasis on the quality of the design and implementation documentation, originality, use of advanced features, and the overall effort and technical quality of the completed application. Students are therefore expected to demonstrate independent development rather than simply reproduce an existing tutorial.

Read Model Answer →
Computer Science / Algorithms and Optimisation

Genetic Algorithms for the Balanced Spanning Tree Problem

This technical research work investigates the Balanced Spanning Tree Problem, an optimisation problem that seeks to construct a spanning tree capable of balancing two competing network objectives: the low overall cost associated with a Minimum Spanning Tree and the short source-to-destination distances provided by a Shortest Path Tree. For an undirected, weighted and connected graph with a designated root vertex, a balanced spanning tree is defined using two parameters, α and β. The first limits the distance between the root and each vertex relative to the corresponding shortest path in the original graph, while the second limits the total tree weight relative to the Minimum Spanning Tree. Finding an optimal balanced spanning tree is computationally challenging because determining whether a graph contains an (α, β)-balanced spanning tree is an NP-complete problem. The research therefore proposes genetic algorithms as heuristic optimisation techniques for two variants of the problem: minimising β while α is fixed, and minimising α while β is fixed. The proposed genetic algorithm represents individual spanning trees as chromosomes composed of graph edges. An initial population of valid spanning trees is generated before evolutionary operations are repeatedly applied. The approach incorporates chromosome selection, crossover, mutation, fitness evaluation and stopping criteria. Four selection strategies are examined: Random Selection, Roulette Wheel Selection, Stochastic Universal Sampling and Tournament Selection. The fitness function is based on the relationship between the Minimum Spanning Tree weight and the total weight of the candidate chromosome. Experimental evaluation is performed using randomly generated weighted graphs containing 6, 10, 15 and 20 vertices. The experiments investigate different values of the balancing parameters, selection mechanisms and population sizes. The implementation uses a population size of 30, a maximum of 300 generations, crossover probability of 0.9 and mutation probability of 0.01 in the principal experiments. The reported results show that the genetic approach can generate high-quality balanced spanning trees and, for the tested instances, produced solutions matching the corresponding optimal balanced spanning trees. The study also examines how balancing parameters and population size influence execution time and convergence, demonstrating the practical use of evolutionary computation for complex graph-optimisation problems.

Read Model Answer →
International Entrepreneurship / Business Management

International Entrepreneurship: Start-up Business Idea and International Market Expansion Pitch

This group presentation assessment requires students to develop and pitch an internationally oriented entrepreneurial business idea. Students may create their own start-up or select an existing small or medium-sized enterprise or family firm. Large multinational organisations are not permitted. The selected business must have an international dimension, either from its inception or through credible plans to undertake international activities such as overseas sourcing, manufacturing, selling or market expansion within approximately three to five years. The presentation requires students to clearly explain the proposed business idea, its products or services and the customer value proposition. Students must demonstrate how a viable market opportunity or gap has been identified and explain how the proposed venture intends to capture that opportunity. Consideration may also be given to social entrepreneurship and the potential contribution of the business to local communities. A significant part of the assessment examines how an entrepreneurial venture can overcome the practical challenges associated with start-up development and internationalisation. Students should evaluate resource scarcity and the role of entrepreneurial networks or open innovation, propose appropriate funding mechanisms such as angel investment, venture capital or crowdfunding, and explain how the venture's intellectual property could be protected. Students must also present a credible international growth strategy. This includes identifying suitable foreign markets, analysing competitors, selecting appropriate market-entry modes, defining target customer segments and developing suitable marketing and promotional strategies. All arguments should be supported with reliable evidence, with sources cited directly within the presentation and a reference list included. The assessment places emphasis on knowledge and application of entrepreneurship theories, clarity and focus of the business idea, quality and reliability of supporting materials, professional presentation delivery and the group's ability to respond confidently during questioning. All group members are expected to contribute to the work and presentation. The accompanying Group Engagement Form specifically records whether members contributed equally and allows agreed contribution percentages to be documented. Reference style: enter Not specified rather than automatically selecting Harvard. The brief requires reliable sources, slide citations and a reference list, but the uploaded assessment documents do not prescribe a named referencing system. If the actual library file you are uploading is the FourGaz presentation sample, rather than a new 2025/26 submission, use the title “FourGaz: International Entrepreneurship Start-up and Market Expansion Strategy” and do not label it 2025/26, because that sample is dated 25 November 2019.

Read Model Answer →
Cyber Security / Digital Forensics 3,500 words

Digital Forensics Portfolio: Disk Image, Memory and Windows Registry Investigation

This Level 7 Digital Forensics portfolio requires students to conduct a structured forensic investigation across disk, memory and Windows Registry evidence. The assessment develops practical investigative skills alongside professional forensic reporting and requires students to preserve evidence integrity, document methodology, interpret technical artefacts and communicate findings clearly. The portfolio is equivalent to 3,500 words and forms 60% of the module assessment. The first part involves analysing a seized USB forensic image in the context of a suspected insider involved in video piracy and potentially more serious criminal activity. Students must follow ACPO digital forensic best practice, verify image integrity before and after examination, maintain a clear chain of custody, identify significant device properties and artefacts, and justify conclusions using evidence. Tools such as FTK Imager and Autopsy may be used, alongside other appropriate forensic utilities. The scenario also requires examination of an encrypted VeraCrypt container discovered within the evidence. The second part focuses on memory forensics using a Windows memory dump. Students are expected to reconstruct process execution timelines, examine suspicious processes including PowerShell, Notepad and AtomicService, identify process owners and SIDs, extract relevant memory artefacts and produce an executive summary suitable for a non-technical audience. The third part requires an extensive Windows Registry and system artefact investigation. Students examine operating-system information, users, network configuration, login activity, suspicious files, executable and DLL creation, BAM records, Prefetch artefacts, scheduled tasks, persistence mechanisms and evidence of potentially malicious activity. Findings must be supported with screenshots, extracted artefacts or other appropriate evidence. The assignment must use the university's official portfolio template and be submitted as a PDF. The template organises the work into forensic image analysis, memory investigation and Windows Registry investigation sections. For a public Reference Library entry, this title is better than simply “Digital Forensics Coursework” because it clearly communicates the three major technical components of the work.

Read Model Answer →

Cyber Security for Business and Cloud Management

This activity aims to assess your comprehension of the diverse concepts discussed in this module. You must use the frameworks and concepts covered in this module's delivery to respond to all the tasks below. Scenario ShieldSafe Analytics Ltd. is a fast-growing health analytics company specialising in AI-driven patient diagnostics and telehealth platforms. Operating across multiple countries, the company processes high volumes of real-time patient data, including biometric and genomic records. Due to the increased reliance on remote healthcare and IoT-enabled medical devices, their infrastructure has expanded into hybrid cloud environments. Recently, ShieldSafe experienced a suspected data exfiltration incident involving anomalous traffic from one of its diagnostic platforms integrated with third-party cloud APIs. As a result, executive leadership has raised concerns about the company’s vulnerability to adversarial information operations, particularly in relation to data manipulation, misinformation, and insider threats. As a Junior Cybersecurity Strategist, you’ve been recruited to support the lead cyber intelligence consultant in reviewing vulnerabilities within their information environment, exploring offensive and defensive Information Operations (IO) concepts, and crafting robust cyber defence mechanisms. The leadership also wants to migrate a legacy electronic health record (EHR) system used across its African operations to a more scalable and secure cloud infrastructure. However, concerns exist regarding cross-border data protection laws, insider threats, and the strategic use of information in potential cyber warfare scenarios.

Read Model Answer →

L7 Cyber Security for Business and Cloud Management

This activity aims to assess your comprehension of the diverse concepts discussed in this module. You must use the frameworks and concepts covered in this module's delivery to respond to all the tasks below. Scenario ShieldSafe Analytics Ltd. is a fast-growing health analytics company specialising in AI-driven patient diagnostics and telehealth platforms. Operating across multiple countries, the company processes high volumes of real-time patient data, including biometric and genomic records. Due to the increased reliance on remote healthcare and IoT-enabled medical devices, their infrastructure has expanded into hybrid cloud environments. Recently, ShieldSafe experienced a suspected data exfiltration incident involving anomalous traffic from one of its diagnostic platforms integrated with third-party cloud APIs. As a result, executive leadership has raised concerns about the company’s vulnerability to adversarial information operations, particularly in relation to data manipulation, misinformation, and insider threats. As a Junior Cybersecurity Strategist, you’ve been recruited to support the lead cyber intelligence consultant in reviewing vulnerabilities within their information environment, exploring offensive and defensive Information Operations (IO) concepts, and crafting robust cyber defence mechanisms. The leadership also wants to migrate a legacy electronic health record (EHR) system used across its African operations to a more scalable and secure cloud infrastructure. However, concerns exist regarding cross-border data protection laws, insider threats, and the strategic use of information in potential cyber warfare scenarios.

Read Model Answer →