Academic Model Answers
Library for UK Postgraduates

Browse tutor-verified model answers across MBA, Law, Finance, Research Methods and more. Use as study references for your own work.

202 model answers 30+ subjects covered 50+ UK universities
Find your assignment

Search the Library

Filter by keyword, subject, or both. Updates live as new model answers are added to our portal.

Filtering by “Insider Threats” Clear filters

Available Model Answers (4)

Real-time Database Sync
Cyber Security / Applied Cryptography / Secure Systems Design 2,500 words

Secure Property Contract Exchange: Cryptographic Protocol Design, Threat Modelling and Post-Quantum Readiness

This Applied Theory of Cyber Security and Secure Design coursework places students in the role of a cyber security consultant engaged by Hackit & Run LLP, a legal firm specialising in UK and international property transactions. The firm wishes to implement a secure digital system for handling, exchanging and legally signing property contracts. Students must design and evaluate a secure communication protocol supporting interactions between the buyer’s solicitor, the seller’s solicitor and the buyer while addressing both first-time communications and previously established secure relationships. 11b17febb9eeb4570f76f6ca95a831a… Section A – Cryptographic Protocol Design, worth 45%, requires a complete secure communication protocol. Students must explain how trust is initially established, how later communications can be simplified without weakening confidentiality, integrity or availability, and how the buyer can digitally sign a contract in a manner enforceable under UK law. The design must justify specific cryptographic algorithms for functions such as key exchange, bulk encryption, digital signatures and hashing. The protocol must be presented through both a sequence diagram showing message flows and cryptographic operations and pseudocode explaining the key algorithmic stages. 11b17febb9eeb4570f76f6ca95a831a… Section B – Threat Modelling, worth 20%, requires a focused analysis using the STRIDE methodology. Students identify three realistic threats from different STRIDE categories and analyse the attack vector, asset at risk and potential effect on the legal transaction. Each threat must then be connected back to specific protocol defences, with residual risks acknowledged where controls cannot provide complete mitigation. The guidance encourages consideration of issues such as social engineering, insider threats, key-management failures and availability risks in addition to purely cryptographic attacks. 11b17febb9eeb4570f76f6ca95a831a… Section C – Security Evaluation Against Standards, worth 15%, requires students to evaluate the proposed system against a recognised cybersecurity standard or framework. Options include ISO/IEC 27001:2022, Common Criteria (ISO/IEC 15408) and the OWASP Application Security Verification Standard. Students select three or four directly relevant controls or requirements, assess whether the proposed design satisfies them, identify gaps and recommend specific improvements. 11b17febb9eeb4570f76f6ca95a831a… Section D – Post-Quantum Readiness and Critical Reflection, worth 15%, examines how a future quantum-capable adversary could affect the protocol. Students identify vulnerable cryptographic components, discuss the NIST Post-Quantum Cryptography standardisation programme, and examine replacement algorithms such as ML-KEM for key establishment and ML-DSA for digital signatures. They must also evaluate a hybrid migration strategy combining classical and post-quantum algorithms, considering performance overhead, backward compatibility and the legal admissibility of post-quantum digital signatures. 11b17febb9eeb4570f76f6ca95a831a… The remaining 5% evaluates professional report quality, logical structure, technical language, integration of diagrams and consistent CUHarvard referencing. Higher-quality work is expected to demonstrate a sophisticated trust model, clear traceability between threats and controls, precise standards mapping, practical security recommendations and well-evidenced analysis of post-quantum migration. 11b17febb9eeb4570f76f6ca95a831a… Important for the public Reference Library: the brief states that the assessment document is intended only for Coventry University Group students and must not be passed to third parties or posted on any website. Therefore, publish only an original high-level description such as the overview above; do not upload or reproduce the original assignment brief publicly. 11b17febb9eeb4570f76f6ca95a831a…

Read Model Answer →
1,500 words

Network Security Evaluation and Monitoring – Reconnaissance, Incident Response and APTs

This coursework assesses the research and analytical abilities required to design and evaluate an effective network security evaluation and monitoring solution. The scenario places the student in the role of a network security evaluation specialist responsible for helping a client design and build a monitoring solution for a complex client network. The client operates in the defence and security sector, works with government departments, multinational organisations and foreign agencies, and handles sensitive information. The network includes several server farms, gateway nodes, hundreds of client nodes, internal application services, externally accessible services and wireless access points. The organisation is considered vulnerable to threats such as sabotage and intellectual property theft. The coursework requires all questions to be answered in the given order within a single report. An abstract is not required, and students are expected to use technical terminology precisely. Relevant and clearly labelled illustrations are encouraged. Where assumptions are required about security software, hardware or services already deployed on the network, these assumptions must be clearly identified in a dedicated “Assumptions” section at the beginning of the report. Question 1 focuses on detecting network reconnaissance originating from inside the organisation. Students must explain how an insider could collect and use reconnaissance information for malicious purposes, identify the types of data that should be collected and the appropriate network locations for collection, and justify the selection of monitoring data. The question also requires recommendations for suitable tools and configurations to detect reconnaissance activity, together with strategies for dealing with the scale and high traffic volume of the client network. This section carries 30 marks and has a suggested length of 500 words. Question 2 focuses on incident response following a confirmed security incident. The scenario involves suspicious out-of-hours activity and an external flash drive connected to a workstation at gateway 10, a large number of files being opened on a file server at gateway 9, and significant traffic between the workstation and a database server at gateway 5. Students must determine which previously collected data would be relevant, explain the evidence expected from that data, and recommend additional network and endpoint data that should be collected. The proposed approach must be forensically sound so that evidence can potentially be used in court. This section carries 50 marks and has a suggested length of 700 words. Question 3 addresses Advanced Persistent Threats (APTs) and evaluates the effectiveness of the proposed monitoring solution. Students must recommend appropriate testing to determine whether the monitoring system operates according to its specifications and objectives, explain the types, timing and location of testing, and identify suitable qualifications, certifications, knowledge and tool experience for security testers. The section also requires discussion of APT behaviour and how the proposed monitoring mechanisms could detect or prevent such activity. This section carries 20 marks and has a suggested length of 300 words. Overall, the coursework develops skills in network security monitoring, reconnaissance detection, incident response, digital forensics, security testing and APT detection. It requires students to connect technical monitoring strategies with practical security, legal and operational considerations within a complex organisational network environment.

Read Model Answer →

Cyber Security for Business and Cloud Management

This activity aims to assess your comprehension of the diverse concepts discussed in this module. You must use the frameworks and concepts covered in this module's delivery to respond to all the tasks below. Scenario ShieldSafe Analytics Ltd. is a fast-growing health analytics company specialising in AI-driven patient diagnostics and telehealth platforms. Operating across multiple countries, the company processes high volumes of real-time patient data, including biometric and genomic records. Due to the increased reliance on remote healthcare and IoT-enabled medical devices, their infrastructure has expanded into hybrid cloud environments. Recently, ShieldSafe experienced a suspected data exfiltration incident involving anomalous traffic from one of its diagnostic platforms integrated with third-party cloud APIs. As a result, executive leadership has raised concerns about the company’s vulnerability to adversarial information operations, particularly in relation to data manipulation, misinformation, and insider threats. As a Junior Cybersecurity Strategist, you’ve been recruited to support the lead cyber intelligence consultant in reviewing vulnerabilities within their information environment, exploring offensive and defensive Information Operations (IO) concepts, and crafting robust cyber defence mechanisms. The leadership also wants to migrate a legacy electronic health record (EHR) system used across its African operations to a more scalable and secure cloud infrastructure. However, concerns exist regarding cross-border data protection laws, insider threats, and the strategic use of information in potential cyber warfare scenarios.

Read Model Answer →

L7 Cyber Security for Business and Cloud Management

This activity aims to assess your comprehension of the diverse concepts discussed in this module. You must use the frameworks and concepts covered in this module's delivery to respond to all the tasks below. Scenario ShieldSafe Analytics Ltd. is a fast-growing health analytics company specialising in AI-driven patient diagnostics and telehealth platforms. Operating across multiple countries, the company processes high volumes of real-time patient data, including biometric and genomic records. Due to the increased reliance on remote healthcare and IoT-enabled medical devices, their infrastructure has expanded into hybrid cloud environments. Recently, ShieldSafe experienced a suspected data exfiltration incident involving anomalous traffic from one of its diagnostic platforms integrated with third-party cloud APIs. As a result, executive leadership has raised concerns about the company’s vulnerability to adversarial information operations, particularly in relation to data manipulation, misinformation, and insider threats. As a Junior Cybersecurity Strategist, you’ve been recruited to support the lead cyber intelligence consultant in reviewing vulnerabilities within their information environment, exploring offensive and defensive Information Operations (IO) concepts, and crafting robust cyber defence mechanisms. The leadership also wants to migrate a legacy electronic health record (EHR) system used across its African operations to a more scalable and secure cloud infrastructure. However, concerns exist regarding cross-border data protection laws, insider threats, and the strategic use of information in potential cyber warfare scenarios.

Read Model Answer →