Academic Model Answers
Library for UK Postgraduates

Browse tutor-verified model answers across MBA, Law, Finance, Research Methods and more. Use as study references for your own work.

200 model answers 30+ subjects covered 50+ UK universities
Find your assignment

Search the Library

Filter by keyword, subject, or both. Updates live as new model answers are added to our portal.

Filtering by “Network Scanning” Clear filters

Available Model Answers (3)

Real-time Database Sync
1,500 words

Network Security Evaluation and Monitoring – Reconnaissance, Incident Response and APTs

This coursework assesses the research and analytical abilities required to design and evaluate an effective network security evaluation and monitoring solution. The scenario places the student in the role of a network security evaluation specialist responsible for helping a client design and build a monitoring solution for a complex client network. The client operates in the defence and security sector, works with government departments, multinational organisations and foreign agencies, and handles sensitive information. The network includes several server farms, gateway nodes, hundreds of client nodes, internal application services, externally accessible services and wireless access points. The organisation is considered vulnerable to threats such as sabotage and intellectual property theft. The coursework requires all questions to be answered in the given order within a single report. An abstract is not required, and students are expected to use technical terminology precisely. Relevant and clearly labelled illustrations are encouraged. Where assumptions are required about security software, hardware or services already deployed on the network, these assumptions must be clearly identified in a dedicated “Assumptions” section at the beginning of the report. Question 1 focuses on detecting network reconnaissance originating from inside the organisation. Students must explain how an insider could collect and use reconnaissance information for malicious purposes, identify the types of data that should be collected and the appropriate network locations for collection, and justify the selection of monitoring data. The question also requires recommendations for suitable tools and configurations to detect reconnaissance activity, together with strategies for dealing with the scale and high traffic volume of the client network. This section carries 30 marks and has a suggested length of 500 words. Question 2 focuses on incident response following a confirmed security incident. The scenario involves suspicious out-of-hours activity and an external flash drive connected to a workstation at gateway 10, a large number of files being opened on a file server at gateway 9, and significant traffic between the workstation and a database server at gateway 5. Students must determine which previously collected data would be relevant, explain the evidence expected from that data, and recommend additional network and endpoint data that should be collected. The proposed approach must be forensically sound so that evidence can potentially be used in court. This section carries 50 marks and has a suggested length of 700 words. Question 3 addresses Advanced Persistent Threats (APTs) and evaluates the effectiveness of the proposed monitoring solution. Students must recommend appropriate testing to determine whether the monitoring system operates according to its specifications and objectives, explain the types, timing and location of testing, and identify suitable qualifications, certifications, knowledge and tool experience for security testers. The section also requires discussion of APT behaviour and how the proposed monitoring mechanisms could detect or prevent such activity. This section carries 20 marks and has a suggested length of 300 words. Overall, the coursework develops skills in network security monitoring, reconnaissance detection, incident response, digital forensics, security testing and APT detection. It requires students to connect technical monitoring strategies with practical security, legal and operational considerations within a complex organisational network environment.

Read Model Answer →
Ethical Hacking 2,500 words

Ethical Hacking – Professional Penetration Testing Report

This resit coursework for the Ethical Hacking module at Coventry University requires students to conduct a professional penetration testing examination of a small office environment represented by a number of virtual machines. The purpose of the assessment is to evaluate the security of the target environment, identify vulnerabilities, demonstrate appropriate exploitation techniques within the authorised assessment environment, and produce professional recommendations for improving the security of the systems. The assignment carries 15 credits and requires a report of approximately 2,000 words, with a permitted variation of ±10%. The report should follow a structured penetration-testing approach. The first section covers reconnaissance and target analysis, requiring students to investigate the target environment and identify its structure, services and potential attack surfaces. The marking criteria emphasise the use of appropriate tools to identify network structure and services and the identification of vulnerabilities during the scanning process. Students are expected to analyse the results rather than simply reproduce the output of scanning tools. The second section focuses on exploitation. Students must describe in detail the steps taken and the tools used to exploit relevant vulnerabilities identified during the assessment. The marking criteria distinguish between compromising the desktop and gaining access to the server, with higher achievement involving multiple relevant vulnerabilities and successful access through more than one vulnerability. The report should provide appropriate screenshots and sample sessions to support the findings. The third section addresses post-exploitation activities. Students are required to document and analyse activities carried out after gaining access to the target systems. Examples identified in the marking criteria include dumping password hashes and creating a persistent backdoor. For server assessment, the criteria also consider activities such as obtaining root access or establishing a persistent connection. The report should explain the significance of the activities rather than merely listing technical actions. The fourth section provides recommendations for securing the target machines. Recommendations must address all vulnerabilities identified during the assessment, not only vulnerabilities that were successfully exploited. Security issues should be discussed using an established risk-rating approach such as OWASP, and proposed countermeasures should be relevant to the specific vulnerabilities discovered. The report should also analyse how vulnerabilities relate to one another and fit within the wider security context. The final section presents the conclusions, including an evaluation of the penetration-testing work and alternative approaches that could have been taken. The overall learning outcomes require students to critically discuss the legal, technical and ethical scope of ethical hacking, evaluate penetration-testing methodologies and security assessment tools, analyse vulnerabilities, and professionally report penetration-test outcomes with suitable countermeasures.

Read Model Answer →
Cyber Security / Penetration Testing 2,400 words

Grey-Box Penetration Testing: Vulnerability Assessment, Exploitation and Mitigation

This technical cyber-security project presents an authorised grey-box penetration test conducted within a controlled virtual laboratory environment. The objective is to assess the security posture of a deliberately vulnerable target system, identify weaknesses in exposed network services, demonstrate how those weaknesses could be exploited, evaluate their security and organisational impact, and recommend appropriate mitigation measures. The assessment follows a practical penetration-testing workflow supported by technical evidence, screenshots, activity records and academic research. The project begins with laboratory configuration, network discovery, service enumeration and vulnerability analysis. Tools including Kali Linux, Metasploitable, VMware, Nmap, Netcat and Metasploit are used across the testing lifecycle. Identified services are mapped to known vulnerabilities before controlled exploitation is undertaken and the resulting access is documented. The activity log records the progression from environment setup and network scanning through vulnerability identification, exploitation, evidence collection and final reporting. Five principal attack vectors are examined. These include the vsftpd 2.3.4 FTP backdoor, Samba username-map-script exploitation, an UnrealIRCd backdoor, insecure Java Remote Method Invocation and a misconfigured DistCC service. The practical demonstrations show how vulnerable or incorrectly configured services can permit unauthorised command execution and, in several cases, privileged shell access. For each vulnerability, the report explains the weakness, exploitation process, observed result, security impact and proposed mitigation. Recommended controls include patching or upgrading obsolete services, disabling unnecessary services, implementing firewall restrictions, strengthening authentication and input validation, restricting access to authorised systems, applying least privilege and monitoring suspicious activity. The project also incorporates group management and reflective practice. Team members perform specialised roles covering laboratory configuration, reconnaissance, vulnerability analysis, exploitation and documentation. Individual reflection considers technical performance, teamwork, evidence management and future skills development, demonstrating how structured collaboration contributes to an effective penetration-testing engagement. Important: unlike the earlier assignment briefs, these uploads appear to be completed student/project materials rather than the official 7COM1068 assessment brief. Therefore I would not invent the university, academic level or academic year. If you upload the actual 7COM1068 assignment guideline, I can fill those fields exactly.

Read Model Answer →