Academic Model Answers
Library for UK Postgraduates

Browse tutor-verified model answers across MBA, Law, Finance, Research Methods and more. Use as study references for your own work.

200 model answers 30+ subjects covered 50+ UK universities
Find your assignment

Search the Library

Filter by keyword, subject, or both. Updates live as new model answers are added to our portal.

Filtering by “OWASP” Clear filters

Available Model Answers (7)

Real-time Database Sync
Security of Connected Systems 4,500 words

CW: Security Evaluation

This assignment is an individual technical report focused on the security evaluation and strategic development of a rapidly expanding Internet of Things (IoT) systems developer based in Coventry. The client specialises in innovative IoT devices and systems for residential and commercial applications, particularly smart energy monitoring, and is planning to scale its operations and expand into new markets. The report is designed to provide practical and strategic guidance on how the organisation can achieve this growth while maintaining strong cybersecurity. The assignment requires students to act as an external IoT Security and Scaling Strategist and critically evaluate the organisation’s current and future security needs. The report covers four principal areas: organisational change strategy, secure design and development strategy, security audit strategy, and security recommendations. The organisational change section considers internal and external factors influencing growth, the development and implementation of an organisational strategy, monitoring against objectives, and approaches to leading and managing strategic change using relevant change management theories and models. The secure design and development section requires an overview and evaluation of possible secure design processes for IoT systems, including their strengths and weaknesses, followed by a recommendation for an appropriate process. The security audit section examines methods such as PTES and OWASP and develops a guide for conducting a security audit, including the testing methodology, rationale for each stage, and evaluation of different approaches. The security recommendations section requires a case study of an IoT security vulnerability, examination of where the security flaw was introduced, assessment of weaknesses in the secure design or audit process, consideration of the resulting security impact, and recommendations for improvement. The report should be written for a technical audience, particularly the client’s software development team, and should use appropriate structure, technical language, diagrams where useful, and APA referencing. The organisational strategy and strategic change proposal should be included in appendices and referenced within the main report. The assessment is worth 30 credits and has a maximum word count of 4,500 words, with the main sections weighted across organisational change, secure design, security auditing, security recommendations, and report structure.

Read Model Answer →
Cyber Security / Internet of Things / Connected Systems 4,500 words

Security Evaluation for Connected Systems: IoT Strategy, Secure Design, Security Auditing and Organisational Change

This Security of Connected Systems assessment requires students to act as an external IoT Security and Scaling Strategist for a rapidly expanding Coventry-based technology startup specialising in connected devices and smart energy-monitoring systems. The client intends to scale its operations and enter new markets and therefore requires both organisational-change guidance and a comprehensive evaluation of its cybersecurity posture. 38f2fba9a933f212c9e46e8cc591cf2… The report combines business strategy with technical cybersecurity analysis. Students must review different secure design and development methodologies, compare their strengths and weaknesses, and recommend an appropriate approach for integrating security into the client's IoT software-development lifecycle. 38f2fba9a933f212c9e46e8cc591cf2… 38f2fba9a933f212c9e46e8cc591cf2… A major component of the assessment focuses on organisational change strategy. Students examine the internal and external factors driving organisational growth, develop a comprehensive strategy for achieving the client's business objectives, and explain how that strategy should be implemented and monitored. The report must also critically evaluate relevant change-management theories and models and address the complexities of leading and managing strategic transformation. This section carries 35% of the marks and is allocated approximately 2,000 words. 38f2fba9a933f212c9e46e8cc591cf2… The Security Audit Strategy section requires students to design a guide for auditing the client's connected system. Different approaches, including methodologies such as PTES and OWASP, should be compared and evaluated. Students must explain each stage of the selected testing methodology and justify why the individual steps are required. 38f2fba9a933f212c9e46e8cc591cf2… The final technical component applies these principles to an IoT vulnerability case study. Students research a real vulnerability in an IoT device, explain where the security flaw was introduced, identify weaknesses in the secure-design or audit process, assess the resulting security impact and propose appropriate corrective actions. 38f2fba9a933f212c9e46e8cc591cf2… Overall, the coursework integrates IoT cybersecurity, secure software development, security auditing, vulnerability analysis, organisational strategy and strategic change management. The marking scheme allocates 35% to organisational-change strategy, 20% each to secure design and development, security auditing and security recommendations, and 5% to report structure. 38f2fba9a933f212c9e46e8cc591cf2… Important: the brief states that it is for Coventry University Group students' own use and must not be passed to third parties or posted on a website. 38f2fba9a933f212c9e46e8cc591cf2… So use an original public summary like the one above, but do not upload the original brief itself.

Read Model Answer →
Cyber Security / Applied Cryptography / Secure Systems Design 2,500 words

Secure Property Contract Exchange: Cryptographic Protocol Design, Threat Modelling and Post-Quantum Readiness

This Applied Theory of Cyber Security and Secure Design coursework places students in the role of a cyber security consultant engaged by Hackit & Run LLP, a legal firm specialising in UK and international property transactions. The firm wishes to implement a secure digital system for handling, exchanging and legally signing property contracts. Students must design and evaluate a secure communication protocol supporting interactions between the buyer’s solicitor, the seller’s solicitor and the buyer while addressing both first-time communications and previously established secure relationships. 11b17febb9eeb4570f76f6ca95a831a… Section A – Cryptographic Protocol Design, worth 45%, requires a complete secure communication protocol. Students must explain how trust is initially established, how later communications can be simplified without weakening confidentiality, integrity or availability, and how the buyer can digitally sign a contract in a manner enforceable under UK law. The design must justify specific cryptographic algorithms for functions such as key exchange, bulk encryption, digital signatures and hashing. The protocol must be presented through both a sequence diagram showing message flows and cryptographic operations and pseudocode explaining the key algorithmic stages. 11b17febb9eeb4570f76f6ca95a831a… Section B – Threat Modelling, worth 20%, requires a focused analysis using the STRIDE methodology. Students identify three realistic threats from different STRIDE categories and analyse the attack vector, asset at risk and potential effect on the legal transaction. Each threat must then be connected back to specific protocol defences, with residual risks acknowledged where controls cannot provide complete mitigation. The guidance encourages consideration of issues such as social engineering, insider threats, key-management failures and availability risks in addition to purely cryptographic attacks. 11b17febb9eeb4570f76f6ca95a831a… Section C – Security Evaluation Against Standards, worth 15%, requires students to evaluate the proposed system against a recognised cybersecurity standard or framework. Options include ISO/IEC 27001:2022, Common Criteria (ISO/IEC 15408) and the OWASP Application Security Verification Standard. Students select three or four directly relevant controls or requirements, assess whether the proposed design satisfies them, identify gaps and recommend specific improvements. 11b17febb9eeb4570f76f6ca95a831a… Section D – Post-Quantum Readiness and Critical Reflection, worth 15%, examines how a future quantum-capable adversary could affect the protocol. Students identify vulnerable cryptographic components, discuss the NIST Post-Quantum Cryptography standardisation programme, and examine replacement algorithms such as ML-KEM for key establishment and ML-DSA for digital signatures. They must also evaluate a hybrid migration strategy combining classical and post-quantum algorithms, considering performance overhead, backward compatibility and the legal admissibility of post-quantum digital signatures. 11b17febb9eeb4570f76f6ca95a831a… The remaining 5% evaluates professional report quality, logical structure, technical language, integration of diagrams and consistent CUHarvard referencing. Higher-quality work is expected to demonstrate a sophisticated trust model, clear traceability between threats and controls, precise standards mapping, practical security recommendations and well-evidenced analysis of post-quantum migration. 11b17febb9eeb4570f76f6ca95a831a… Important for the public Reference Library: the brief states that the assessment document is intended only for Coventry University Group students and must not be passed to third parties or posted on any website. Therefore, publish only an original high-level description such as the overview above; do not upload or reproduce the original assignment brief publicly. 11b17febb9eeb4570f76f6ca95a831a…

Read Model Answer →
Cyber Security / Penetration Testing

Web Application Penetration Testing and Security Vulnerability Assessment Portfolio

This postgraduate cyber security portfolio requires students to conduct a structured penetration test of a controlled web application and document the technical findings in a professional security-testing format. The assessment develops practical competence in identifying, validating and communicating security vulnerabilities while maintaining appropriate legal, ethical and professional boundaries. Assessment Brief CMP-L021 (PG) … Students begin by performing network and service enumeration, identifying open ports and the services running on the target host. They are expected to interpret the security implications of the findings and provide appropriate recommendations to a hypothetical client. The assessment then progresses into web-application vulnerability testing using tools such as a web browser, Burp Suite Community, Nmap and student-developed scripts. Assessment Brief CMP-L021 (PG) … A major part of the portfolio examines common web-security weaknesses including SQL Injection and Cross-Site Scripting. Students must demonstrate how they tested the application, capture relevant requests and responses, and explain the evidence supporting their conclusions. Additional tasks involve application and server reconnaissance, including identification of technologies, server versions, publicly exposed files and other information that may create security risks. Assessment Brief CMP-L021 (PG) … The higher-level reporting component requires students to document significant vulnerabilities using the conventions of a professional penetration-test report. This includes assigning CVSS scores, relating identified weaknesses to the OWASP Top 10 and NIST classifications, and supporting findings with appropriate technical evidence. Assessment Brief CMP-L021 (PG) … Students must also produce an executive summary for a non-technical audience, considering security, privacy, regulatory exposure and budget implications. A vulnerability table linking technical weaknesses with relevant regulatory concerns is also required. Overall, the assessment integrates technical penetration testing with risk communication, vulnerability classification, evidence collection and professional security reporting. Assessment Brief CMP-L021 (PG) … Overview word count: approximately 320 words. AI-use note: AI can be used in this assessment, but any use must be acknowledged and AI-generated outputs must be appropriately cited. Assessment Brief CMP-L021 (PG) …

Read Model Answer →
Cyber Security / Ethical Hacking / Penetration Testing 4,000 words

Ethical Hacking and Penetration Testing: Vulnerability Exploitation, Privilege Escalation and Mitigation

This Ethical Hacking and Penetration Testing coursework requires students to conduct a practical CTF-style penetration test against a set of authorised target machines and produce a professional technical report documenting the compromise of one selected target. The assessment evaluates practical exploitation skills alongside the ability to analyse risk, explain attack vectors and recommend effective security controls. 8598ba8d8fff5a38af8d427a4ce8f84… The practical element requires students to identify vulnerabilities in multiple target systems, exploit those weaknesses to gain low-privileged access and then perform privilege escalation to obtain root-level access. Successful completion of each stage produces flags, with separate user and root flags contributing directly to the practical marks. Brief descriptions of the attack vectors and payloads used must also be recorded. 8598ba8d8fff5a38af8d427a4ce8f84… The written report focuses in detail on one compromised machine. Students must explain the reconnaissance and vulnerability-identification process, including the techniques used to discover services, web content and potential attack surfaces. The marking criteria specifically recognise appropriate reconnaissance tools such as Nmap and FFUF and reward clear justification of methods and links between reconnaissance results and identified threats. 8598ba8d8fff5a38af8d427a4ce8f84… 8598ba8d8fff5a38af8d427a4ce8f84… A further component requires a formal risk rating for the discovered vulnerabilities. Students should use a recognised risk-classification approach, such as OWASP or SANS, justify the assigned severity and discuss relevant social, legal and ethical considerations. Higher-performing work is expected to connect those considerations directly to the specific vulnerabilities identified. 8598ba8d8fff5a38af8d427a4ce8f84… The exploit section should explain the technical cause of the vulnerability, describe the exploitation process and present relevant example payloads. Mitigation recommendations must then be linked directly to the vulnerabilities discovered, with clear explanations of where the weakness occurs and how it can be remediated. 8598ba8d8fff5a38af8d427a4ce8f84… Overall, the coursework integrates reconnaissance, vulnerability analysis, exploitation, privilege escalation, risk assessment, ethical and legal considerations, technical reporting and defensive mitigation within an authorised penetration-testing environment. Important: this brief states that it is for Coventry University Group students' own use and must not be passed to third parties or posted publicly. 8598ba8d8fff5a38af8d427a4ce8f84… So for your public Reference Library, use an original summary like the one above rather than uploading the assessment brief itself.

Read Model Answer →
Security of Emerging Connected Systems 2,000 words

Security Evaluation – Secure Design, Security Audit and IoT Security Recommendations

This individual coursework for the Security of Emerging Connected Systems module requires students to prepare a 2,000-word technical report evaluating secure design, security auditing and security recommendations for an organisation developing Internet of Things (IoT) devices and systems for home and workplace environments. The assessment is worth 10 credits and requires students to provide practical and evidence-based guidance to the client’s software development team. The report is assessed across secure design and development methodology, security audit methodology, security recommendations and overall report structure. The first major section addresses Secure Design and Development Methodology. The client wants to incorporate secure design principles into its software development workflow and therefore requires an overview of possible secure design processes relevant to IoT. Students must evaluate the strengths and weaknesses of different approaches and provide a justified recommendation for a process that would be appropriate for the client. The emphasis is on integrating security into the design and development of systems rather than treating security as a separate activity after development. The second section focuses on Security Audit Methodology. The client wants to complement its secure design process with a security audit of the final developed system. Students must provide a practical guide explaining how a security audit could be performed, including the overall testing methodology and the purpose of each stage. The brief identifies methodologies such as PTES and OWASP as examples. Students are also expected to discuss different approaches and evaluate their respective strengths and weaknesses. The third section concerns Security Recommendations and requires students to demonstrate the implications of strong secure design and auditing through an IoT security case study. Students must research a security vulnerability affecting an IoT device, explain the vulnerability and identify where the security flaw was introduced. The report must then examine which parts of the secure design and audit processes were not implemented correctly and evaluate the resulting impact on the security of the product. The report is intended for a technical audience, specifically the client's software development team. Students are expected to use an appropriate technical structure and language, support their arguments and analysis with references, and use APA referencing. The assessment also encourages appropriate diagrams to support the written content. The report structure component accounts for 10% of the assessment, while Secure Design and Development Methodology, Security Audit Methodology and Security Recommendations each account for 30%. The coursework assesses learning outcomes relating to defence-in-depth solutions for technical internet security vulnerabilities, secure private networks for IoT and BYOD, and current research and technological advances in network security. These outcomes connect the assignment to practical IoT security engineering, secure development, security auditing and emerging network-security practices.

Read Model Answer →
Ethical Hacking 2,500 words

Ethical Hacking – Professional Penetration Testing Report

This resit coursework for the Ethical Hacking module at Coventry University requires students to conduct a professional penetration testing examination of a small office environment represented by a number of virtual machines. The purpose of the assessment is to evaluate the security of the target environment, identify vulnerabilities, demonstrate appropriate exploitation techniques within the authorised assessment environment, and produce professional recommendations for improving the security of the systems. The assignment carries 15 credits and requires a report of approximately 2,000 words, with a permitted variation of ±10%. The report should follow a structured penetration-testing approach. The first section covers reconnaissance and target analysis, requiring students to investigate the target environment and identify its structure, services and potential attack surfaces. The marking criteria emphasise the use of appropriate tools to identify network structure and services and the identification of vulnerabilities during the scanning process. Students are expected to analyse the results rather than simply reproduce the output of scanning tools. The second section focuses on exploitation. Students must describe in detail the steps taken and the tools used to exploit relevant vulnerabilities identified during the assessment. The marking criteria distinguish between compromising the desktop and gaining access to the server, with higher achievement involving multiple relevant vulnerabilities and successful access through more than one vulnerability. The report should provide appropriate screenshots and sample sessions to support the findings. The third section addresses post-exploitation activities. Students are required to document and analyse activities carried out after gaining access to the target systems. Examples identified in the marking criteria include dumping password hashes and creating a persistent backdoor. For server assessment, the criteria also consider activities such as obtaining root access or establishing a persistent connection. The report should explain the significance of the activities rather than merely listing technical actions. The fourth section provides recommendations for securing the target machines. Recommendations must address all vulnerabilities identified during the assessment, not only vulnerabilities that were successfully exploited. Security issues should be discussed using an established risk-rating approach such as OWASP, and proposed countermeasures should be relevant to the specific vulnerabilities discovered. The report should also analyse how vulnerabilities relate to one another and fit within the wider security context. The final section presents the conclusions, including an evaluation of the penetration-testing work and alternative approaches that could have been taken. The overall learning outcomes require students to critically discuss the legal, technical and ethical scope of ethical hacking, evaluate penetration-testing methodologies and security assessment tools, analyse vulnerabilities, and professionally report penetration-test outcomes with suitable countermeasures.

Read Model Answer →