Academic Model Answers
Library for UK Postgraduates

Browse tutor-verified model answers across MBA, Law, Finance, Research Methods and more. Use as study references for your own work.

200 model answers 30+ subjects covered 50+ UK universities
Find your assignment

Search the Library

Filter by keyword, subject, or both. Updates live as new model answers are added to our portal.

Filtering by “Reconnaissance” Clear filters

Available Model Answers (5)

Real-time Database Sync
Cyber Security / Penetration Testing

Web Application Penetration Testing and Security Vulnerability Assessment Portfolio

This postgraduate cyber security portfolio requires students to conduct a structured penetration test of a controlled web application and document the technical findings in a professional security-testing format. The assessment develops practical competence in identifying, validating and communicating security vulnerabilities while maintaining appropriate legal, ethical and professional boundaries. Assessment Brief CMP-L021 (PG) … Students begin by performing network and service enumeration, identifying open ports and the services running on the target host. They are expected to interpret the security implications of the findings and provide appropriate recommendations to a hypothetical client. The assessment then progresses into web-application vulnerability testing using tools such as a web browser, Burp Suite Community, Nmap and student-developed scripts. Assessment Brief CMP-L021 (PG) … A major part of the portfolio examines common web-security weaknesses including SQL Injection and Cross-Site Scripting. Students must demonstrate how they tested the application, capture relevant requests and responses, and explain the evidence supporting their conclusions. Additional tasks involve application and server reconnaissance, including identification of technologies, server versions, publicly exposed files and other information that may create security risks. Assessment Brief CMP-L021 (PG) … The higher-level reporting component requires students to document significant vulnerabilities using the conventions of a professional penetration-test report. This includes assigning CVSS scores, relating identified weaknesses to the OWASP Top 10 and NIST classifications, and supporting findings with appropriate technical evidence. Assessment Brief CMP-L021 (PG) … Students must also produce an executive summary for a non-technical audience, considering security, privacy, regulatory exposure and budget implications. A vulnerability table linking technical weaknesses with relevant regulatory concerns is also required. Overall, the assessment integrates technical penetration testing with risk communication, vulnerability classification, evidence collection and professional security reporting. Assessment Brief CMP-L021 (PG) … Overview word count: approximately 320 words. AI-use note: AI can be used in this assessment, but any use must be acknowledged and AI-generated outputs must be appropriately cited. Assessment Brief CMP-L021 (PG) …

Read Model Answer →
Cyber Security / Ethical Hacking / Penetration Testing 4,000 words

Ethical Hacking and Penetration Testing: Vulnerability Exploitation, Privilege Escalation and Mitigation

This Ethical Hacking and Penetration Testing coursework requires students to conduct a practical CTF-style penetration test against a set of authorised target machines and produce a professional technical report documenting the compromise of one selected target. The assessment evaluates practical exploitation skills alongside the ability to analyse risk, explain attack vectors and recommend effective security controls. 8598ba8d8fff5a38af8d427a4ce8f84… The practical element requires students to identify vulnerabilities in multiple target systems, exploit those weaknesses to gain low-privileged access and then perform privilege escalation to obtain root-level access. Successful completion of each stage produces flags, with separate user and root flags contributing directly to the practical marks. Brief descriptions of the attack vectors and payloads used must also be recorded. 8598ba8d8fff5a38af8d427a4ce8f84… The written report focuses in detail on one compromised machine. Students must explain the reconnaissance and vulnerability-identification process, including the techniques used to discover services, web content and potential attack surfaces. The marking criteria specifically recognise appropriate reconnaissance tools such as Nmap and FFUF and reward clear justification of methods and links between reconnaissance results and identified threats. 8598ba8d8fff5a38af8d427a4ce8f84… 8598ba8d8fff5a38af8d427a4ce8f84… A further component requires a formal risk rating for the discovered vulnerabilities. Students should use a recognised risk-classification approach, such as OWASP or SANS, justify the assigned severity and discuss relevant social, legal and ethical considerations. Higher-performing work is expected to connect those considerations directly to the specific vulnerabilities identified. 8598ba8d8fff5a38af8d427a4ce8f84… The exploit section should explain the technical cause of the vulnerability, describe the exploitation process and present relevant example payloads. Mitigation recommendations must then be linked directly to the vulnerabilities discovered, with clear explanations of where the weakness occurs and how it can be remediated. 8598ba8d8fff5a38af8d427a4ce8f84… Overall, the coursework integrates reconnaissance, vulnerability analysis, exploitation, privilege escalation, risk assessment, ethical and legal considerations, technical reporting and defensive mitigation within an authorised penetration-testing environment. Important: this brief states that it is for Coventry University Group students' own use and must not be passed to third parties or posted publicly. 8598ba8d8fff5a38af8d427a4ce8f84… So for your public Reference Library, use an original summary like the one above rather than uploading the assessment brief itself.

Read Model Answer →
1,500 words

Network Security Evaluation and Monitoring – Reconnaissance, Incident Response and APTs

This coursework assesses the research and analytical abilities required to design and evaluate an effective network security evaluation and monitoring solution. The scenario places the student in the role of a network security evaluation specialist responsible for helping a client design and build a monitoring solution for a complex client network. The client operates in the defence and security sector, works with government departments, multinational organisations and foreign agencies, and handles sensitive information. The network includes several server farms, gateway nodes, hundreds of client nodes, internal application services, externally accessible services and wireless access points. The organisation is considered vulnerable to threats such as sabotage and intellectual property theft. The coursework requires all questions to be answered in the given order within a single report. An abstract is not required, and students are expected to use technical terminology precisely. Relevant and clearly labelled illustrations are encouraged. Where assumptions are required about security software, hardware or services already deployed on the network, these assumptions must be clearly identified in a dedicated “Assumptions” section at the beginning of the report. Question 1 focuses on detecting network reconnaissance originating from inside the organisation. Students must explain how an insider could collect and use reconnaissance information for malicious purposes, identify the types of data that should be collected and the appropriate network locations for collection, and justify the selection of monitoring data. The question also requires recommendations for suitable tools and configurations to detect reconnaissance activity, together with strategies for dealing with the scale and high traffic volume of the client network. This section carries 30 marks and has a suggested length of 500 words. Question 2 focuses on incident response following a confirmed security incident. The scenario involves suspicious out-of-hours activity and an external flash drive connected to a workstation at gateway 10, a large number of files being opened on a file server at gateway 9, and significant traffic between the workstation and a database server at gateway 5. Students must determine which previously collected data would be relevant, explain the evidence expected from that data, and recommend additional network and endpoint data that should be collected. The proposed approach must be forensically sound so that evidence can potentially be used in court. This section carries 50 marks and has a suggested length of 700 words. Question 3 addresses Advanced Persistent Threats (APTs) and evaluates the effectiveness of the proposed monitoring solution. Students must recommend appropriate testing to determine whether the monitoring system operates according to its specifications and objectives, explain the types, timing and location of testing, and identify suitable qualifications, certifications, knowledge and tool experience for security testers. The section also requires discussion of APT behaviour and how the proposed monitoring mechanisms could detect or prevent such activity. This section carries 20 marks and has a suggested length of 300 words. Overall, the coursework develops skills in network security monitoring, reconnaissance detection, incident response, digital forensics, security testing and APT detection. It requires students to connect technical monitoring strategies with practical security, legal and operational considerations within a complex organisational network environment.

Read Model Answer →
Ethical Hacking 2,500 words

Ethical Hacking – Professional Penetration Testing Report

This resit coursework for the Ethical Hacking module at Coventry University requires students to conduct a professional penetration testing examination of a small office environment represented by a number of virtual machines. The purpose of the assessment is to evaluate the security of the target environment, identify vulnerabilities, demonstrate appropriate exploitation techniques within the authorised assessment environment, and produce professional recommendations for improving the security of the systems. The assignment carries 15 credits and requires a report of approximately 2,000 words, with a permitted variation of ±10%. The report should follow a structured penetration-testing approach. The first section covers reconnaissance and target analysis, requiring students to investigate the target environment and identify its structure, services and potential attack surfaces. The marking criteria emphasise the use of appropriate tools to identify network structure and services and the identification of vulnerabilities during the scanning process. Students are expected to analyse the results rather than simply reproduce the output of scanning tools. The second section focuses on exploitation. Students must describe in detail the steps taken and the tools used to exploit relevant vulnerabilities identified during the assessment. The marking criteria distinguish between compromising the desktop and gaining access to the server, with higher achievement involving multiple relevant vulnerabilities and successful access through more than one vulnerability. The report should provide appropriate screenshots and sample sessions to support the findings. The third section addresses post-exploitation activities. Students are required to document and analyse activities carried out after gaining access to the target systems. Examples identified in the marking criteria include dumping password hashes and creating a persistent backdoor. For server assessment, the criteria also consider activities such as obtaining root access or establishing a persistent connection. The report should explain the significance of the activities rather than merely listing technical actions. The fourth section provides recommendations for securing the target machines. Recommendations must address all vulnerabilities identified during the assessment, not only vulnerabilities that were successfully exploited. Security issues should be discussed using an established risk-rating approach such as OWASP, and proposed countermeasures should be relevant to the specific vulnerabilities discovered. The report should also analyse how vulnerabilities relate to one another and fit within the wider security context. The final section presents the conclusions, including an evaluation of the penetration-testing work and alternative approaches that could have been taken. The overall learning outcomes require students to critically discuss the legal, technical and ethical scope of ethical hacking, evaluate penetration-testing methodologies and security assessment tools, analyse vulnerabilities, and professionally report penetration-test outcomes with suitable countermeasures.

Read Model Answer →
Cyber Security / Penetration Testing 2,400 words

Grey-Box Penetration Testing: Vulnerability Assessment, Exploitation and Mitigation

This technical cyber-security project presents an authorised grey-box penetration test conducted within a controlled virtual laboratory environment. The objective is to assess the security posture of a deliberately vulnerable target system, identify weaknesses in exposed network services, demonstrate how those weaknesses could be exploited, evaluate their security and organisational impact, and recommend appropriate mitigation measures. The assessment follows a practical penetration-testing workflow supported by technical evidence, screenshots, activity records and academic research. The project begins with laboratory configuration, network discovery, service enumeration and vulnerability analysis. Tools including Kali Linux, Metasploitable, VMware, Nmap, Netcat and Metasploit are used across the testing lifecycle. Identified services are mapped to known vulnerabilities before controlled exploitation is undertaken and the resulting access is documented. The activity log records the progression from environment setup and network scanning through vulnerability identification, exploitation, evidence collection and final reporting. Five principal attack vectors are examined. These include the vsftpd 2.3.4 FTP backdoor, Samba username-map-script exploitation, an UnrealIRCd backdoor, insecure Java Remote Method Invocation and a misconfigured DistCC service. The practical demonstrations show how vulnerable or incorrectly configured services can permit unauthorised command execution and, in several cases, privileged shell access. For each vulnerability, the report explains the weakness, exploitation process, observed result, security impact and proposed mitigation. Recommended controls include patching or upgrading obsolete services, disabling unnecessary services, implementing firewall restrictions, strengthening authentication and input validation, restricting access to authorised systems, applying least privilege and monitoring suspicious activity. The project also incorporates group management and reflective practice. Team members perform specialised roles covering laboratory configuration, reconnaissance, vulnerability analysis, exploitation and documentation. Individual reflection considers technical performance, teamwork, evidence management and future skills development, demonstrating how structured collaboration contributes to an effective penetration-testing engagement. Important: unlike the earlier assignment briefs, these uploads appear to be completed student/project materials rather than the official 7COM1068 assessment brief. Therefore I would not invent the university, academic level or academic year. If you upload the actual 7COM1068 assignment guideline, I can fill those fields exactly.

Read Model Answer →