Filter by keyword, subject, or both. Updates live as new model answers are added to our portal.
Cyber Security / Ethical Hacking / Penetration Testing
4,000 words
Ethical Hacking and Penetration Testing: Vulnerability Exploitation, Privilege Escalation and Mitigation
This Ethical Hacking and Penetration Testing coursework requires students to conduct a practical CTF-style penetration test against a set of authorised target machines and produce a professional technical report documenting the compromise of one selected target. The assessment evaluates practical exploitation skills alongside the ability to analyse risk, explain attack vectors and recommend effective security controls. 8598ba8d8fff5a38af8d427a4ce8f84… The practical element requires students to identify vulnerabilities in multiple target systems, exploit those weaknesses to gain low-privileged access and then perform privilege escalation to obtain root-level access. Successful completion of each stage produces flags, with separate user and root flags contributing directly to the practical marks. Brief descriptions of the attack vectors and payloads used must also be recorded. 8598ba8d8fff5a38af8d427a4ce8f84… The written report focuses in detail on one compromised machine. Students must explain the reconnaissance and vulnerability-identification process, including the techniques used to discover services, web content and potential attack surfaces. The marking criteria specifically recognise appropriate reconnaissance tools such as Nmap and FFUF and reward clear justification of methods and links between reconnaissance results and identified threats. 8598ba8d8fff5a38af8d427a4ce8f84… 8598ba8d8fff5a38af8d427a4ce8f84… A further component requires a formal risk rating for the discovered vulnerabilities. Students should use a recognised risk-classification approach, such as OWASP or SANS, justify the assigned severity and discuss relevant social, legal and ethical considerations. Higher-performing work is expected to connect those considerations directly to the specific vulnerabilities identified. 8598ba8d8fff5a38af8d427a4ce8f84… The exploit section should explain the technical cause of the vulnerability, describe the exploitation process and present relevant example payloads. Mitigation recommendations must then be linked directly to the vulnerabilities discovered, with clear explanations of where the weakness occurs and how it can be remediated. 8598ba8d8fff5a38af8d427a4ce8f84… Overall, the coursework integrates reconnaissance, vulnerability analysis, exploitation, privilege escalation, risk assessment, ethical and legal considerations, technical reporting and defensive mitigation within an authorised penetration-testing environment. Important: this brief states that it is for Coventry University Group students' own use and must not be passed to third parties or posted publicly. 8598ba8d8fff5a38af8d427a4ce8f84… So for your public Reference Library, use an original summary like the one above rather than uploading the assessment brief itself.
Read Model Answer →
Cyber Security
Contextual Risk Assessment and Policy to Address Information Security within Supplier Agreements
This assignment focuses on the development of a contextual risk assessment and an information security policy addressing security requirements within supplier agreements for Heathrow Airport Holdings (LHR). The assessment is an individual postgraduate task worth 60% of the module and requires students to apply information security risk assessment methods, security standards and policy development techniques to a realistic organisational scenario. The assignment is based on a cyber-attack affecting Heathrow and other European airports in September 2025, where disruption to a third-party cloud-based check-in and baggage system affected airport and airline operations. The scenario highlights the security risks associated with interconnected systems, third-party suppliers and dependence on critical digital services. Students are required to assume the role of a new Chief Information Security Officer (CISO) at Heathrow Airport Holdings and investigate the organisation, its environment and the relevant threat landscape. The task requires the development of a clear organisational context, including appropriate assumptions, followed by an asset-based information security risk assessment. The risk assessment should identify and prioritise relevant risks and support the selection of controls needed to manage residual information security risks. The main policy component requires students to develop an “Information Security within Supplier Agreements” policy aligned with the ISO 27000 family. The policy should establish clear security responsibilities between LHR and its suppliers and address the protection of information assets, legal and regulatory requirements, and supplier-related security obligations. Particular attention is required for confidentiality, integrity and availability, together with ISO 27002 controls relating to information security policies and supplier agreements. The assignment also requires consideration of acceptable use of information and other assets, information classification and information labelling. The final submission consists of a cover page, context establishment, an asset-based risk assessment, the supplier information security policy, references and supporting appendices. The context establishment is limited to a maximum of two pages or 1,000 words, while the policy is limited to three pages or 1,500 words. The risk assessment is completed using the supplied template. Students are also required to provide evidence and commentary concerning the development and tailoring of the policy when using an approved AI tool, together with a self-written evaluation addressing strengths, weaknesses, privacy, GDPR and ethical considerations. The assessment is marked across context establishment, asset-based risk assessment, the information security within supplier agreements policy, and presentation, design and references. At least 20 authentic references, including standards and papers accessed through the University library, are required.
Read Model Answer →
Digital Security Risk and Audit
2,000 words
Digital Security Risk and Audit – Information Security Audit of ABC Air
This individual coursework for the Digital Security Risk and Audit module requires students to prepare a 2,000-word information security audit report based on a case study involving ABC Air, a small aircraft service company responsible for aircraft maintenance for civil operators. The company records information including aircraft flying hours, servicing time, engineers' man-hours and related maintenance activities. An external contractor has also provided a report outlining a possible solution for ABC Air. Students are required to assess the information security risks associated with the scenario, complete an information security audit and produce a professional report, clearly identifying any assumptions made during the analysis. The assessment requires students to examine risk assessment, identification and analysis as part of the audit process. A suitable auditing approach must be selected and justified, with students considering either a general risk-based approach or a specific control-based approach. The report should explain why the selected approach is appropriate for the ABC Air scenario and demonstrate how it can be applied to the organisation's information security environment. The coursework also requires consideration of potential cyber attacks and their use within an integrated fault event analysis. Students must identify relevant information security threats and examine how an attack could affect the organisation and its information assets. The report should further identify appropriate standards, best practices or guidelines that could be used to mitigate information security breaches. These should be critically evaluated, including discussion of their advantages and disadvantages rather than simply being listed. The assessment develops students' ability to apply information security governance and audit practices within legal, ethical and professional contexts. It also requires consideration of recognised industry frameworks such as COBIT and international standards including the ISO 27000 series. Students are expected to perform systematic risk assessment and analysis, critically evaluate information assurance reference models, and select appropriate information security audit strategies for complex real-world scenarios. The marking criteria place particular emphasis on the quality of the information security audit, identification and adoption of appropriate international standards and frameworks, and critical evaluation of the benefits and limitations of security audit frameworks. The assessment allocates 20% to identifying and applying an appropriate audit approach, 50% to completing the conceptual information security audit and assurance, and 30% to interpreting and critically evaluating information assurance reference models. The report is an individual assessment and must be submitted as a PDF through Aula/Turnitin. The brief states that APA referencing should be used for the work and that all sources and any AI tools used must be acknowledged.
Read Model Answer →
Digital Forensics / Cybersecurity
2,000 words
AI-Augmented Digital Forensics Workflow Audit: Feasibility and Risk Assessment of ForensiScan AI
This digital forensics assessment examines the feasibility, reliability and legal risks associated with introducing AI-assisted analysis into a conventional forensic investigation workflow. Students act as a Lead Forensic Consultant assessing a proposed black-box system called ForensiScan AI, which claims to automatically classify illicit images and identify suspicious intent within encrypted messaging applications using Large Language Models. The central objective is to determine whether the efficiency benefits of AI can be achieved without compromising evidential integrity, transparency or legal defensibility. The report maps the proposed AI system across the four stages of the NIST forensic process: Collection, Examination, Analysis and Reporting. For each phase, students identify the data entering and leaving the AI system and determine whether the technology should be used for preliminary triage or as part of final forensic analysis. A major component concerns verification and validation. Because AI systems may hallucinate or misclassify evidence, students must design a ground-truth protocol involving human verification, statistical sampling and known datasets. The assessment also investigates whether AI-generated results can be reproduced reliably when identical evidence is processed again. The report further addresses chain of custody and data integrity, particularly whether AI processing could alter timestamps, metadata or other forensic artefacts. Ethical and legal analysis covers potential model bias, language and contextual limitations, and whether AI-generated outputs could satisfy the requirements of the Daubert Test for expert evidence. Overall, the assessment combines digital-forensic architecture, AI governance, evidential integrity, model validation, legal admissibility and professional accountability. The grading criteria place particular emphasis on forensic soundness, protection against evidence alteration, critical analysis of AI limitations such as hallucination and non-determinism, and professional technical communication. Overview word count: approximately 340 words. AI-use note: the brief permits AI only for limited assistance such as brainstorming risks, structural feedback and grammar refinement. It explicitly prohibits full report generation, unverified forensic claims and using AI to substitute for the student's own final recommendation or verification protocol. Any AI use requires an appendix containing the tool, exact prompts and a human verification log.
Read Model Answer →