Network Security and Incident Report
1,500 words
Network Security and Incident Report – Megadodo Publications
This 1,500-word individual coursework for the Network Security and Incident Report module examines the network infrastructure and security challenges of Megadodo Publications, a company located near Warwick that has expanded into two buildings, Ursa Major Alpha and Ursa Minor Beta. Despite investment in new networking equipment, the organisation is experiencing poor network performance and repeated security incidents involving the leakage of sensitive information into the public domain. The situation is particularly urgent because the company is negotiating an important government contract. The student is placed in the role of a network security professional asked to investigate the existing environment and provide recommendations for improving its infrastructure and security. The case study provides a network topology, addressing scheme, equipment information and an existing security policy. The network connects departments across the two buildings and includes servers, management systems, sales, marketing, legal, finance, software development, product testing, administration, IT support, Wi-Fi and a rented floor occupied by a separate start-up company. The addressing scheme identifies separate subnets for several organisational functions, while the topology includes multiple switches, routers, servers and wireless access points. The report requires students to make reasonable assumptions where information is incomplete and document those assumptions at the beginning of the report. The first substantive task evaluates how the organisation's network performance could be improved. Recommendations should address the existing infrastructure and, where the design is changed, include an appropriate network diagram using tools such as Packet Tracer or other suitable applications. The second major area addresses amendments to the existing security policy. Students should recommend improvements to the current policy rather than create a completely new policy. The report must also discuss how appropriate security measures could be implemented across the network and its devices. Detailed device configurations are not required, although relevant examples or configuration snippets are encouraged. The final section requires a summary of the key findings and recommendations, together with a proposal for how the organisation could use its remaining IT support budget of approximately £8,000 and identify areas for future investment. The assessment is divided into introduction, assumptions and requirements, improving performance, policy amendments, security and devices, summary and budget, and references. The marking scheme allocates 50% of the module mark to this coursework, with the individual report submitted as a single DOC, DOCX or PDF document.
Read Model Answer →
Ethical Hacking
2,500 words
Ethical Hacking – Professional Penetration Testing Report
This resit coursework for the Ethical Hacking module at Coventry University requires students to conduct a professional penetration testing examination of a small office environment represented by a number of virtual machines. The purpose of the assessment is to evaluate the security of the target environment, identify vulnerabilities, demonstrate appropriate exploitation techniques within the authorised assessment environment, and produce professional recommendations for improving the security of the systems. The assignment carries 15 credits and requires a report of approximately 2,000 words, with a permitted variation of ±10%. The report should follow a structured penetration-testing approach. The first section covers reconnaissance and target analysis, requiring students to investigate the target environment and identify its structure, services and potential attack surfaces. The marking criteria emphasise the use of appropriate tools to identify network structure and services and the identification of vulnerabilities during the scanning process. Students are expected to analyse the results rather than simply reproduce the output of scanning tools. The second section focuses on exploitation. Students must describe in detail the steps taken and the tools used to exploit relevant vulnerabilities identified during the assessment. The marking criteria distinguish between compromising the desktop and gaining access to the server, with higher achievement involving multiple relevant vulnerabilities and successful access through more than one vulnerability. The report should provide appropriate screenshots and sample sessions to support the findings. The third section addresses post-exploitation activities. Students are required to document and analyse activities carried out after gaining access to the target systems. Examples identified in the marking criteria include dumping password hashes and creating a persistent backdoor. For server assessment, the criteria also consider activities such as obtaining root access or establishing a persistent connection. The report should explain the significance of the activities rather than merely listing technical actions. The fourth section provides recommendations for securing the target machines. Recommendations must address all vulnerabilities identified during the assessment, not only vulnerabilities that were successfully exploited. Security issues should be discussed using an established risk-rating approach such as OWASP, and proposed countermeasures should be relevant to the specific vulnerabilities discovered. The report should also analyse how vulnerabilities relate to one another and fit within the wider security context. The final section presents the conclusions, including an evaluation of the penetration-testing work and alternative approaches that could have been taken. The overall learning outcomes require students to critically discuss the legal, technical and ethical scope of ethical hacking, evaluate penetration-testing methodologies and security assessment tools, analyse vulnerabilities, and professionally report penetration-test outcomes with suitable countermeasures.
Read Model Answer →