Filter by keyword, subject, or both. Updates live as new model answers are added to our portal.
Security of Connected Systems
4,500 words
CW: Security Evaluation
This assignment is an individual technical report focused on the security evaluation and strategic development of a rapidly expanding Internet of Things (IoT) systems developer based in Coventry. The client specialises in innovative IoT devices and systems for residential and commercial applications, particularly smart energy monitoring, and is planning to scale its operations and expand into new markets. The report is designed to provide practical and strategic guidance on how the organisation can achieve this growth while maintaining strong cybersecurity. The assignment requires students to act as an external IoT Security and Scaling Strategist and critically evaluate the organisation’s current and future security needs. The report covers four principal areas: organisational change strategy, secure design and development strategy, security audit strategy, and security recommendations. The organisational change section considers internal and external factors influencing growth, the development and implementation of an organisational strategy, monitoring against objectives, and approaches to leading and managing strategic change using relevant change management theories and models. The secure design and development section requires an overview and evaluation of possible secure design processes for IoT systems, including their strengths and weaknesses, followed by a recommendation for an appropriate process. The security audit section examines methods such as PTES and OWASP and develops a guide for conducting a security audit, including the testing methodology, rationale for each stage, and evaluation of different approaches. The security recommendations section requires a case study of an IoT security vulnerability, examination of where the security flaw was introduced, assessment of weaknesses in the secure design or audit process, consideration of the resulting security impact, and recommendations for improvement. The report should be written for a technical audience, particularly the client’s software development team, and should use appropriate structure, technical language, diagrams where useful, and APA referencing. The organisational strategy and strategic change proposal should be included in appendices and referenced within the main report. The assessment is worth 30 credits and has a maximum word count of 4,500 words, with the main sections weighted across organisational change, secure design, security auditing, security recommendations, and report structure.
Read Model Answer →
Cyber Security / Internet of Things / Connected Systems
4,500 words
Security Evaluation for Connected Systems: IoT Strategy, Secure Design, Security Auditing and Organisational Change
This Security of Connected Systems assessment requires students to act as an external IoT Security and Scaling Strategist for a rapidly expanding Coventry-based technology startup specialising in connected devices and smart energy-monitoring systems. The client intends to scale its operations and enter new markets and therefore requires both organisational-change guidance and a comprehensive evaluation of its cybersecurity posture. 38f2fba9a933f212c9e46e8cc591cf2… The report combines business strategy with technical cybersecurity analysis. Students must review different secure design and development methodologies, compare their strengths and weaknesses, and recommend an appropriate approach for integrating security into the client's IoT software-development lifecycle. 38f2fba9a933f212c9e46e8cc591cf2… 38f2fba9a933f212c9e46e8cc591cf2… A major component of the assessment focuses on organisational change strategy. Students examine the internal and external factors driving organisational growth, develop a comprehensive strategy for achieving the client's business objectives, and explain how that strategy should be implemented and monitored. The report must also critically evaluate relevant change-management theories and models and address the complexities of leading and managing strategic transformation. This section carries 35% of the marks and is allocated approximately 2,000 words. 38f2fba9a933f212c9e46e8cc591cf2… The Security Audit Strategy section requires students to design a guide for auditing the client's connected system. Different approaches, including methodologies such as PTES and OWASP, should be compared and evaluated. Students must explain each stage of the selected testing methodology and justify why the individual steps are required. 38f2fba9a933f212c9e46e8cc591cf2… The final technical component applies these principles to an IoT vulnerability case study. Students research a real vulnerability in an IoT device, explain where the security flaw was introduced, identify weaknesses in the secure-design or audit process, assess the resulting security impact and propose appropriate corrective actions. 38f2fba9a933f212c9e46e8cc591cf2… Overall, the coursework integrates IoT cybersecurity, secure software development, security auditing, vulnerability analysis, organisational strategy and strategic change management. The marking scheme allocates 35% to organisational-change strategy, 20% each to secure design and development, security auditing and security recommendations, and 5% to report structure. 38f2fba9a933f212c9e46e8cc591cf2… Important: the brief states that it is for Coventry University Group students' own use and must not be passed to third parties or posted on a website. 38f2fba9a933f212c9e46e8cc591cf2… So use an original public summary like the one above, but do not upload the original brief itself.
Read Model Answer →
Cyber Security / Applied Cryptography / Secure Systems Design
2,500 words
Secure Property Contract Exchange: Cryptographic Protocol Design, Threat Modelling and Post-Quantum Readiness
This Applied Theory of Cyber Security and Secure Design coursework places students in the role of a cyber security consultant engaged by Hackit & Run LLP, a legal firm specialising in UK and international property transactions. The firm wishes to implement a secure digital system for handling, exchanging and legally signing property contracts. Students must design and evaluate a secure communication protocol supporting interactions between the buyer’s solicitor, the seller’s solicitor and the buyer while addressing both first-time communications and previously established secure relationships. 11b17febb9eeb4570f76f6ca95a831a… Section A – Cryptographic Protocol Design, worth 45%, requires a complete secure communication protocol. Students must explain how trust is initially established, how later communications can be simplified without weakening confidentiality, integrity or availability, and how the buyer can digitally sign a contract in a manner enforceable under UK law. The design must justify specific cryptographic algorithms for functions such as key exchange, bulk encryption, digital signatures and hashing. The protocol must be presented through both a sequence diagram showing message flows and cryptographic operations and pseudocode explaining the key algorithmic stages. 11b17febb9eeb4570f76f6ca95a831a… Section B – Threat Modelling, worth 20%, requires a focused analysis using the STRIDE methodology. Students identify three realistic threats from different STRIDE categories and analyse the attack vector, asset at risk and potential effect on the legal transaction. Each threat must then be connected back to specific protocol defences, with residual risks acknowledged where controls cannot provide complete mitigation. The guidance encourages consideration of issues such as social engineering, insider threats, key-management failures and availability risks in addition to purely cryptographic attacks. 11b17febb9eeb4570f76f6ca95a831a… Section C – Security Evaluation Against Standards, worth 15%, requires students to evaluate the proposed system against a recognised cybersecurity standard or framework. Options include ISO/IEC 27001:2022, Common Criteria (ISO/IEC 15408) and the OWASP Application Security Verification Standard. Students select three or four directly relevant controls or requirements, assess whether the proposed design satisfies them, identify gaps and recommend specific improvements. 11b17febb9eeb4570f76f6ca95a831a… Section D – Post-Quantum Readiness and Critical Reflection, worth 15%, examines how a future quantum-capable adversary could affect the protocol. Students identify vulnerable cryptographic components, discuss the NIST Post-Quantum Cryptography standardisation programme, and examine replacement algorithms such as ML-KEM for key establishment and ML-DSA for digital signatures. They must also evaluate a hybrid migration strategy combining classical and post-quantum algorithms, considering performance overhead, backward compatibility and the legal admissibility of post-quantum digital signatures. 11b17febb9eeb4570f76f6ca95a831a… The remaining 5% evaluates professional report quality, logical structure, technical language, integration of diagrams and consistent CUHarvard referencing. Higher-quality work is expected to demonstrate a sophisticated trust model, clear traceability between threats and controls, precise standards mapping, practical security recommendations and well-evidenced analysis of post-quantum migration. 11b17febb9eeb4570f76f6ca95a831a… Important for the public Reference Library: the brief states that the assessment document is intended only for Coventry University Group students and must not be passed to third parties or posted on any website. Therefore, publish only an original high-level description such as the overview above; do not upload or reproduce the original assignment brief publicly. 11b17febb9eeb4570f76f6ca95a831a…
Read Model Answer →
Networking and Security Practice
Networking and Security Practice – Recorded Demonstration
This assessment for the MSc Cyber Security module Networking and Security Practice is a practical recorded-demonstration coursework designed to assess students' ability to configure, secure, troubleshoot and monitor a virtualised sandbox network. The assessment contributes 60% of the module mark and consists of four recorded demonstration videos, with each video limited to a maximum of five minutes. The completed videos are submitted through a Moodle quiz as video files or accessible links. The practical environment uses virtual machines running Ubuntu Server and Ubuntu Desktop on VirtualBox or UTM. Students deploy a four-machine architecture consisting of a Gateway, Webserver, Workstation and Zabbix-Server. The Gateway acts as the router, firewall and NAT gateway; the Webserver hosts an Nginx web server; the Workstation is used for administration and testing; and the Zabbix-Server provides network monitoring. The architecture requires appropriate network interfaces, IP addresses, routing and communication between the different internal networks. The coursework develops practical networking and system administration skills through several phases. Students install and configure operating systems, allocate virtual machine resources, configure static IP addresses, enable IP forwarding and NAT masquerading, and implement firewall rules using iptables. They also develop command-line proficiency using networking, DNS, security, remote-access and web tools including ping, traceroute, ss, nslookup, dig, nmap, Wireshark, netcat, SSH, SCP, rsync, curl and wget. Students must also configure secure remote access and deploy an Nginx web server. SSH must be hardened by disabling password authentication and root login, while key-based authentication is used for secure access. The Webserver must contain a customised landing page showing the student's name and student ID, which is accessed from the Workstation. The monitoring component requires installation and configuration of Zabbix, deployment of agents across the virtual machines, host monitoring, a customised dashboard containing at least five live-data widgets and configured alerts or triggers. Students must explain what their selected monitoring elements measure and why they are operationally useful. The traffic-analysis component uses Wireshark to capture and examine HTTP, ICMP and DNS traffic. Students apply appropriate filters, identify protocols using the Protocol Hierarchy and discuss the security implications of unencrypted HTTP traffic, including secure alternatives such as HTTPS and DNS over TLS. The security-evaluation component uses Nmap within the isolated virtualised sandbox to identify open ports and services, assess vulnerabilities and recommend mitigations. Students must also demonstrate iptables forwarding and NAT masquerading rules. The four videos cover Network Infrastructure, Network Monitoring, Traffic Analysis and Security Evaluation. The assessment is marked out of 100, with 35 marks allocated to Network Infrastructure, 25 to Network Monitoring, 20 to Traffic Analysis and 20 to Security Evaluation. Students are expected to provide clear voice narration, explain commands and outputs, demonstrate technical understanding and critically relate their work to network security. The assessment develops employability skills in Linux administration, remote system management, network troubleshooting, security hardening, packet analysis, port and service scanning, virtualisation and network monitoring. It also requires students to conduct security testing ethically within their own isolated virtualised environment and prohibits unauthorised scanning of university networks, public websites or other systems.
Read Model Answer →
Security of Emerging Connected Systems
2,000 words
Security Evaluation – Secure Design, Security Audit and IoT Security Recommendations
This individual coursework for the Security of Emerging Connected Systems module requires students to prepare a 2,000-word technical report evaluating secure design, security auditing and security recommendations for an organisation developing Internet of Things (IoT) devices and systems for home and workplace environments. The assessment is worth 10 credits and requires students to provide practical and evidence-based guidance to the client’s software development team. The report is assessed across secure design and development methodology, security audit methodology, security recommendations and overall report structure. The first major section addresses Secure Design and Development Methodology. The client wants to incorporate secure design principles into its software development workflow and therefore requires an overview of possible secure design processes relevant to IoT. Students must evaluate the strengths and weaknesses of different approaches and provide a justified recommendation for a process that would be appropriate for the client. The emphasis is on integrating security into the design and development of systems rather than treating security as a separate activity after development. The second section focuses on Security Audit Methodology. The client wants to complement its secure design process with a security audit of the final developed system. Students must provide a practical guide explaining how a security audit could be performed, including the overall testing methodology and the purpose of each stage. The brief identifies methodologies such as PTES and OWASP as examples. Students are also expected to discuss different approaches and evaluate their respective strengths and weaknesses. The third section concerns Security Recommendations and requires students to demonstrate the implications of strong secure design and auditing through an IoT security case study. Students must research a security vulnerability affecting an IoT device, explain the vulnerability and identify where the security flaw was introduced. The report must then examine which parts of the secure design and audit processes were not implemented correctly and evaluate the resulting impact on the security of the product. The report is intended for a technical audience, specifically the client's software development team. Students are expected to use an appropriate technical structure and language, support their arguments and analysis with references, and use APA referencing. The assessment also encourages appropriate diagrams to support the written content. The report structure component accounts for 10% of the assessment, while Secure Design and Development Methodology, Security Audit Methodology and Security Recommendations each account for 30%. The coursework assesses learning outcomes relating to defence-in-depth solutions for technical internet security vulnerabilities, secure private networks for IoT and BYOD, and current research and technological advances in network security. These outcomes connect the assignment to practical IoT security engineering, secure development, security auditing and emerging network-security practices.
Read Model Answer →
1,500 words
Network Security Evaluation and Monitoring – Reconnaissance, Incident Response and APTs
This coursework assesses the research and analytical abilities required to design and evaluate an effective network security evaluation and monitoring solution. The scenario places the student in the role of a network security evaluation specialist responsible for helping a client design and build a monitoring solution for a complex client network. The client operates in the defence and security sector, works with government departments, multinational organisations and foreign agencies, and handles sensitive information. The network includes several server farms, gateway nodes, hundreds of client nodes, internal application services, externally accessible services and wireless access points. The organisation is considered vulnerable to threats such as sabotage and intellectual property theft. The coursework requires all questions to be answered in the given order within a single report. An abstract is not required, and students are expected to use technical terminology precisely. Relevant and clearly labelled illustrations are encouraged. Where assumptions are required about security software, hardware or services already deployed on the network, these assumptions must be clearly identified in a dedicated “Assumptions” section at the beginning of the report. Question 1 focuses on detecting network reconnaissance originating from inside the organisation. Students must explain how an insider could collect and use reconnaissance information for malicious purposes, identify the types of data that should be collected and the appropriate network locations for collection, and justify the selection of monitoring data. The question also requires recommendations for suitable tools and configurations to detect reconnaissance activity, together with strategies for dealing with the scale and high traffic volume of the client network. This section carries 30 marks and has a suggested length of 500 words. Question 2 focuses on incident response following a confirmed security incident. The scenario involves suspicious out-of-hours activity and an external flash drive connected to a workstation at gateway 10, a large number of files being opened on a file server at gateway 9, and significant traffic between the workstation and a database server at gateway 5. Students must determine which previously collected data would be relevant, explain the evidence expected from that data, and recommend additional network and endpoint data that should be collected. The proposed approach must be forensically sound so that evidence can potentially be used in court. This section carries 50 marks and has a suggested length of 700 words. Question 3 addresses Advanced Persistent Threats (APTs) and evaluates the effectiveness of the proposed monitoring solution. Students must recommend appropriate testing to determine whether the monitoring system operates according to its specifications and objectives, explain the types, timing and location of testing, and identify suitable qualifications, certifications, knowledge and tool experience for security testers. The section also requires discussion of APT behaviour and how the proposed monitoring mechanisms could detect or prevent such activity. This section carries 20 marks and has a suggested length of 300 words. Overall, the coursework develops skills in network security monitoring, reconnaissance detection, incident response, digital forensics, security testing and APT detection. It requires students to connect technical monitoring strategies with practical security, legal and operational considerations within a complex organisational network environment.
Read Model Answer →