Filter by keyword, subject, or both. Updates live as new model answers are added to our portal.
Security of Connected Systems
4,500 words
CW: Security Evaluation
This assignment is an individual technical report focused on the security evaluation and strategic development of a rapidly expanding Internet of Things (IoT) systems developer based in Coventry. The client specialises in innovative IoT devices and systems for residential and commercial applications, particularly smart energy monitoring, and is planning to scale its operations and expand into new markets. The report is designed to provide practical and strategic guidance on how the organisation can achieve this growth while maintaining strong cybersecurity. The assignment requires students to act as an external IoT Security and Scaling Strategist and critically evaluate the organisation’s current and future security needs. The report covers four principal areas: organisational change strategy, secure design and development strategy, security audit strategy, and security recommendations. The organisational change section considers internal and external factors influencing growth, the development and implementation of an organisational strategy, monitoring against objectives, and approaches to leading and managing strategic change using relevant change management theories and models. The secure design and development section requires an overview and evaluation of possible secure design processes for IoT systems, including their strengths and weaknesses, followed by a recommendation for an appropriate process. The security audit section examines methods such as PTES and OWASP and develops a guide for conducting a security audit, including the testing methodology, rationale for each stage, and evaluation of different approaches. The security recommendations section requires a case study of an IoT security vulnerability, examination of where the security flaw was introduced, assessment of weaknesses in the secure design or audit process, consideration of the resulting security impact, and recommendations for improvement. The report should be written for a technical audience, particularly the client’s software development team, and should use appropriate structure, technical language, diagrams where useful, and APA referencing. The organisational strategy and strategic change proposal should be included in appendices and referenced within the main report. The assessment is worth 30 credits and has a maximum word count of 4,500 words, with the main sections weighted across organisational change, secure design, security auditing, security recommendations, and report structure.
Read Model Answer →
Cyber Security / Penetration Testing
Web Application Penetration Testing and Security Vulnerability Assessment Portfolio
This postgraduate cyber security portfolio requires students to conduct a structured penetration test of a controlled web application and document the technical findings in a professional security-testing format. The assessment develops practical competence in identifying, validating and communicating security vulnerabilities while maintaining appropriate legal, ethical and professional boundaries. Assessment Brief CMP-L021 (PG) … Students begin by performing network and service enumeration, identifying open ports and the services running on the target host. They are expected to interpret the security implications of the findings and provide appropriate recommendations to a hypothetical client. The assessment then progresses into web-application vulnerability testing using tools such as a web browser, Burp Suite Community, Nmap and student-developed scripts. Assessment Brief CMP-L021 (PG) … A major part of the portfolio examines common web-security weaknesses including SQL Injection and Cross-Site Scripting. Students must demonstrate how they tested the application, capture relevant requests and responses, and explain the evidence supporting their conclusions. Additional tasks involve application and server reconnaissance, including identification of technologies, server versions, publicly exposed files and other information that may create security risks. Assessment Brief CMP-L021 (PG) … The higher-level reporting component requires students to document significant vulnerabilities using the conventions of a professional penetration-test report. This includes assigning CVSS scores, relating identified weaknesses to the OWASP Top 10 and NIST classifications, and supporting findings with appropriate technical evidence. Assessment Brief CMP-L021 (PG) … Students must also produce an executive summary for a non-technical audience, considering security, privacy, regulatory exposure and budget implications. A vulnerability table linking technical weaknesses with relevant regulatory concerns is also required. Overall, the assessment integrates technical penetration testing with risk communication, vulnerability classification, evidence collection and professional security reporting. Assessment Brief CMP-L021 (PG) … Overview word count: approximately 320 words. AI-use note: AI can be used in this assessment, but any use must be acknowledged and AI-generated outputs must be appropriately cited. Assessment Brief CMP-L021 (PG) …
Read Model Answer →
Operating Systems and Networks
2,000 words
Security of Operating Systems and Networks – Individual Assignment
This individual assignment focuses on the security of operating systems and computer networks. Students are required to produce a professional technical report of approximately 2,000 words demonstrating a deep and systematic understanding of operating-system security, networking functions, security threats, vulnerabilities and practical security testing. The assessment carries 50% and forms 100% of the module assessment. Students are expected to support their work with appropriate technical evidence, images showing practical steps and relevant sources. The assignment uses a business scenario involving Net-Tech, a small and medium-sized technology-services enterprise. The organisation is concerned about the security of its proposed system, including operating-system attacks such as buffer overflow and network threats such as hacking and phishing. Students are required to investigate, design and experiment with the features and functions of a web server used to serve the company's website, while assessing the security landscape and presenting findings that can support appropriate organisational security decisions. As part of the practical work, students must create a prototype Net-Tech network test rig. This includes creating two users, with one configured as a superuser and another as a standard user, applying appropriate baseline security measures, installing suitable software and identifying vulnerabilities, using appropriate tools to conduct security tests, and writing scripts to automate repetitive tasks. Students must document assumptions and parameters used within the project, including further security implementations and recommendations such as the use of a suitable database for a database-driven website. The report is structured around introduction, background research, pre-engagement, engagement and post-engagement activities. The introduction should explain the business scenario, assumptions, aims, objectives, deliverables, available skills and resources, constraints and project plan. The background research should address common vulnerabilities, threats, risk models, security-testing approaches, relevant attack and testing tools, legal and organisational requirements, and ethical, social, professional and sustainability considerations. The pre-engagement section covers the test-rig setup and testing strategy. The engagement section requires practical comparison and demonstration of operating-system and network security, including user authentication, file and directory permissions, protection against stack-overflow attacks, network weaknesses, operating-system discovery, firewalls, listening ports, network statistics, prevention of denial-of-service attacks and scripting for automation. The post-engagement section requires a summary of the work, deductions and limitations, mitigation measures and recommendations, and personal reflection. The assessment requires students to use relevant sources, provide a bibliography and demonstrate appropriate analysis, evaluation and reflection. The assignment is designed to assess learning outcomes relating to knowledge of network security threats and the development of complex software and scripts relevant to operating systems and computer networks.
Read Model Answer →
Networking and Security Practice
Networking and Security Practice – Recorded Demonstration
This assessment for the MSc Cyber Security module Networking and Security Practice is a practical recorded-demonstration coursework designed to assess students' ability to configure, secure, troubleshoot and monitor a virtualised sandbox network. The assessment contributes 60% of the module mark and consists of four recorded demonstration videos, with each video limited to a maximum of five minutes. The completed videos are submitted through a Moodle quiz as video files or accessible links. The practical environment uses virtual machines running Ubuntu Server and Ubuntu Desktop on VirtualBox or UTM. Students deploy a four-machine architecture consisting of a Gateway, Webserver, Workstation and Zabbix-Server. The Gateway acts as the router, firewall and NAT gateway; the Webserver hosts an Nginx web server; the Workstation is used for administration and testing; and the Zabbix-Server provides network monitoring. The architecture requires appropriate network interfaces, IP addresses, routing and communication between the different internal networks. The coursework develops practical networking and system administration skills through several phases. Students install and configure operating systems, allocate virtual machine resources, configure static IP addresses, enable IP forwarding and NAT masquerading, and implement firewall rules using iptables. They also develop command-line proficiency using networking, DNS, security, remote-access and web tools including ping, traceroute, ss, nslookup, dig, nmap, Wireshark, netcat, SSH, SCP, rsync, curl and wget. Students must also configure secure remote access and deploy an Nginx web server. SSH must be hardened by disabling password authentication and root login, while key-based authentication is used for secure access. The Webserver must contain a customised landing page showing the student's name and student ID, which is accessed from the Workstation. The monitoring component requires installation and configuration of Zabbix, deployment of agents across the virtual machines, host monitoring, a customised dashboard containing at least five live-data widgets and configured alerts or triggers. Students must explain what their selected monitoring elements measure and why they are operationally useful. The traffic-analysis component uses Wireshark to capture and examine HTTP, ICMP and DNS traffic. Students apply appropriate filters, identify protocols using the Protocol Hierarchy and discuss the security implications of unencrypted HTTP traffic, including secure alternatives such as HTTPS and DNS over TLS. The security-evaluation component uses Nmap within the isolated virtualised sandbox to identify open ports and services, assess vulnerabilities and recommend mitigations. Students must also demonstrate iptables forwarding and NAT masquerading rules. The four videos cover Network Infrastructure, Network Monitoring, Traffic Analysis and Security Evaluation. The assessment is marked out of 100, with 35 marks allocated to Network Infrastructure, 25 to Network Monitoring, 20 to Traffic Analysis and 20 to Security Evaluation. Students are expected to provide clear voice narration, explain commands and outputs, demonstrate technical understanding and critically relate their work to network security. The assessment develops employability skills in Linux administration, remote system management, network troubleshooting, security hardening, packet analysis, port and service scanning, virtualisation and network monitoring. It also requires students to conduct security testing ethically within their own isolated virtualised environment and prohibits unauthorised scanning of university networks, public websites or other systems.
Read Model Answer →
Security of Emerging Connected Systems
2,000 words
Security Evaluation – Secure Design, Security Audit and IoT Security Recommendations
This individual coursework for the Security of Emerging Connected Systems module requires students to prepare a 2,000-word technical report evaluating secure design, security auditing and security recommendations for an organisation developing Internet of Things (IoT) devices and systems for home and workplace environments. The assessment is worth 10 credits and requires students to provide practical and evidence-based guidance to the client’s software development team. The report is assessed across secure design and development methodology, security audit methodology, security recommendations and overall report structure. The first major section addresses Secure Design and Development Methodology. The client wants to incorporate secure design principles into its software development workflow and therefore requires an overview of possible secure design processes relevant to IoT. Students must evaluate the strengths and weaknesses of different approaches and provide a justified recommendation for a process that would be appropriate for the client. The emphasis is on integrating security into the design and development of systems rather than treating security as a separate activity after development. The second section focuses on Security Audit Methodology. The client wants to complement its secure design process with a security audit of the final developed system. Students must provide a practical guide explaining how a security audit could be performed, including the overall testing methodology and the purpose of each stage. The brief identifies methodologies such as PTES and OWASP as examples. Students are also expected to discuss different approaches and evaluate their respective strengths and weaknesses. The third section concerns Security Recommendations and requires students to demonstrate the implications of strong secure design and auditing through an IoT security case study. Students must research a security vulnerability affecting an IoT device, explain the vulnerability and identify where the security flaw was introduced. The report must then examine which parts of the secure design and audit processes were not implemented correctly and evaluate the resulting impact on the security of the product. The report is intended for a technical audience, specifically the client's software development team. Students are expected to use an appropriate technical structure and language, support their arguments and analysis with references, and use APA referencing. The assessment also encourages appropriate diagrams to support the written content. The report structure component accounts for 10% of the assessment, while Secure Design and Development Methodology, Security Audit Methodology and Security Recommendations each account for 30%. The coursework assesses learning outcomes relating to defence-in-depth solutions for technical internet security vulnerabilities, secure private networks for IoT and BYOD, and current research and technological advances in network security. These outcomes connect the assignment to practical IoT security engineering, secure development, security auditing and emerging network-security practices.
Read Model Answer →
1,500 words
Network Security Evaluation and Monitoring – Reconnaissance, Incident Response and APTs
This coursework assesses the research and analytical abilities required to design and evaluate an effective network security evaluation and monitoring solution. The scenario places the student in the role of a network security evaluation specialist responsible for helping a client design and build a monitoring solution for a complex client network. The client operates in the defence and security sector, works with government departments, multinational organisations and foreign agencies, and handles sensitive information. The network includes several server farms, gateway nodes, hundreds of client nodes, internal application services, externally accessible services and wireless access points. The organisation is considered vulnerable to threats such as sabotage and intellectual property theft. The coursework requires all questions to be answered in the given order within a single report. An abstract is not required, and students are expected to use technical terminology precisely. Relevant and clearly labelled illustrations are encouraged. Where assumptions are required about security software, hardware or services already deployed on the network, these assumptions must be clearly identified in a dedicated “Assumptions” section at the beginning of the report. Question 1 focuses on detecting network reconnaissance originating from inside the organisation. Students must explain how an insider could collect and use reconnaissance information for malicious purposes, identify the types of data that should be collected and the appropriate network locations for collection, and justify the selection of monitoring data. The question also requires recommendations for suitable tools and configurations to detect reconnaissance activity, together with strategies for dealing with the scale and high traffic volume of the client network. This section carries 30 marks and has a suggested length of 500 words. Question 2 focuses on incident response following a confirmed security incident. The scenario involves suspicious out-of-hours activity and an external flash drive connected to a workstation at gateway 10, a large number of files being opened on a file server at gateway 9, and significant traffic between the workstation and a database server at gateway 5. Students must determine which previously collected data would be relevant, explain the evidence expected from that data, and recommend additional network and endpoint data that should be collected. The proposed approach must be forensically sound so that evidence can potentially be used in court. This section carries 50 marks and has a suggested length of 700 words. Question 3 addresses Advanced Persistent Threats (APTs) and evaluates the effectiveness of the proposed monitoring solution. Students must recommend appropriate testing to determine whether the monitoring system operates according to its specifications and objectives, explain the types, timing and location of testing, and identify suitable qualifications, certifications, knowledge and tool experience for security testers. The section also requires discussion of APT behaviour and how the proposed monitoring mechanisms could detect or prevent such activity. This section carries 20 marks and has a suggested length of 300 words. Overall, the coursework develops skills in network security monitoring, reconnaissance detection, incident response, digital forensics, security testing and APT detection. It requires students to connect technical monitoring strategies with practical security, legal and operational considerations within a complex organisational network environment.
Read Model Answer →
Secure Design and Development
2,000 words
Secure Design and Development – PixelForge Nexus (UITS)
This assessment for Coventry University’s Secure Design and Development module requires students to design and develop a functional secure online system with the aid of a Large Language Model (LLM). The assignment is based on a practical scenario involving Creative SkillZ LLC and its proposed “PixelForge Nexus” system. The submission combines a functional prototype, an individual 2,000-word report, source code hosted in the Coventry University GitHub environment, and a video report demonstrating the completed prototype. The PixelForge Nexus prototype is intended to provide secure project management and basic asset and resource management for a game-development environment. Core functionality includes adding and removing projects, viewing active projects, assigning developers to projects, allowing developers to view their assigned projects, uploading project documents, and allowing authorised users to access documents associated with their projects. The system must implement privilege separation between Admin, Project Lead and Developer roles. Security is a central requirement of the assignment. Administrators are responsible for managing projects and user accounts, Project Leads can assign developers and upload project documents, while Developers can view assigned projects and associated documents. The system must include a robust login mechanism with secure password hashing and storage, with Multi-Factor Authentication recommended as an additional security measure. Proposed pages include Sign In/Register, a role-based User Dashboard, Account Settings and a Project Details page. The practical assessment evaluates four major areas: System Design, Security Testing and Analysis, System Development, and Formal Methods. System design requires consideration of secure design principles and their application to the development lifecycle. Security testing requires critical evaluation of security techniques, identification of issues and proposed mitigation measures. System development requires a functional prototype that follows the proposed design and considers legal and ethical requirements. Formal methods require a behavioural model and appropriate verification techniques to establish whether the system meets its specification. The individual report must document the methods and techniques used to develop the prototype and discuss the stages of the development lifecycle, including specification, design and development. It must also explain the deployment and testing approach, limitations of the prototype, possible improvements, security techniques and the formal model used. The submission must include links to the Coventry University GitHub repository and Microsoft OneDrive video, while the required appendix contains the LLM prompt history and other resources used with APA-style referencing.
Read Model Answer →