Filter by keyword, subject, or both. Updates live as new model answers are added to our portal.
Cyber Security / Internet of Things / Connected Systems
4,500 words
Security Evaluation for Connected Systems: IoT Strategy, Secure Design, Security Auditing and Organisational Change
This Security of Connected Systems assessment requires students to act as an external IoT Security and Scaling Strategist for a rapidly expanding Coventry-based technology startup specialising in connected devices and smart energy-monitoring systems. The client intends to scale its operations and enter new markets and therefore requires both organisational-change guidance and a comprehensive evaluation of its cybersecurity posture. 38f2fba9a933f212c9e46e8cc591cf2… The report combines business strategy with technical cybersecurity analysis. Students must review different secure design and development methodologies, compare their strengths and weaknesses, and recommend an appropriate approach for integrating security into the client's IoT software-development lifecycle. 38f2fba9a933f212c9e46e8cc591cf2… 38f2fba9a933f212c9e46e8cc591cf2… A major component of the assessment focuses on organisational change strategy. Students examine the internal and external factors driving organisational growth, develop a comprehensive strategy for achieving the client's business objectives, and explain how that strategy should be implemented and monitored. The report must also critically evaluate relevant change-management theories and models and address the complexities of leading and managing strategic transformation. This section carries 35% of the marks and is allocated approximately 2,000 words. 38f2fba9a933f212c9e46e8cc591cf2… The Security Audit Strategy section requires students to design a guide for auditing the client's connected system. Different approaches, including methodologies such as PTES and OWASP, should be compared and evaluated. Students must explain each stage of the selected testing methodology and justify why the individual steps are required. 38f2fba9a933f212c9e46e8cc591cf2… The final technical component applies these principles to an IoT vulnerability case study. Students research a real vulnerability in an IoT device, explain where the security flaw was introduced, identify weaknesses in the secure-design or audit process, assess the resulting security impact and propose appropriate corrective actions. 38f2fba9a933f212c9e46e8cc591cf2… Overall, the coursework integrates IoT cybersecurity, secure software development, security auditing, vulnerability analysis, organisational strategy and strategic change management. The marking scheme allocates 35% to organisational-change strategy, 20% each to secure design and development, security auditing and security recommendations, and 5% to report structure. 38f2fba9a933f212c9e46e8cc591cf2… Important: the brief states that it is for Coventry University Group students' own use and must not be passed to third parties or posted on a website. 38f2fba9a933f212c9e46e8cc591cf2… So use an original public summary like the one above, but do not upload the original brief itself.
Read Model Answer →
Cyber Security / Penetration Testing
Web Application Penetration Testing and Security Vulnerability Assessment Portfolio
This postgraduate cyber security portfolio requires students to conduct a structured penetration test of a controlled web application and document the technical findings in a professional security-testing format. The assessment develops practical competence in identifying, validating and communicating security vulnerabilities while maintaining appropriate legal, ethical and professional boundaries. Assessment Brief CMP-L021 (PG) … Students begin by performing network and service enumeration, identifying open ports and the services running on the target host. They are expected to interpret the security implications of the findings and provide appropriate recommendations to a hypothetical client. The assessment then progresses into web-application vulnerability testing using tools such as a web browser, Burp Suite Community, Nmap and student-developed scripts. Assessment Brief CMP-L021 (PG) … A major part of the portfolio examines common web-security weaknesses including SQL Injection and Cross-Site Scripting. Students must demonstrate how they tested the application, capture relevant requests and responses, and explain the evidence supporting their conclusions. Additional tasks involve application and server reconnaissance, including identification of technologies, server versions, publicly exposed files and other information that may create security risks. Assessment Brief CMP-L021 (PG) … The higher-level reporting component requires students to document significant vulnerabilities using the conventions of a professional penetration-test report. This includes assigning CVSS scores, relating identified weaknesses to the OWASP Top 10 and NIST classifications, and supporting findings with appropriate technical evidence. Assessment Brief CMP-L021 (PG) … Students must also produce an executive summary for a non-technical audience, considering security, privacy, regulatory exposure and budget implications. A vulnerability table linking technical weaknesses with relevant regulatory concerns is also required. Overall, the assessment integrates technical penetration testing with risk communication, vulnerability classification, evidence collection and professional security reporting. Assessment Brief CMP-L021 (PG) … Overview word count: approximately 320 words. AI-use note: AI can be used in this assessment, but any use must be acknowledged and AI-generated outputs must be appropriately cited. Assessment Brief CMP-L021 (PG) …
Read Model Answer →
Cyber Security / Ethical Hacking / Penetration Testing
4,000 words
Ethical Hacking and Penetration Testing: Vulnerability Exploitation, Privilege Escalation and Mitigation
This Ethical Hacking and Penetration Testing coursework requires students to conduct a practical CTF-style penetration test against a set of authorised target machines and produce a professional technical report documenting the compromise of one selected target. The assessment evaluates practical exploitation skills alongside the ability to analyse risk, explain attack vectors and recommend effective security controls. 8598ba8d8fff5a38af8d427a4ce8f84… The practical element requires students to identify vulnerabilities in multiple target systems, exploit those weaknesses to gain low-privileged access and then perform privilege escalation to obtain root-level access. Successful completion of each stage produces flags, with separate user and root flags contributing directly to the practical marks. Brief descriptions of the attack vectors and payloads used must also be recorded. 8598ba8d8fff5a38af8d427a4ce8f84… The written report focuses in detail on one compromised machine. Students must explain the reconnaissance and vulnerability-identification process, including the techniques used to discover services, web content and potential attack surfaces. The marking criteria specifically recognise appropriate reconnaissance tools such as Nmap and FFUF and reward clear justification of methods and links between reconnaissance results and identified threats. 8598ba8d8fff5a38af8d427a4ce8f84… 8598ba8d8fff5a38af8d427a4ce8f84… A further component requires a formal risk rating for the discovered vulnerabilities. Students should use a recognised risk-classification approach, such as OWASP or SANS, justify the assigned severity and discuss relevant social, legal and ethical considerations. Higher-performing work is expected to connect those considerations directly to the specific vulnerabilities identified. 8598ba8d8fff5a38af8d427a4ce8f84… The exploit section should explain the technical cause of the vulnerability, describe the exploitation process and present relevant example payloads. Mitigation recommendations must then be linked directly to the vulnerabilities discovered, with clear explanations of where the weakness occurs and how it can be remediated. 8598ba8d8fff5a38af8d427a4ce8f84… Overall, the coursework integrates reconnaissance, vulnerability analysis, exploitation, privilege escalation, risk assessment, ethical and legal considerations, technical reporting and defensive mitigation within an authorised penetration-testing environment. Important: this brief states that it is for Coventry University Group students' own use and must not be passed to third parties or posted publicly. 8598ba8d8fff5a38af8d427a4ce8f84… So for your public Reference Library, use an original summary like the one above rather than uploading the assessment brief itself.
Read Model Answer →
Operating Systems and Networks
2,000 words
Security of Operating Systems and Networks – Individual Assignment
This individual assignment focuses on the security of operating systems and computer networks. Students are required to produce a professional technical report of approximately 2,000 words demonstrating a deep and systematic understanding of operating-system security, networking functions, security threats, vulnerabilities and practical security testing. The assessment carries 50% and forms 100% of the module assessment. Students are expected to support their work with appropriate technical evidence, images showing practical steps and relevant sources. The assignment uses a business scenario involving Net-Tech, a small and medium-sized technology-services enterprise. The organisation is concerned about the security of its proposed system, including operating-system attacks such as buffer overflow and network threats such as hacking and phishing. Students are required to investigate, design and experiment with the features and functions of a web server used to serve the company's website, while assessing the security landscape and presenting findings that can support appropriate organisational security decisions. As part of the practical work, students must create a prototype Net-Tech network test rig. This includes creating two users, with one configured as a superuser and another as a standard user, applying appropriate baseline security measures, installing suitable software and identifying vulnerabilities, using appropriate tools to conduct security tests, and writing scripts to automate repetitive tasks. Students must document assumptions and parameters used within the project, including further security implementations and recommendations such as the use of a suitable database for a database-driven website. The report is structured around introduction, background research, pre-engagement, engagement and post-engagement activities. The introduction should explain the business scenario, assumptions, aims, objectives, deliverables, available skills and resources, constraints and project plan. The background research should address common vulnerabilities, threats, risk models, security-testing approaches, relevant attack and testing tools, legal and organisational requirements, and ethical, social, professional and sustainability considerations. The pre-engagement section covers the test-rig setup and testing strategy. The engagement section requires practical comparison and demonstration of operating-system and network security, including user authentication, file and directory permissions, protection against stack-overflow attacks, network weaknesses, operating-system discovery, firewalls, listening ports, network statistics, prevention of denial-of-service attacks and scripting for automation. The post-engagement section requires a summary of the work, deductions and limitations, mitigation measures and recommendations, and personal reflection. The assessment requires students to use relevant sources, provide a bibliography and demonstrate appropriate analysis, evaluation and reflection. The assignment is designed to assess learning outcomes relating to knowledge of network security threats and the development of complex software and scripts relevant to operating systems and computer networks.
Read Model Answer →
Networking and Security Practice
Networking and Security Practice – Recorded Demonstration
This assessment for the MSc Cyber Security module Networking and Security Practice is a practical recorded-demonstration coursework designed to assess students' ability to configure, secure, troubleshoot and monitor a virtualised sandbox network. The assessment contributes 60% of the module mark and consists of four recorded demonstration videos, with each video limited to a maximum of five minutes. The completed videos are submitted through a Moodle quiz as video files or accessible links. The practical environment uses virtual machines running Ubuntu Server and Ubuntu Desktop on VirtualBox or UTM. Students deploy a four-machine architecture consisting of a Gateway, Webserver, Workstation and Zabbix-Server. The Gateway acts as the router, firewall and NAT gateway; the Webserver hosts an Nginx web server; the Workstation is used for administration and testing; and the Zabbix-Server provides network monitoring. The architecture requires appropriate network interfaces, IP addresses, routing and communication between the different internal networks. The coursework develops practical networking and system administration skills through several phases. Students install and configure operating systems, allocate virtual machine resources, configure static IP addresses, enable IP forwarding and NAT masquerading, and implement firewall rules using iptables. They also develop command-line proficiency using networking, DNS, security, remote-access and web tools including ping, traceroute, ss, nslookup, dig, nmap, Wireshark, netcat, SSH, SCP, rsync, curl and wget. Students must also configure secure remote access and deploy an Nginx web server. SSH must be hardened by disabling password authentication and root login, while key-based authentication is used for secure access. The Webserver must contain a customised landing page showing the student's name and student ID, which is accessed from the Workstation. The monitoring component requires installation and configuration of Zabbix, deployment of agents across the virtual machines, host monitoring, a customised dashboard containing at least five live-data widgets and configured alerts or triggers. Students must explain what their selected monitoring elements measure and why they are operationally useful. The traffic-analysis component uses Wireshark to capture and examine HTTP, ICMP and DNS traffic. Students apply appropriate filters, identify protocols using the Protocol Hierarchy and discuss the security implications of unencrypted HTTP traffic, including secure alternatives such as HTTPS and DNS over TLS. The security-evaluation component uses Nmap within the isolated virtualised sandbox to identify open ports and services, assess vulnerabilities and recommend mitigations. Students must also demonstrate iptables forwarding and NAT masquerading rules. The four videos cover Network Infrastructure, Network Monitoring, Traffic Analysis and Security Evaluation. The assessment is marked out of 100, with 35 marks allocated to Network Infrastructure, 25 to Network Monitoring, 20 to Traffic Analysis and 20 to Security Evaluation. Students are expected to provide clear voice narration, explain commands and outputs, demonstrate technical understanding and critically relate their work to network security. The assessment develops employability skills in Linux administration, remote system management, network troubleshooting, security hardening, packet analysis, port and service scanning, virtualisation and network monitoring. It also requires students to conduct security testing ethically within their own isolated virtualised environment and prohibits unauthorised scanning of university networks, public websites or other systems.
Read Model Answer →
Security of Emerging Connected Systems
2,000 words
Security Evaluation – Secure Design, Security Audit and IoT Security Recommendations
This individual coursework for the Security of Emerging Connected Systems module requires students to prepare a 2,000-word technical report evaluating secure design, security auditing and security recommendations for an organisation developing Internet of Things (IoT) devices and systems for home and workplace environments. The assessment is worth 10 credits and requires students to provide practical and evidence-based guidance to the client’s software development team. The report is assessed across secure design and development methodology, security audit methodology, security recommendations and overall report structure. The first major section addresses Secure Design and Development Methodology. The client wants to incorporate secure design principles into its software development workflow and therefore requires an overview of possible secure design processes relevant to IoT. Students must evaluate the strengths and weaknesses of different approaches and provide a justified recommendation for a process that would be appropriate for the client. The emphasis is on integrating security into the design and development of systems rather than treating security as a separate activity after development. The second section focuses on Security Audit Methodology. The client wants to complement its secure design process with a security audit of the final developed system. Students must provide a practical guide explaining how a security audit could be performed, including the overall testing methodology and the purpose of each stage. The brief identifies methodologies such as PTES and OWASP as examples. Students are also expected to discuss different approaches and evaluate their respective strengths and weaknesses. The third section concerns Security Recommendations and requires students to demonstrate the implications of strong secure design and auditing through an IoT security case study. Students must research a security vulnerability affecting an IoT device, explain the vulnerability and identify where the security flaw was introduced. The report must then examine which parts of the secure design and audit processes were not implemented correctly and evaluate the resulting impact on the security of the product. The report is intended for a technical audience, specifically the client's software development team. Students are expected to use an appropriate technical structure and language, support their arguments and analysis with references, and use APA referencing. The assessment also encourages appropriate diagrams to support the written content. The report structure component accounts for 10% of the assessment, while Secure Design and Development Methodology, Security Audit Methodology and Security Recommendations each account for 30%. The coursework assesses learning outcomes relating to defence-in-depth solutions for technical internet security vulnerabilities, secure private networks for IoT and BYOD, and current research and technological advances in network security. These outcomes connect the assignment to practical IoT security engineering, secure development, security auditing and emerging network-security practices.
Read Model Answer →
Ethical Hacking
2,500 words
Ethical Hacking – Professional Penetration Testing Report
This resit coursework for the Ethical Hacking module at Coventry University requires students to conduct a professional penetration testing examination of a small office environment represented by a number of virtual machines. The purpose of the assessment is to evaluate the security of the target environment, identify vulnerabilities, demonstrate appropriate exploitation techniques within the authorised assessment environment, and produce professional recommendations for improving the security of the systems. The assignment carries 15 credits and requires a report of approximately 2,000 words, with a permitted variation of ±10%. The report should follow a structured penetration-testing approach. The first section covers reconnaissance and target analysis, requiring students to investigate the target environment and identify its structure, services and potential attack surfaces. The marking criteria emphasise the use of appropriate tools to identify network structure and services and the identification of vulnerabilities during the scanning process. Students are expected to analyse the results rather than simply reproduce the output of scanning tools. The second section focuses on exploitation. Students must describe in detail the steps taken and the tools used to exploit relevant vulnerabilities identified during the assessment. The marking criteria distinguish between compromising the desktop and gaining access to the server, with higher achievement involving multiple relevant vulnerabilities and successful access through more than one vulnerability. The report should provide appropriate screenshots and sample sessions to support the findings. The third section addresses post-exploitation activities. Students are required to document and analyse activities carried out after gaining access to the target systems. Examples identified in the marking criteria include dumping password hashes and creating a persistent backdoor. For server assessment, the criteria also consider activities such as obtaining root access or establishing a persistent connection. The report should explain the significance of the activities rather than merely listing technical actions. The fourth section provides recommendations for securing the target machines. Recommendations must address all vulnerabilities identified during the assessment, not only vulnerabilities that were successfully exploited. Security issues should be discussed using an established risk-rating approach such as OWASP, and proposed countermeasures should be relevant to the specific vulnerabilities discovered. The report should also analyse how vulnerabilities relate to one another and fit within the wider security context. The final section presents the conclusions, including an evaluation of the penetration-testing work and alternative approaches that could have been taken. The overall learning outcomes require students to critically discuss the legal, technical and ethical scope of ethical hacking, evaluate penetration-testing methodologies and security assessment tools, analyse vulnerabilities, and professionally report penetration-test outcomes with suitable countermeasures.
Read Model Answer →
Network Systems and Administration
3,500 words
Network Systems and Administration – Linux System and Network Administration Portfolio
This assessment is an individual portfolio for the Network Systems and Administration unit. It consists of two quizzes and a report based on a case study involving the development, implementation, configuration, testing, maintenance, and evaluation of a network solution using an industry-standard network operating system. The report requires students to justify their design and implementation decisions, provide a detailed testing strategy, develop a maintenance and disaster recovery plan, and critically evaluate the completed solution. The case study concerns Piranha, a small organisation in which the business owner has been maintaining a server containing information relating to finance, management, production, and sales. The student is required to undertake the role of Network Systems Administrator and configure an appropriate Linux-based network environment. The practical work includes creating a new user account with root access, confirming root privileges, verifying access to company files, and configuring group-based access controls for finance, management, production, and sales directories. Students must then establish a client-server network by installing a Linux distribution on a separate virtual machine in VirtualBox. SSH connections are required to verify user access and the configured file permissions. The assessment also requires students to use Wireshark to observe network traffic during SSH sessions, report on packet types and encryption, identify potential security vulnerabilities, and recommend improvements such as SSH keys and unique passwords. A maintenance schedule and a brief disaster recovery or backup strategy must also be proposed. The final report must document the practical work with clear explanations and screenshots showing commands, user accounts, and results. The report should be between 1,500 and 3,500 words. The assessment also includes Linux Essentials and Networking Essentials final grades. The marking criteria cover system and network administration, the maintenance plan, reflection and report writing, screenshots, references, and Harvard referencing.
Read Model Answer →
Cyber Security / Cloud Management
2,500 words
Cyber Security and Cloud Defence Strategy for ShieldSafe Analytics
This Level 7 Cyber Security for Business and Cloud Management portfolio examines the security challenges faced by ShieldSafe Analytics Ltd., a multinational health analytics organisation specialising in AI-enabled diagnostics and telehealth. The organisation processes high volumes of sensitive patient information, including biometric and genomic data, across hybrid-cloud environments and IoT-enabled healthcare infrastructure. Following a suspected data-exfiltration incident involving anomalous traffic from a diagnostic platform connected to third-party cloud APIs, students are required to evaluate the organisation's information environment and develop appropriate cyber-security and cloud-defence strategies. The first task focuses on information environments and the weaponisation of information. Students identify critical elements of ShieldSafe's information environment, evaluate vulnerabilities associated with the data-exfiltration incident and examine how patient data or analytical systems could be manipulated by malicious actors. Relevant real-world healthcare cyber incidents should be used to support the analysis. The second task examines offensive and defensive Information Operations. Students analyse techniques used by nation-state actors and cybercriminal organisations, including healthcare ransomware incidents such as WannaCry, and compare offensive and defensive approaches. The analysis considers how ShieldSafe can balance these approaches while protecting sensitive data and preserving trust in AI-enabled diagnostic systems. The third task applies Information Operations within legal and ethical boundaries and requires development of a secure cloud migration strategy for ShieldSafe's legacy Electronic Health Record system. The supporting student guide specifically permits students to demonstrate an implementation using Amazon AWS, including IAM users and roles, VPC configuration, security groups, web servers, EC2 instances and AWS migration services. The final task requires a comprehensive cyber-defence strategy, including implementation of Zero Trust Architecture across cloud platforms and analysis of vulnerabilities affecting cyber-physical healthcare systems such as wearable medical devices and diagnostic equipment. Students must propose controls against both remote and local attacks. Overall, the portfolio integrates information operations, healthcare cybersecurity, hybrid-cloud protection, secure migration, Zero Trust, cyber-physical security and strategic cyber defence. The work is produced as a portfolio report using PebblePad and must use Harvard referencing throughout, with appropriate citation of academic sources, images, definitions and external arguments.
Read Model Answer →
Cyber Security / Penetration Testing
2,400 words
Grey-Box Penetration Testing: Vulnerability Assessment, Exploitation and Mitigation
This technical cyber-security project presents an authorised grey-box penetration test conducted within a controlled virtual laboratory environment. The objective is to assess the security posture of a deliberately vulnerable target system, identify weaknesses in exposed network services, demonstrate how those weaknesses could be exploited, evaluate their security and organisational impact, and recommend appropriate mitigation measures. The assessment follows a practical penetration-testing workflow supported by technical evidence, screenshots, activity records and academic research. The project begins with laboratory configuration, network discovery, service enumeration and vulnerability analysis. Tools including Kali Linux, Metasploitable, VMware, Nmap, Netcat and Metasploit are used across the testing lifecycle. Identified services are mapped to known vulnerabilities before controlled exploitation is undertaken and the resulting access is documented. The activity log records the progression from environment setup and network scanning through vulnerability identification, exploitation, evidence collection and final reporting. Five principal attack vectors are examined. These include the vsftpd 2.3.4 FTP backdoor, Samba username-map-script exploitation, an UnrealIRCd backdoor, insecure Java Remote Method Invocation and a misconfigured DistCC service. The practical demonstrations show how vulnerable or incorrectly configured services can permit unauthorised command execution and, in several cases, privileged shell access. For each vulnerability, the report explains the weakness, exploitation process, observed result, security impact and proposed mitigation. Recommended controls include patching or upgrading obsolete services, disabling unnecessary services, implementing firewall restrictions, strengthening authentication and input validation, restricting access to authorised systems, applying least privilege and monitoring suspicious activity. The project also incorporates group management and reflective practice. Team members perform specialised roles covering laboratory configuration, reconnaissance, vulnerability analysis, exploitation and documentation. Individual reflection considers technical performance, teamwork, evidence management and future skills development, demonstrating how structured collaboration contributes to an effective penetration-testing engagement. Important: unlike the earlier assignment briefs, these uploads appear to be completed student/project materials rather than the official 7COM1068 assessment brief. Therefore I would not invent the university, academic level or academic year. If you upload the actual 7COM1068 assignment guideline, I can fill those fields exactly.
Read Model Answer →
Cyber Security for Business and Cloud Management
This activity aims to assess your comprehension of the diverse concepts discussed in this module. You must use the frameworks and concepts covered in this module's delivery to respond to all the tasks below. Scenario ShieldSafe Analytics Ltd. is a fast-growing health analytics company specialising in AI-driven patient diagnostics and telehealth platforms. Operating across multiple countries, the company processes high volumes of real-time patient data, including biometric and genomic records. Due to the increased reliance on remote healthcare and IoT-enabled medical devices, their infrastructure has expanded into hybrid cloud environments. Recently, ShieldSafe experienced a suspected data exfiltration incident involving anomalous traffic from one of its diagnostic platforms integrated with third-party cloud APIs. As a result, executive leadership has raised concerns about the company’s vulnerability to adversarial information operations, particularly in relation to data manipulation, misinformation, and insider threats. As a Junior Cybersecurity Strategist, you’ve been recruited to support the lead cyber intelligence consultant in reviewing vulnerabilities within their information environment, exploring offensive and defensive Information Operations (IO) concepts, and crafting robust cyber defence mechanisms. The leadership also wants to migrate a legacy electronic health record (EHR) system used across its African operations to a more scalable and secure cloud infrastructure. However, concerns exist regarding cross-border data protection laws, insider threats, and the strategic use of information in potential cyber warfare scenarios.
Read Model Answer →
L7 Cyber Security for Business and Cloud Management
This activity aims to assess your comprehension of the diverse concepts discussed in this module. You must use the frameworks and concepts covered in this module's delivery to respond to all the tasks below. Scenario ShieldSafe Analytics Ltd. is a fast-growing health analytics company specialising in AI-driven patient diagnostics and telehealth platforms. Operating across multiple countries, the company processes high volumes of real-time patient data, including biometric and genomic records. Due to the increased reliance on remote healthcare and IoT-enabled medical devices, their infrastructure has expanded into hybrid cloud environments. Recently, ShieldSafe experienced a suspected data exfiltration incident involving anomalous traffic from one of its diagnostic platforms integrated with third-party cloud APIs. As a result, executive leadership has raised concerns about the company’s vulnerability to adversarial information operations, particularly in relation to data manipulation, misinformation, and insider threats. As a Junior Cybersecurity Strategist, you’ve been recruited to support the lead cyber intelligence consultant in reviewing vulnerabilities within their information environment, exploring offensive and defensive Information Operations (IO) concepts, and crafting robust cyber defence mechanisms. The leadership also wants to migrate a legacy electronic health record (EHR) system used across its African operations to a more scalable and secure cloud infrastructure. However, concerns exist regarding cross-border data protection laws, insider threats, and the strategic use of information in potential cyber warfare scenarios.
Read Model Answer →