CSEC3616Cybersecurity Engineering

    Assignment 1: what it tests

    A revision map for Assignment 1: the administrative facts and which lecture topics each question draws on. No answers, no methods.

    • Know the weighting, dates and submission format for Assignment 1.
    • Find the topic pages that cover the material each question is drawn from.

    5 min read

    This page is a map, not an answer key. It tells you which lecture topics each question draws on, and where to go and revise them. It does not work through any part of the assignment.

    The facts

    Assignment 1 is worth 10% of the final course mark and covers Weeks 1–3.

    Dates:

    • Due: Week 5, Sunday 6 September 2026, 11:59pm
    • Informal extension: up to 5 days late with no penalty and no request needed, until Friday 11 September 2026, 23:59
    • Answer release: 14 September 2026, 00:00. Any submission after that receives zero marks regardless of special consideration.

    Submission: two separate Canvas links, a typeset PDF report (handwritten answers score zero) and a ZIP of your code. The report must include instructions for running the code, and must not repeat the question text.

    Questions and where they come from

    Q1a: Definitions (5 marks)

    What this question tests: Week 1–2, fundamental definitions and distinctions in security engineering.

    Revise: What security engineering is.

    Q1b: Conceptual framework (10 marks)

    What this question tests: Week 1–2, conceptual framework components (assets, threats, vulnerabilities, countermeasures).

    Revise: Policy, mechanism, assurance, incentives.

    Q1c: Security goals (10 marks)

    What this question tests: Week 2–3, security goals and threat identification in real-world incidents.

    Revise: Security goals.

    Q2: Social engineering in practice (25 marks)

    What this question tests: Week 1–3, social engineering reconnaissance, password guessing, and cryptographic hashing (MD5).

    Revise: Password usability and outdated advice and Password strength and generation.

    Q3a: Access control basics (7 marks)

    What this question tests: Week 3, access control models (the DAC vs MAC spectrum).

    Revise: Discretionary and mandatory access control.

    Q3b: Security policy models (18 marks)

    What this question tests: Week 3, the Bell-LaPadula model and the Biba model, and clearance-level deduction from simulator output.

    Revise: Bell-LaPadula, Biba and MLS.

    Q4: Linux access control (25 marks)

    What this question tests: Week 3, Linux users, groups and sudo, file permissions, directory permissions and the sticky bit.

    Revise: Unix and Linux permissions.

    Pitfall

    This site does not answer assessed work. Nothing on this page, or anywhere else on this site, walks through a method, a command, or a worked example for any part of Assignment 1. Work from the topic pages linked above and from the lecture material itself.