The aim of this assignment is to demonstrate your understanding of the theory presented in lectures and the practical exercises conducted in workshops about using containers for the development and deployment of software projects, as well as secure development, common vulnerabilities, software testing and code review.
This assignment has three main tasks:
The first task is about building images and running the whole project using docker-compose and Kubernetes.
The second task requires you to perform automated security testing and vulnerability analysis on the project.
The third task requires you to discuss the concepts and skills you have learned and how you apply them in your future career.
Each team should have 4 students.
If you cannot meet this requirement due to special reasons, you must contact the course convenors for approval.
Teams will manage the project together, and complete 1 team planning and 2 peer review activities.
Each member must contribute to all tasks. Workload should be evenly distributed; individual marking applies for significant discrepancies. Non-contributing members receive 0 marks.
Due date: 29th August, 23:59
What to submit:
One project management form including all planned milestones with due dates and work allocation (can be revised later).
Due date: 12th September, 23:59
What to submit:
Updated project management form including milestone reviews and optional revisions
Zipped file containing all source files you created/adapted (excluding GitHub files)
Technical report (PDF) per team including:
Student numbers and names, peer review scores (out of 10)
Project number selected, e.g., Project 0
Description of what you have done and the results (with screenshots)
Due date: 10th October, 23:59
What to submit:
Updated project management form including milestone reviews
Technical report (PDF) per team including:
Student numbers and names, peer review scores (out of 10)
Project number selected, e.g., Project 0
Description of what you have done and the results (with screenshots)
List of references with proper formatting
5-minute video from each team member explaining vulnerabilities and individual contributions. Options:
Upload to online repository (e.g., OneDrive) and give access
Submit one zipped file (max 500 MB)
Record one 20-minute Teams meeting with all members
Note: Video is supplementary; technical report should contain all information for marking
Use AWS VM with Docker CLI (not GUI Docker Manager)
Create docker images and containers to run full-stack project including at least four containers:
Front-end Web application
Back-end database
Graphical interface for back-end database (e.g., Mongo Express)
Nginx proxy for secure HTTPS connections
Create docker-compose.yml with:
Clearly defined internal Docker networks
Exposed ports and volumes
Environment variable configuration
Demonstrate containers working together during lab:
Logs showing containers running and database connected
Web interface accessed via correct HTTPS URL and port
Mongo Express interface accessed via correct URL and port
Adding/updating data from Mongo Express works correctly
Adding/updating data from Web interface and verifying it
Excellent mark:
Create Kubernetes cluster with Minikube (1 node) automating project services
Cluster contains at least four containers with internal and external services and exposed ports
Use ZAP project for automated/manual testing
Identify 4 vulnerabilities, each from a different class with a unique CWE code
Report each vulnerability with:
Name & CWE Code
Detection method(s)
Description: examples, exploitation, impact
Justification: verification, code source, supporting data
Remediation: recommendations or project-specific fixes
Video: Briefly justify CWE classification and explain remediation
Reflect on concepts and skills learned and their future career application (e.g., system/network administration, software development, cybersecurity)
Include:
Self-learning resources used (with citations, e.g., forums, articles, videos, ChatGPT prompts)
How you supported team members and managed teamwork
Reflection should focus on learning experience and outcomes, not general discussion
The 2808ICT – Secure Development Operations Assignment is designed to evaluate both theoretical understanding and practical skills in secure software development, containerization, and vulnerability management. The assignment consists of three main tasks:
Task 1: Build and Run Project with Containers and Kubernetes (30 Marks)
Develop Docker images and containers for a full-stack project (frontend, backend database, Mongo Express, Nginx).
Demonstrate container interoperability, data handling, and HTTPS access.
Optional: Deploy using Kubernetes (Minikube) with internal/external services.
Task 2: Security Testing and Vulnerability Analysis (38 Marks)
Conduct automated and/or manual testing using OWASP ZAP.
Identify at least 4 vulnerabilities from different CWE classes.
Report vulnerabilities with name, CWE code, detection method, impact, verification, and remediation.
Submit a short video explaining CWE classification and remediation.
Task 3: Reflect on Learning and Teamwork (12 Marks)
Reflect on concepts, skills, and career relevance (system/network admin, software dev, cybersecurity).
Discuss team contributions, resource usage, and learning outcomes.
Teamwork and Submission Details:
Teams of 4 students, manage planning, peer reviews, and equal workload.
Submission Deadlines:
Team Plan: 29th August
Task 1: 12th September
Tasks 2 & 3: 10th October
Required deliverables: project management form, zipped source files, technical report, references, and supplementary videos.
The academic mentor guided the student systematically to ensure understanding, practical execution, and learning outcomes:
Understanding Assessment Objectives
Reviewed assignment brief with the student to clarify expectations, marking criteria, and deadlines.
Highlighted key tools: Docker, Docker Compose, Kubernetes, OWASP ZAP, and reporting formats.
Task 1: Containerization and Kubernetes Deployment
Planning Phase: Mentor helped students define milestones in the project management form.
Practical Guidance:
Demonstrated Docker CLI commands for building images, running containers, and checking logs.
Explained network configurations, port exposure, and environment variable setup.
Guided creation of docker-compose.yml with 4 containers and inter-container communication.
Assisted with optional Kubernetes deployment using Minikube, mapping services to nodes and exposing ports.
Verification: Students tested the application via HTTPS and Mongo Express, confirming data integrity and connectivity.
Task 2: Security Testing and Vulnerability Analysis
Tool Introduction: Mentor introduced OWASP ZAP for automated and manual testing.
Vulnerability Identification: Students learned to classify vulnerabilities with CWE codes.
Reporting Guidance: Mentor instructed students to include:
Vulnerability name and CWE code
Detection methods (manual/automated)
Impact and exploitation examples
Verification and evidence (screenshots, logs)
Remediation recommendations
Video Preparation: Students recorded short videos explaining classification and remediation, ensuring clarity and individual contribution.
Task 3: Reflection and Teamwork
Reflection Structuring: Mentor guided students to focus on practical learning outcomes rather than general discussion.
Team Collaboration: Demonstrated effective documentation of peer contributions, problem-solving strategies, and resource usage.
Career Relevance: Students were encouraged to connect learned skills to future roles in software development, system/network administration, and cybersecurity.
Outcome Achieved:
Successfully built and deployed a multi-container full-stack application using Docker and optionally Kubernetes.
Conducted comprehensive security testing and vulnerability analysis, producing detailed technical reports and CWE-based remediation.
Documented teamwork contributions, reflected on learning outcomes, and demonstrated professional reporting skills.
Learning Objectives Covered:
Practical containerization using Docker and Kubernetes.
Automated and manual security testing techniques.
Vulnerability analysis and remediation with CWE standards.
Effective teamwork, planning, and peer review in project development.
Documentation and reporting for technical and academic purposes.
Reflection on skill application in future professional contexts.
Looking for guidance on your assignment? You can download our sample solution to see how a high-quality submission is structured, learn the concepts, and understand the step-by-step approach. Remember: The sample is for reference only. Submitting it as your own work may lead to plagiarism issues.
Want a fully custom, plagiarism-free solution? Our team of professional academic writers can craft a fresh assignment tailored to your requirements, ensuring originality, accuracy, and clarity. Ordering a custom solution helps you:
Save time while understanding key concepts
Receive a solution that meets academic standards
Avoid plagiarism risks with 100% unique content
Get professional formatting and referencing
Take action now and secure the support you need:
Download Sample Solution Order Fresh Assignment
© Copyright 2026 My Uni Papers – Student Hustle Made Hassle Free. All rights reserved.