SlideShare a Scribd company logo
1 of 7
erm Paper: Penetration Testing
Due Week 10 and worth 120 points
As a penetration tester, you are hired as a consultant by a small-
to mid-sized business that is interested in calculating its overall
security risk today, January 1, 2012. The business specializes in
providing private loans to college students. This business uses
both an e-Commerce site and point-of-sales devices (credit card
swipes) to collect payment. Also, there exist a number of file
transfer operations where sensitive and confidential data is
transferred to and from several external partnering companies.
The typical volume of payment transactions totals is
approximately $100 million. You decide that the risk
assessments are to take into account the entire network of
workstations, VoIP phone sets, servers, routers, switches and
other networking gear. During your interview with one of the
business’s IT staff members, you are told that many external
vendors want to sell security networking products and software
solutions. The staff member also claimed that their network was
too “flat.” During the initial onsite visit, you captured the
following pertinent data to use in creation of the Penetration
Test Plan.
Non-stateful packet firewall separates the business’s internal
network from its DMZ.
All departments--including Finance, Marketing, Development,
and IT--connect into the same enterprise switch and are
therefore on the same LAN. Senior management (CEO, CIO,
President, etc.) and the Help Desk are not on that LAN; they are
connected via a common Ethernet hub and then to the switched
LAN.
All of the workstations used by employees are either Windows
98 or Windows XP. None of the workstations have service
packs or updates beyond service pack one.
Two (2) Web servers containing customer portals for logging in
and ordering products exist on the DMZ running Windows 2000
Server SP1, and IIS v5.
One (1) internal server containing Active Directory (AD)
services to authenticate users, a DB where all data for the
company is stored (i.e. HR, financial, product design, customer,
transactions). The AD server is using LM instead of NTLM.
Write a six to eight (6-8) page paper in which you:
Explain the tests you would run and the reason(s) for running
them (e.g. to support the risk assessment plan).
Determine the expected results from tests and research based on
the specific informational details provided. (i.e., IIS v5,
Windows Server 2000, AD server not using NTLM)
Analyze the software tools you would use for your investigation
and reasons for choosing them.
Describe the legal requirements and ethical issues involved.
Using Visio or its open source alternative, provide a diagram of
how you would redesign this business’ network. Include a
description of your drawing.
Note
: The graphically depicted solution is not included in the
required page length.
Propose your final recommendations and reporting. Explain
what risks exist and ways to either eliminate or reduce the risk.
Use at least three (3) quality resources in this assignment.
Note:
Wikipedia and similar Websites do not qualify as quality
resources.
Your assignment must follow these formatting requirements:
Be typed, double spaced, using Times New Roman font (size
12), with one-inch margins on all sides; citations and references
must follow APA or school-specific format. Check with your
professor for any additional instructions.
Include a cover page containing the title of the assignment, the
student’s name, the professor’s name, the course title, and the
date. The cover page and the reference page are not included in
the required assignment page length.
The specific course learning outcomes associated with this
assignment are:
Perform vulnerability analysis as well as external and internal
penetration testing.
Demonstrate the ability to describe and perform penetration
tests on communication media to include wireless networks,
VoIPs, VPNs, Bluetooth and handheld devices.
Use technology and information resources to research issues in
penetration testing tools and techniques.
Write clearly and concisely about Network Penetration Testing
topics using proper writing mechanics and technical style
conventions.
Points: 120
Term Paper: Penetration Testing
Criteria
Unacceptable
Below 60% F
Meets Minimum Expectations
60-69% D
Fair
70-79% C
Proficient
80-89% B
Exemplary
90-100% A
1. Explain the tests you would run and the reason(s) for running
them (e.g. to support the risk assessment plan).
Weight 10%
Did not submit or incompletely explained the tests you would
run and the reason(s) for running them (e.g. to support the risk
assessment plan).
Insufficiently explained the tests you would run and the
reason(s) for running them (e.g. to support the risk assessment
plan).
Partially explained the tests you would run and the reason(s) for
running them (e.g. to support the risk assessment plan).
Satisfactorily explained the tests you would run and the
reason(s) for running them (e.g. to support the risk assessment
plan).
Thoroughly explained the tests you would run and the reason(s)
for running them (e.g. to support the risk assessment plan).
2. Determine the expected results from tests and research based
on the specific informational details provided.
Weight: 10%
Did not submit or incompletely determined the expected results
from tests and research based on the specific informational
details provided.
Insufficiently determined the expected results from tests and
research based on the specific informational details provided.
Partially determined the expected results from tests and
research based on the specific informational details provided.
Satisfactorily determined the expected results from tests and
research based on the specific informational details provided.
Thoroughly determined the expected results from tests and
research based on the specific informational details provided.
3. Analyze the software tools you would use for your
investigation and reasons for choosing them.
Weight: 15%
Did not submit or incompletely analyzed the software tools you
would use for your investigation and reasons for choosing them.
Insufficiently analyzed the software tools you would use for
your investigation and reasons for choosing them.
Partially analyzed the software tools you would use for your
investigation and reasons for choosing them.
Satisfactorily analyzed the software tools you would use for
your investigation and reasons for choosing them.
Thoroughly analyzed the software tools you would use for your
investigation and reasons for choosing them.
4. Describe the legal requirements and ethical issues involved.
Weight: 15%
Did not submit or incompletely described the legal
requirements; did not submit or incompletely described ethical
issues involved.
Insufficiently described the legal requirements; insufficiently
described ethical issues involved.
Partially described the legal requirements; partially described
ethical issues involved.
Satisfactorily described the legal requirements; satisfactorily
described ethical issues involved.
Thoroughly described the legal requirements; thoroughly
described ethical issues involved.
5. Using Visio or its open source alternative, provide a diagram
of how you would redesign this business’ network. Include a
description of your drawing.
Weight: 20%
Did not submit or incompletely provided a diagram of how you
would redesign this business’ network using Visio or its open
source alternative. Did not submit or incompletely included a
description of your drawing.
Insufficiently provided a diagram of how you would redesign
this business’ network using Visio or its open source
alternative. Insufficiently included a description of your
drawing.
Partially provided a diagram of how you would redesign this
business’ network using Visio or its open source alternative.
Partially included a description of your drawing.
Satisfactorily provided a diagram of how you would redesign
this business’ network using Visio or its open source
alternative. Satisfactorily included a description of your
drawing.
Thoroughly provided a diagram of how you would redesign this
business’ network using Visio or its open source alternative.
Thoroughly included a description of your drawing.
6. Propose your final recommendations and reporting. Explain
what risks exist and ways to either eliminate or reduce the risk.
Weight: 15%
Did not submit or incompletely proposed your final
recommendations and reporting. Did not submit or
incompletely explained what risks exist and ways to either
eliminate or reduce the risk.
Insufficiently proposed your final recommendations and
reporting. Insufficiently explained what risks exist and ways to
either eliminate or reduce the risk.
Partially proposed your final recommendations and reporting.
Partially explained what risks exist and ways to either eliminate
or reduce the risk.
Satisfactorily proposed your final recommendations and
reporting. Satisfactorily explained what risks exist and ways to
either eliminate or reduce the risk.
Thoroughly proposed your final recommendations and
reporting. Thoroughly explained what risks exist and ways to
either eliminate or reduce the risk.
7. 3 references
Weight: 5%
No references provided
Does not meet the required number of references; all references
poor quality choices.
Does not meet the required number of references; some
references poor quality choices.
Meets number of required references; all references high quality
choices.
Exceeds number of required references; all references high
quality choices.
8. Clarity, writing mechanics, and formatting requirements
Weight: 10%
More than 8 errors present
7-8 errors present
5-6 errors present
3-4 errors present
0-2 errors present

More Related Content

Similar to erm Paper Penetration TestingDue Week 10 and worth 120 points.docx

The security consulting firm that you work for has been awarded a co.docx
The security consulting firm that you work for has been awarded a co.docxThe security consulting firm that you work for has been awarded a co.docx
The security consulting firm that you work for has been awarded a co.docxjoshua2345678
 
Note Chapter 5 of the required textbook may be helpful in the com.docx
Note Chapter 5 of the required textbook may be helpful in the com.docxNote Chapter 5 of the required textbook may be helpful in the com.docx
Note Chapter 5 of the required textbook may be helpful in the com.docxIlonaThornburg83
 
Points 160Technical Paper Risk AssessmentCriteriaUna.docx
Points 160Technical Paper Risk AssessmentCriteriaUna.docxPoints 160Technical Paper Risk AssessmentCriteriaUna.docx
Points 160Technical Paper Risk AssessmentCriteriaUna.docxLeilaniPoolsy
 
INTRODUCTIONOne of the most critical factors in customer relat.docx
INTRODUCTIONOne of the most critical factors in customer relat.docxINTRODUCTIONOne of the most critical factors in customer relat.docx
INTRODUCTIONOne of the most critical factors in customer relat.docxbagotjesusa
 
Assignment 4 Designing Compliance within the LAN-to-WAN DomainNot.docx
Assignment 4 Designing Compliance within the LAN-to-WAN DomainNot.docxAssignment 4 Designing Compliance within the LAN-to-WAN DomainNot.docx
Assignment 4 Designing Compliance within the LAN-to-WAN DomainNot.docxastonrenna
 
Executive Proposal ProjectThe purpose of this project is to evalua.docx
Executive Proposal ProjectThe purpose of this project is to evalua.docxExecutive Proposal ProjectThe purpose of this project is to evalua.docx
Executive Proposal ProjectThe purpose of this project is to evalua.docxrhetttrevannion
 
Web Application Penetration Tests - Reporting
Web Application Penetration Tests - ReportingWeb Application Penetration Tests - Reporting
Web Application Penetration Tests - ReportingNetsparker
 
Week 10 Assignment 1 SubmissionClick the link above to submit yo.docx
Week 10 Assignment 1 SubmissionClick the link above to submit yo.docxWeek 10 Assignment 1 SubmissionClick the link above to submit yo.docx
Week 10 Assignment 1 SubmissionClick the link above to submit yo.docxdannies7qbuggie
 
CST 630 RANK Remember Education--cst630rank.com
CST 630 RANK Remember Education--cst630rank.comCST 630 RANK Remember Education--cst630rank.com
CST 630 RANK Remember Education--cst630rank.comchrysanthemu49
 
CST 630 RANK Redefined Education--cst630rank.com
CST 630 RANK Redefined Education--cst630rank.comCST 630 RANK Redefined Education--cst630rank.com
CST 630 RANK Redefined Education--cst630rank.comclaric241
 
QSO 510 Final Project Guidelines and Rubric Overview .docx
QSO 510 Final Project Guidelines and Rubric  Overview .docxQSO 510 Final Project Guidelines and Rubric  Overview .docx
QSO 510 Final Project Guidelines and Rubric Overview .docxmakdul
 
Cst 630 Enhance teaching / snaptutorial.com
Cst 630 Enhance teaching / snaptutorial.comCst 630 Enhance teaching / snaptutorial.com
Cst 630 Enhance teaching / snaptutorial.comBaileyabw
 
CST 630 RANK Achievement Education--cst630rank.com
CST 630 RANK Achievement Education--cst630rank.comCST 630 RANK Achievement Education--cst630rank.com
CST 630 RANK Achievement Education--cst630rank.comkopiko147
 
CST 630 RANK Introduction Education--cst630rank.com
CST 630 RANK Introduction Education--cst630rank.comCST 630 RANK Introduction Education--cst630rank.com
CST 630 RANK Introduction Education--cst630rank.comagathachristie266
 
CST 630 RANK Educational Specialist--cst630rank.com
CST 630 RANK Educational Specialist--cst630rank.comCST 630 RANK Educational Specialist--cst630rank.com
CST 630 RANK Educational Specialist--cst630rank.comVSNaipaul15
 
CST 630 RANK Inspiring Innovation--cst630rank.com
CST 630 RANK Inspiring Innovation--cst630rank.comCST 630 RANK Inspiring Innovation--cst630rank.com
CST 630 RANK Inspiring Innovation--cst630rank.comKeatonJennings104
 
CST 630 RANK Become Exceptional--cst630rank.com
CST 630 RANK Become Exceptional--cst630rank.comCST 630 RANK Become Exceptional--cst630rank.com
CST 630 RANK Become Exceptional--cst630rank.comagathachristie113
 
Cst 630 Education Organization-snaptutorial.com
Cst 630 Education Organization-snaptutorial.comCst 630 Education Organization-snaptutorial.com
Cst 630 Education Organization-snaptutorial.comrobertlesew6
 
Running head VOIP WORK BREAKDOWN STRUCTURE 1VOIP WORK BRE.docx
Running head VOIP WORK BREAKDOWN STRUCTURE 1VOIP WORK BRE.docxRunning head VOIP WORK BREAKDOWN STRUCTURE 1VOIP WORK BRE.docx
Running head VOIP WORK BREAKDOWN STRUCTURE 1VOIP WORK BRE.docxrtodd599
 
Cst 630 Inspiring Innovation--tutorialrank.com
Cst 630 Inspiring Innovation--tutorialrank.comCst 630 Inspiring Innovation--tutorialrank.com
Cst 630 Inspiring Innovation--tutorialrank.comPrescottLunt385
 

Similar to erm Paper Penetration TestingDue Week 10 and worth 120 points.docx (20)

The security consulting firm that you work for has been awarded a co.docx
The security consulting firm that you work for has been awarded a co.docxThe security consulting firm that you work for has been awarded a co.docx
The security consulting firm that you work for has been awarded a co.docx
 
Note Chapter 5 of the required textbook may be helpful in the com.docx
Note Chapter 5 of the required textbook may be helpful in the com.docxNote Chapter 5 of the required textbook may be helpful in the com.docx
Note Chapter 5 of the required textbook may be helpful in the com.docx
 
Points 160Technical Paper Risk AssessmentCriteriaUna.docx
Points 160Technical Paper Risk AssessmentCriteriaUna.docxPoints 160Technical Paper Risk AssessmentCriteriaUna.docx
Points 160Technical Paper Risk AssessmentCriteriaUna.docx
 
INTRODUCTIONOne of the most critical factors in customer relat.docx
INTRODUCTIONOne of the most critical factors in customer relat.docxINTRODUCTIONOne of the most critical factors in customer relat.docx
INTRODUCTIONOne of the most critical factors in customer relat.docx
 
Assignment 4 Designing Compliance within the LAN-to-WAN DomainNot.docx
Assignment 4 Designing Compliance within the LAN-to-WAN DomainNot.docxAssignment 4 Designing Compliance within the LAN-to-WAN DomainNot.docx
Assignment 4 Designing Compliance within the LAN-to-WAN DomainNot.docx
 
Executive Proposal ProjectThe purpose of this project is to evalua.docx
Executive Proposal ProjectThe purpose of this project is to evalua.docxExecutive Proposal ProjectThe purpose of this project is to evalua.docx
Executive Proposal ProjectThe purpose of this project is to evalua.docx
 
Web Application Penetration Tests - Reporting
Web Application Penetration Tests - ReportingWeb Application Penetration Tests - Reporting
Web Application Penetration Tests - Reporting
 
Week 10 Assignment 1 SubmissionClick the link above to submit yo.docx
Week 10 Assignment 1 SubmissionClick the link above to submit yo.docxWeek 10 Assignment 1 SubmissionClick the link above to submit yo.docx
Week 10 Assignment 1 SubmissionClick the link above to submit yo.docx
 
CST 630 RANK Remember Education--cst630rank.com
CST 630 RANK Remember Education--cst630rank.comCST 630 RANK Remember Education--cst630rank.com
CST 630 RANK Remember Education--cst630rank.com
 
CST 630 RANK Redefined Education--cst630rank.com
CST 630 RANK Redefined Education--cst630rank.comCST 630 RANK Redefined Education--cst630rank.com
CST 630 RANK Redefined Education--cst630rank.com
 
QSO 510 Final Project Guidelines and Rubric Overview .docx
QSO 510 Final Project Guidelines and Rubric  Overview .docxQSO 510 Final Project Guidelines and Rubric  Overview .docx
QSO 510 Final Project Guidelines and Rubric Overview .docx
 
Cst 630 Enhance teaching / snaptutorial.com
Cst 630 Enhance teaching / snaptutorial.comCst 630 Enhance teaching / snaptutorial.com
Cst 630 Enhance teaching / snaptutorial.com
 
CST 630 RANK Achievement Education--cst630rank.com
CST 630 RANK Achievement Education--cst630rank.comCST 630 RANK Achievement Education--cst630rank.com
CST 630 RANK Achievement Education--cst630rank.com
 
CST 630 RANK Introduction Education--cst630rank.com
CST 630 RANK Introduction Education--cst630rank.comCST 630 RANK Introduction Education--cst630rank.com
CST 630 RANK Introduction Education--cst630rank.com
 
CST 630 RANK Educational Specialist--cst630rank.com
CST 630 RANK Educational Specialist--cst630rank.comCST 630 RANK Educational Specialist--cst630rank.com
CST 630 RANK Educational Specialist--cst630rank.com
 
CST 630 RANK Inspiring Innovation--cst630rank.com
CST 630 RANK Inspiring Innovation--cst630rank.comCST 630 RANK Inspiring Innovation--cst630rank.com
CST 630 RANK Inspiring Innovation--cst630rank.com
 
CST 630 RANK Become Exceptional--cst630rank.com
CST 630 RANK Become Exceptional--cst630rank.comCST 630 RANK Become Exceptional--cst630rank.com
CST 630 RANK Become Exceptional--cst630rank.com
 
Cst 630 Education Organization-snaptutorial.com
Cst 630 Education Organization-snaptutorial.comCst 630 Education Organization-snaptutorial.com
Cst 630 Education Organization-snaptutorial.com
 
Running head VOIP WORK BREAKDOWN STRUCTURE 1VOIP WORK BRE.docx
Running head VOIP WORK BREAKDOWN STRUCTURE 1VOIP WORK BRE.docxRunning head VOIP WORK BREAKDOWN STRUCTURE 1VOIP WORK BRE.docx
Running head VOIP WORK BREAKDOWN STRUCTURE 1VOIP WORK BRE.docx
 
Cst 630 Inspiring Innovation--tutorialrank.com
Cst 630 Inspiring Innovation--tutorialrank.comCst 630 Inspiring Innovation--tutorialrank.com
Cst 630 Inspiring Innovation--tutorialrank.com
 

More from mealsdeidre

Example One Child does not celebrate birthdaysCultural Identifi.docx
Example One Child does not celebrate birthdaysCultural Identifi.docxExample One Child does not celebrate birthdaysCultural Identifi.docx
Example One Child does not celebrate birthdaysCultural Identifi.docxmealsdeidre
 
example is in the attachment. i just need a summary paragraph for 5 .docx
example is in the attachment. i just need a summary paragraph for 5 .docxexample is in the attachment. i just need a summary paragraph for 5 .docx
example is in the attachment. i just need a summary paragraph for 5 .docxmealsdeidre
 
Example Hemming uses a perpetual inventory system.1. De.docx
Example Hemming uses a perpetual inventory system.1. De.docxExample Hemming uses a perpetual inventory system.1. De.docx
Example Hemming uses a perpetual inventory system.1. De.docxmealsdeidre
 
Example digital media projects includeA video using photos and au.docx
Example digital media projects includeA video using photos and au.docxExample digital media projects includeA video using photos and au.docx
Example digital media projects includeA video using photos and au.docxmealsdeidre
 
Examine the U.S. Governments support during the Great Depression fo.docx
Examine the U.S. Governments support during the Great Depression fo.docxExamine the U.S. Governments support during the Great Depression fo.docx
Examine the U.S. Governments support during the Great Depression fo.docxmealsdeidre
 
Examine the U.S. Governments support during the Great Depression .docx
Examine the U.S. Governments support during the Great Depression .docxExamine the U.S. Governments support during the Great Depression .docx
Examine the U.S. Governments support during the Great Depression .docxmealsdeidre
 
Examine the various types of financial resources Health Educators us.docx
Examine the various types of financial resources Health Educators us.docxExamine the various types of financial resources Health Educators us.docx
Examine the various types of financial resources Health Educators us.docxmealsdeidre
 
Examine the relationship between advances in technology and the resp.docx
Examine the relationship between advances in technology and the resp.docxExamine the relationship between advances in technology and the resp.docx
Examine the relationship between advances in technology and the resp.docxmealsdeidre
 
Examine the traditional and contemporary approaches to leadership an.docx
Examine the traditional and contemporary approaches to leadership an.docxExamine the traditional and contemporary approaches to leadership an.docx
Examine the traditional and contemporary approaches to leadership an.docxmealsdeidre
 
Examine the social perssure to learn English. What have you observe .docx
Examine the social perssure to learn English. What have you observe .docxExamine the social perssure to learn English. What have you observe .docx
Examine the social perssure to learn English. What have you observe .docxmealsdeidre
 
Exercise 3 New(s) ChangeA brief situational statementThe new.docx
Exercise 3 New(s) ChangeA brief situational statementThe new.docxExercise 3 New(s) ChangeA brief situational statementThe new.docx
Exercise 3 New(s) ChangeA brief situational statementThe new.docxmealsdeidre
 
Exercise 22-3Taveras Co. decides at the beginning of 2014 to adopt.docx
Exercise 22-3Taveras Co. decides at the beginning of 2014 to adopt.docxExercise 22-3Taveras Co. decides at the beginning of 2014 to adopt.docx
Exercise 22-3Taveras Co. decides at the beginning of 2014 to adopt.docxmealsdeidre
 
Exercise 14-1 Recording bond issuance and interest L.O. P1On Janua.docx
Exercise 14-1 Recording bond issuance and interest L.O. P1On Janua.docxExercise 14-1 Recording bond issuance and interest L.O. P1On Janua.docx
Exercise 14-1 Recording bond issuance and interest L.O. P1On Janua.docxmealsdeidre
 
Exercise 1-11Two items are omitted from each of the following summ.docx
Exercise 1-11Two items are omitted from each of the following summ.docxExercise 1-11Two items are omitted from each of the following summ.docx
Exercise 1-11Two items are omitted from each of the following summ.docxmealsdeidre
 
Exchange Rate and Transaction and Translation Exposure  Please resp.docx
Exchange Rate and Transaction and Translation Exposure  Please resp.docxExchange Rate and Transaction and Translation Exposure  Please resp.docx
Exchange Rate and Transaction and Translation Exposure  Please resp.docxmealsdeidre
 
Excel spreadsheetDetailsWeekly tasks or assignments (Individu.docx
Excel spreadsheetDetailsWeekly tasks or assignments (Individu.docxExcel spreadsheetDetailsWeekly tasks or assignments (Individu.docx
Excel spreadsheetDetailsWeekly tasks or assignments (Individu.docxmealsdeidre
 
Exceptionality PresentationIn this course, you have learned about .docx
Exceptionality PresentationIn this course, you have learned about .docxExceptionality PresentationIn this course, you have learned about .docx
Exceptionality PresentationIn this course, you have learned about .docxmealsdeidre
 
examine how an organization motivates a diverse group of individuals.docx
examine how an organization motivates a diverse group of individuals.docxexamine how an organization motivates a diverse group of individuals.docx
examine how an organization motivates a diverse group of individuals.docxmealsdeidre
 
Examine different sociologists’ accounts of the effect of urbanism. .docx
Examine different sociologists’ accounts of the effect of urbanism. .docxExamine different sociologists’ accounts of the effect of urbanism. .docx
Examine different sociologists’ accounts of the effect of urbanism. .docxmealsdeidre
 
Examine the extent that the culture in the United States has changed.docx
Examine the extent that the culture in the United States has changed.docxExamine the extent that the culture in the United States has changed.docx
Examine the extent that the culture in the United States has changed.docxmealsdeidre
 

More from mealsdeidre (20)

Example One Child does not celebrate birthdaysCultural Identifi.docx
Example One Child does not celebrate birthdaysCultural Identifi.docxExample One Child does not celebrate birthdaysCultural Identifi.docx
Example One Child does not celebrate birthdaysCultural Identifi.docx
 
example is in the attachment. i just need a summary paragraph for 5 .docx
example is in the attachment. i just need a summary paragraph for 5 .docxexample is in the attachment. i just need a summary paragraph for 5 .docx
example is in the attachment. i just need a summary paragraph for 5 .docx
 
Example Hemming uses a perpetual inventory system.1. De.docx
Example Hemming uses a perpetual inventory system.1. De.docxExample Hemming uses a perpetual inventory system.1. De.docx
Example Hemming uses a perpetual inventory system.1. De.docx
 
Example digital media projects includeA video using photos and au.docx
Example digital media projects includeA video using photos and au.docxExample digital media projects includeA video using photos and au.docx
Example digital media projects includeA video using photos and au.docx
 
Examine the U.S. Governments support during the Great Depression fo.docx
Examine the U.S. Governments support during the Great Depression fo.docxExamine the U.S. Governments support during the Great Depression fo.docx
Examine the U.S. Governments support during the Great Depression fo.docx
 
Examine the U.S. Governments support during the Great Depression .docx
Examine the U.S. Governments support during the Great Depression .docxExamine the U.S. Governments support during the Great Depression .docx
Examine the U.S. Governments support during the Great Depression .docx
 
Examine the various types of financial resources Health Educators us.docx
Examine the various types of financial resources Health Educators us.docxExamine the various types of financial resources Health Educators us.docx
Examine the various types of financial resources Health Educators us.docx
 
Examine the relationship between advances in technology and the resp.docx
Examine the relationship between advances in technology and the resp.docxExamine the relationship between advances in technology and the resp.docx
Examine the relationship between advances in technology and the resp.docx
 
Examine the traditional and contemporary approaches to leadership an.docx
Examine the traditional and contemporary approaches to leadership an.docxExamine the traditional and contemporary approaches to leadership an.docx
Examine the traditional and contemporary approaches to leadership an.docx
 
Examine the social perssure to learn English. What have you observe .docx
Examine the social perssure to learn English. What have you observe .docxExamine the social perssure to learn English. What have you observe .docx
Examine the social perssure to learn English. What have you observe .docx
 
Exercise 3 New(s) ChangeA brief situational statementThe new.docx
Exercise 3 New(s) ChangeA brief situational statementThe new.docxExercise 3 New(s) ChangeA brief situational statementThe new.docx
Exercise 3 New(s) ChangeA brief situational statementThe new.docx
 
Exercise 22-3Taveras Co. decides at the beginning of 2014 to adopt.docx
Exercise 22-3Taveras Co. decides at the beginning of 2014 to adopt.docxExercise 22-3Taveras Co. decides at the beginning of 2014 to adopt.docx
Exercise 22-3Taveras Co. decides at the beginning of 2014 to adopt.docx
 
Exercise 14-1 Recording bond issuance and interest L.O. P1On Janua.docx
Exercise 14-1 Recording bond issuance and interest L.O. P1On Janua.docxExercise 14-1 Recording bond issuance and interest L.O. P1On Janua.docx
Exercise 14-1 Recording bond issuance and interest L.O. P1On Janua.docx
 
Exercise 1-11Two items are omitted from each of the following summ.docx
Exercise 1-11Two items are omitted from each of the following summ.docxExercise 1-11Two items are omitted from each of the following summ.docx
Exercise 1-11Two items are omitted from each of the following summ.docx
 
Exchange Rate and Transaction and Translation Exposure  Please resp.docx
Exchange Rate and Transaction and Translation Exposure  Please resp.docxExchange Rate and Transaction and Translation Exposure  Please resp.docx
Exchange Rate and Transaction and Translation Exposure  Please resp.docx
 
Excel spreadsheetDetailsWeekly tasks or assignments (Individu.docx
Excel spreadsheetDetailsWeekly tasks or assignments (Individu.docxExcel spreadsheetDetailsWeekly tasks or assignments (Individu.docx
Excel spreadsheetDetailsWeekly tasks or assignments (Individu.docx
 
Exceptionality PresentationIn this course, you have learned about .docx
Exceptionality PresentationIn this course, you have learned about .docxExceptionality PresentationIn this course, you have learned about .docx
Exceptionality PresentationIn this course, you have learned about .docx
 
examine how an organization motivates a diverse group of individuals.docx
examine how an organization motivates a diverse group of individuals.docxexamine how an organization motivates a diverse group of individuals.docx
examine how an organization motivates a diverse group of individuals.docx
 
Examine different sociologists’ accounts of the effect of urbanism. .docx
Examine different sociologists’ accounts of the effect of urbanism. .docxExamine different sociologists’ accounts of the effect of urbanism. .docx
Examine different sociologists’ accounts of the effect of urbanism. .docx
 
Examine the extent that the culture in the United States has changed.docx
Examine the extent that the culture in the United States has changed.docxExamine the extent that the culture in the United States has changed.docx
Examine the extent that the culture in the United States has changed.docx
 

Recently uploaded

internship ppt on smartinternz platform as salesforce developer
internship ppt on smartinternz platform as salesforce developerinternship ppt on smartinternz platform as salesforce developer
internship ppt on smartinternz platform as salesforce developerunnathinaik
 
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptxPOINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptxSayali Powar
 
Science 7 - LAND and SEA BREEZE and its Characteristics
Science 7 - LAND and SEA BREEZE and its CharacteristicsScience 7 - LAND and SEA BREEZE and its Characteristics
Science 7 - LAND and SEA BREEZE and its CharacteristicsKarinaGenton
 
भारत-रोम व्यापार.pptx, Indo-Roman Trade,
भारत-रोम व्यापार.pptx, Indo-Roman Trade,भारत-रोम व्यापार.pptx, Indo-Roman Trade,
भारत-रोम व्यापार.pptx, Indo-Roman Trade,Virag Sontakke
 
Enzyme, Pharmaceutical Aids, Miscellaneous Last Part of Chapter no 5th.pdf
Enzyme, Pharmaceutical Aids, Miscellaneous Last Part of Chapter no 5th.pdfEnzyme, Pharmaceutical Aids, Miscellaneous Last Part of Chapter no 5th.pdf
Enzyme, Pharmaceutical Aids, Miscellaneous Last Part of Chapter no 5th.pdfSumit Tiwari
 
Introduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher EducationIntroduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher Educationpboyjonauth
 
Class 11 Legal Studies Ch-1 Concept of State .pdf
Class 11 Legal Studies Ch-1 Concept of State .pdfClass 11 Legal Studies Ch-1 Concept of State .pdf
Class 11 Legal Studies Ch-1 Concept of State .pdfakmcokerachita
 
Incoming and Outgoing Shipments in 1 STEP Using Odoo 17
Incoming and Outgoing Shipments in 1 STEP Using Odoo 17Incoming and Outgoing Shipments in 1 STEP Using Odoo 17
Incoming and Outgoing Shipments in 1 STEP Using Odoo 17Celine George
 
Computed Fields and api Depends in the Odoo 17
Computed Fields and api Depends in the Odoo 17Computed Fields and api Depends in the Odoo 17
Computed Fields and api Depends in the Odoo 17Celine George
 
Painted Grey Ware.pptx, PGW Culture of India
Painted Grey Ware.pptx, PGW Culture of IndiaPainted Grey Ware.pptx, PGW Culture of India
Painted Grey Ware.pptx, PGW Culture of IndiaVirag Sontakke
 
Blooming Together_ Growing a Community Garden Worksheet.docx
Blooming Together_ Growing a Community Garden Worksheet.docxBlooming Together_ Growing a Community Garden Worksheet.docx
Blooming Together_ Growing a Community Garden Worksheet.docxUnboundStockton
 
Presiding Officer Training module 2024 lok sabha elections
Presiding Officer Training module 2024 lok sabha electionsPresiding Officer Training module 2024 lok sabha elections
Presiding Officer Training module 2024 lok sabha electionsanshu789521
 
Sanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfSanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfsanyamsingh5019
 
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPTECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPTiammrhaywood
 
Pharmacognosy Flower 3. Compositae 2023.pdf
Pharmacognosy Flower 3. Compositae 2023.pdfPharmacognosy Flower 3. Compositae 2023.pdf
Pharmacognosy Flower 3. Compositae 2023.pdfMahmoud M. Sallam
 
Hybridoma Technology ( Production , Purification , and Application )
Hybridoma Technology  ( Production , Purification , and Application  ) Hybridoma Technology  ( Production , Purification , and Application  )
Hybridoma Technology ( Production , Purification , and Application ) Sakshi Ghasle
 
BASLIQ CURRENT LOOKBOOK LOOKBOOK(1) (1).pdf
BASLIQ CURRENT LOOKBOOK  LOOKBOOK(1) (1).pdfBASLIQ CURRENT LOOKBOOK  LOOKBOOK(1) (1).pdf
BASLIQ CURRENT LOOKBOOK LOOKBOOK(1) (1).pdfSoniaTolstoy
 
Biting mechanism of poisonous snakes.pdf
Biting mechanism of poisonous snakes.pdfBiting mechanism of poisonous snakes.pdf
Biting mechanism of poisonous snakes.pdfadityarao40181
 
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxSOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxiammrhaywood
 

Recently uploaded (20)

internship ppt on smartinternz platform as salesforce developer
internship ppt on smartinternz platform as salesforce developerinternship ppt on smartinternz platform as salesforce developer
internship ppt on smartinternz platform as salesforce developer
 
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptxPOINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
POINT- BIOCHEMISTRY SEM 2 ENZYMES UNIT 5.pptx
 
Science 7 - LAND and SEA BREEZE and its Characteristics
Science 7 - LAND and SEA BREEZE and its CharacteristicsScience 7 - LAND and SEA BREEZE and its Characteristics
Science 7 - LAND and SEA BREEZE and its Characteristics
 
भारत-रोम व्यापार.pptx, Indo-Roman Trade,
भारत-रोम व्यापार.pptx, Indo-Roman Trade,भारत-रोम व्यापार.pptx, Indo-Roman Trade,
भारत-रोम व्यापार.pptx, Indo-Roman Trade,
 
Enzyme, Pharmaceutical Aids, Miscellaneous Last Part of Chapter no 5th.pdf
Enzyme, Pharmaceutical Aids, Miscellaneous Last Part of Chapter no 5th.pdfEnzyme, Pharmaceutical Aids, Miscellaneous Last Part of Chapter no 5th.pdf
Enzyme, Pharmaceutical Aids, Miscellaneous Last Part of Chapter no 5th.pdf
 
Introduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher EducationIntroduction to ArtificiaI Intelligence in Higher Education
Introduction to ArtificiaI Intelligence in Higher Education
 
Class 11 Legal Studies Ch-1 Concept of State .pdf
Class 11 Legal Studies Ch-1 Concept of State .pdfClass 11 Legal Studies Ch-1 Concept of State .pdf
Class 11 Legal Studies Ch-1 Concept of State .pdf
 
Incoming and Outgoing Shipments in 1 STEP Using Odoo 17
Incoming and Outgoing Shipments in 1 STEP Using Odoo 17Incoming and Outgoing Shipments in 1 STEP Using Odoo 17
Incoming and Outgoing Shipments in 1 STEP Using Odoo 17
 
Computed Fields and api Depends in the Odoo 17
Computed Fields and api Depends in the Odoo 17Computed Fields and api Depends in the Odoo 17
Computed Fields and api Depends in the Odoo 17
 
Painted Grey Ware.pptx, PGW Culture of India
Painted Grey Ware.pptx, PGW Culture of IndiaPainted Grey Ware.pptx, PGW Culture of India
Painted Grey Ware.pptx, PGW Culture of India
 
Blooming Together_ Growing a Community Garden Worksheet.docx
Blooming Together_ Growing a Community Garden Worksheet.docxBlooming Together_ Growing a Community Garden Worksheet.docx
Blooming Together_ Growing a Community Garden Worksheet.docx
 
Staff of Color (SOC) Retention Efforts DDSD
Staff of Color (SOC) Retention Efforts DDSDStaff of Color (SOC) Retention Efforts DDSD
Staff of Color (SOC) Retention Efforts DDSD
 
Presiding Officer Training module 2024 lok sabha elections
Presiding Officer Training module 2024 lok sabha electionsPresiding Officer Training module 2024 lok sabha elections
Presiding Officer Training module 2024 lok sabha elections
 
Sanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdfSanyam Choudhary Chemistry practical.pdf
Sanyam Choudhary Chemistry practical.pdf
 
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPTECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
ECONOMIC CONTEXT - LONG FORM TV DRAMA - PPT
 
Pharmacognosy Flower 3. Compositae 2023.pdf
Pharmacognosy Flower 3. Compositae 2023.pdfPharmacognosy Flower 3. Compositae 2023.pdf
Pharmacognosy Flower 3. Compositae 2023.pdf
 
Hybridoma Technology ( Production , Purification , and Application )
Hybridoma Technology  ( Production , Purification , and Application  ) Hybridoma Technology  ( Production , Purification , and Application  )
Hybridoma Technology ( Production , Purification , and Application )
 
BASLIQ CURRENT LOOKBOOK LOOKBOOK(1) (1).pdf
BASLIQ CURRENT LOOKBOOK  LOOKBOOK(1) (1).pdfBASLIQ CURRENT LOOKBOOK  LOOKBOOK(1) (1).pdf
BASLIQ CURRENT LOOKBOOK LOOKBOOK(1) (1).pdf
 
Biting mechanism of poisonous snakes.pdf
Biting mechanism of poisonous snakes.pdfBiting mechanism of poisonous snakes.pdf
Biting mechanism of poisonous snakes.pdf
 
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxSOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
 

erm Paper Penetration TestingDue Week 10 and worth 120 points.docx

  • 1. erm Paper: Penetration Testing Due Week 10 and worth 120 points As a penetration tester, you are hired as a consultant by a small- to mid-sized business that is interested in calculating its overall security risk today, January 1, 2012. The business specializes in providing private loans to college students. This business uses both an e-Commerce site and point-of-sales devices (credit card swipes) to collect payment. Also, there exist a number of file transfer operations where sensitive and confidential data is transferred to and from several external partnering companies. The typical volume of payment transactions totals is approximately $100 million. You decide that the risk assessments are to take into account the entire network of workstations, VoIP phone sets, servers, routers, switches and other networking gear. During your interview with one of the business’s IT staff members, you are told that many external vendors want to sell security networking products and software solutions. The staff member also claimed that their network was too “flat.” During the initial onsite visit, you captured the following pertinent data to use in creation of the Penetration Test Plan. Non-stateful packet firewall separates the business’s internal network from its DMZ. All departments--including Finance, Marketing, Development, and IT--connect into the same enterprise switch and are therefore on the same LAN. Senior management (CEO, CIO, President, etc.) and the Help Desk are not on that LAN; they are connected via a common Ethernet hub and then to the switched LAN. All of the workstations used by employees are either Windows 98 or Windows XP. None of the workstations have service packs or updates beyond service pack one. Two (2) Web servers containing customer portals for logging in and ordering products exist on the DMZ running Windows 2000
  • 2. Server SP1, and IIS v5. One (1) internal server containing Active Directory (AD) services to authenticate users, a DB where all data for the company is stored (i.e. HR, financial, product design, customer, transactions). The AD server is using LM instead of NTLM. Write a six to eight (6-8) page paper in which you: Explain the tests you would run and the reason(s) for running them (e.g. to support the risk assessment plan). Determine the expected results from tests and research based on the specific informational details provided. (i.e., IIS v5, Windows Server 2000, AD server not using NTLM) Analyze the software tools you would use for your investigation and reasons for choosing them. Describe the legal requirements and ethical issues involved. Using Visio or its open source alternative, provide a diagram of how you would redesign this business’ network. Include a description of your drawing. Note : The graphically depicted solution is not included in the required page length. Propose your final recommendations and reporting. Explain what risks exist and ways to either eliminate or reduce the risk. Use at least three (3) quality resources in this assignment. Note: Wikipedia and similar Websites do not qualify as quality resources. Your assignment must follow these formatting requirements: Be typed, double spaced, using Times New Roman font (size 12), with one-inch margins on all sides; citations and references must follow APA or school-specific format. Check with your professor for any additional instructions. Include a cover page containing the title of the assignment, the student’s name, the professor’s name, the course title, and the date. The cover page and the reference page are not included in
  • 3. the required assignment page length. The specific course learning outcomes associated with this assignment are: Perform vulnerability analysis as well as external and internal penetration testing. Demonstrate the ability to describe and perform penetration tests on communication media to include wireless networks, VoIPs, VPNs, Bluetooth and handheld devices. Use technology and information resources to research issues in penetration testing tools and techniques. Write clearly and concisely about Network Penetration Testing topics using proper writing mechanics and technical style conventions. Points: 120 Term Paper: Penetration Testing Criteria Unacceptable Below 60% F Meets Minimum Expectations 60-69% D Fair 70-79% C Proficient 80-89% B Exemplary 90-100% A 1. Explain the tests you would run and the reason(s) for running them (e.g. to support the risk assessment plan). Weight 10% Did not submit or incompletely explained the tests you would run and the reason(s) for running them (e.g. to support the risk
  • 4. assessment plan). Insufficiently explained the tests you would run and the reason(s) for running them (e.g. to support the risk assessment plan). Partially explained the tests you would run and the reason(s) for running them (e.g. to support the risk assessment plan). Satisfactorily explained the tests you would run and the reason(s) for running them (e.g. to support the risk assessment plan). Thoroughly explained the tests you would run and the reason(s) for running them (e.g. to support the risk assessment plan). 2. Determine the expected results from tests and research based on the specific informational details provided. Weight: 10% Did not submit or incompletely determined the expected results from tests and research based on the specific informational details provided. Insufficiently determined the expected results from tests and research based on the specific informational details provided. Partially determined the expected results from tests and research based on the specific informational details provided. Satisfactorily determined the expected results from tests and research based on the specific informational details provided. Thoroughly determined the expected results from tests and research based on the specific informational details provided. 3. Analyze the software tools you would use for your investigation and reasons for choosing them. Weight: 15% Did not submit or incompletely analyzed the software tools you would use for your investigation and reasons for choosing them. Insufficiently analyzed the software tools you would use for your investigation and reasons for choosing them. Partially analyzed the software tools you would use for your investigation and reasons for choosing them. Satisfactorily analyzed the software tools you would use for your investigation and reasons for choosing them.
  • 5. Thoroughly analyzed the software tools you would use for your investigation and reasons for choosing them. 4. Describe the legal requirements and ethical issues involved. Weight: 15% Did not submit or incompletely described the legal requirements; did not submit or incompletely described ethical issues involved. Insufficiently described the legal requirements; insufficiently described ethical issues involved. Partially described the legal requirements; partially described ethical issues involved. Satisfactorily described the legal requirements; satisfactorily described ethical issues involved. Thoroughly described the legal requirements; thoroughly described ethical issues involved. 5. Using Visio or its open source alternative, provide a diagram of how you would redesign this business’ network. Include a description of your drawing. Weight: 20% Did not submit or incompletely provided a diagram of how you would redesign this business’ network using Visio or its open source alternative. Did not submit or incompletely included a description of your drawing. Insufficiently provided a diagram of how you would redesign this business’ network using Visio or its open source alternative. Insufficiently included a description of your drawing. Partially provided a diagram of how you would redesign this business’ network using Visio or its open source alternative. Partially included a description of your drawing. Satisfactorily provided a diagram of how you would redesign this business’ network using Visio or its open source alternative. Satisfactorily included a description of your drawing. Thoroughly provided a diagram of how you would redesign this business’ network using Visio or its open source alternative.
  • 6. Thoroughly included a description of your drawing. 6. Propose your final recommendations and reporting. Explain what risks exist and ways to either eliminate or reduce the risk. Weight: 15% Did not submit or incompletely proposed your final recommendations and reporting. Did not submit or incompletely explained what risks exist and ways to either eliminate or reduce the risk. Insufficiently proposed your final recommendations and reporting. Insufficiently explained what risks exist and ways to either eliminate or reduce the risk. Partially proposed your final recommendations and reporting. Partially explained what risks exist and ways to either eliminate or reduce the risk. Satisfactorily proposed your final recommendations and reporting. Satisfactorily explained what risks exist and ways to either eliminate or reduce the risk. Thoroughly proposed your final recommendations and reporting. Thoroughly explained what risks exist and ways to either eliminate or reduce the risk. 7. 3 references Weight: 5% No references provided Does not meet the required number of references; all references poor quality choices. Does not meet the required number of references; some references poor quality choices. Meets number of required references; all references high quality choices. Exceeds number of required references; all references high quality choices. 8. Clarity, writing mechanics, and formatting requirements Weight: 10% More than 8 errors present 7-8 errors present 5-6 errors present
  • 7. 3-4 errors present 0-2 errors present