Reference no: EM131053037
In this assignment, you will have an opportunity to prepare a proposal for a penetration test. During this module, you discussed several aspects of penetration testing. This assignment will give you the opportunity to demonstrate some of the items you learned throughout the module.
Scenario:
You are the owner and operator of a small information security consulting firm. You have received a request from one of your clients, Infusion Web Marketing, that you provide a written proposal for performing a penetration test on the company's production web servers and corporate network.
You need to prepare a 3- to 5-page Microsoft Word document written proposal for a penetration test on the firm. The penetration test proposal will include a listing of the specific tasks, deliverables, and reports that will be delivered as part of the penetration-testing process.
Company Environment:
Scope
|
The e-commerce web application server acts as an external point of entry into the network. Here the following occurs:
- Ubuntu Linux 10.04 LTS Server (TargetUbuntu01)
- Apache Web Server runs the e-commerce web application server.
- Credit card transaction processing occurs on all web servers.
|
Intrusive or nonintrusive
|
Intrusive. The test will include penetrating specific security checkpoints.
|
Compromise or no compromise
|
No compromise. The test can compromise with written client authorization only.
|
Maintenance scheduling
|
Maintenance is only to be conducted between 2:00 a.m. and 6:00 a.m. Monday through Friday (Mountain Standard Time) and one day over the weekend (Saturday or Sunday).
|
Tasks:
Using information from the scenario above, provide a 3- to 5-page written attack-and-penetration test plan. The plan should include the following sections in a Microsoft Word document:
- A cover page and a table of contents
- A project summary
- Goals and objectives
- Tasks
- Reports
a. List what penetration-testing reports will be provided to the company
b. Explain what type of information will be included in each report
c. Describe each report's significance and what the results mean
- A schedule
o Some penetration-testing activities can be disruptive to network operations. Therefore, this section should explain when these types of activities should or can be scheduled
- A summary
- A reference page, a bibliography page, or both
Note: Utilize at least three scholarly or professional sources (beyond your textbook) in your paper. Your paper should be written in a clear, concise, and organized manner; demonstrate ethical scholarship in accurate representation and attribution of sources (i.e., in APA format); and display accurate spelling, grammar, and punctuation.
Grow an investment to a specific amount of money
: Which of the following statements about calculating the number of years needed to grow an investment to a specific amount of money is true?
|
Explore the value of various types of methodologies
: Explore the value of various types of methodologies. For this assignment, identify your topic of interest and use and cite existing literature to support the need for further research in the area.
|
How much money would be needed to pay the cost of replanting
: The local botanical society wants to ensure that the gardens in the town park, are properly cared for. They recently spent $100,000 to plant the gardens. They would like to set up a perpetual fund to provide $100,000 for future replanting of the gard..
|
Employees announcing the opening for a supervisor position
: Write to your employees announcing the opening for a supervisor position within your company. Write to your stock holders informing them of a new satellite location of your office that will be opening next year in Detroit, Michigan.
|
Explain what type of information will be included in record
: List what penetration-testing reports will be provided to the company. Explain what type of information will be included in each report. Describe each report's significance and what the results mean.
|
Articles addressing privatization-arizona private prisons
: After reading the two articles addressing privatization,Arizona's private prisons: A bad bargainandThe case for privatizing California's prisons, respond to each of the following questions:
|
How are future values affected by changes in interest rates
: How are future values affected by changes in interest rates?
|
Create year-end net worth statement and annual cash flow
: You are a new, but highly educated financial planner and need to prepare some financial statements and answer some questions for your clients, Robert and Cora Crawley, the Earl and Countess of Grantham. Create a year-end net worth statement and annua..
|
Preventing school and workplace violence
: What are some significant differences between on-campus crime and crime in the general population? Discuss the challenged inherent in preventing school and workplace violence.
|