Network exploitation and post-exploitation assessment

Assignment Help Computer Network Security
Reference no: EM133812919

Penetration Testing

Assessment - Cyber Attack Analysis and Mitigation Report

Task

This assessment is to be completed individually. In this assessment, you will conduct individual research and produce an incident analysis report for any two cybersecurity incidents that might have happened to an organisation based on a case study scenario below.

Assessment Description

In this assessment:
You will research cyber security incidents and document different observable attack techniques, tactics, and procedures (TTPs), their impact on the organisation, and potential risks associated with these attacks based on the scenario below.

You are to provide a critical analysis of each attack phase, detailing vulnerabilities and entry points exploited by attackers for any incident.
The objective of this assessment is to help you develop research skills and the ability to assess and analyse various cybersecurity incidents, and threats. You are then required to recommend countermeasures based on the content covered during Weeks 4 to 7 using a real-world scenario focusing on:

Social Engineering Assessment

Analyse the different social engineering methods that could have been used in the recent incident above to gain unauthorised access.
Investigate and document how the social engineering tactics used affected the organisation's security posture.

Scanning and Enumeration Analysis
Explore the different ways that the intruders could have used to conduct scanning and enumeration to identify potential vulnerabilities within the organisation network.

Identify any weaknesses that the intruders could have exploited through the scanning and enumeration phases.

Network Exploitation and Post-Exploitation Assessment
Investigate the different methods that the intruders may have used to exploit vulnerabilities in the network, gain unauthorised access, and pivot into sensitive areas. Hire Writers Now!
Analyse how the post-exploitation activities such as privilege escalation or data exfiltration may have been done.

Active Directory Attack Evaluation
Highlight the impact that may have been witnessed because of Active Directory attacks on the organisation's infrastructure and user accounts.

Explain how the attackers may have gained control or manipulated the directory services.

Case Scenario
As a newly employed cybersecurity consultant, you are presented with an incident involving a medium-sized organisation. The organisation recently experienced a series of cyber incidents, and your task is to conduct a comprehensive incident analysis and propose defence strategies against various cyber-attack techniques that have impacted it.

The organisation runs an extensive network infrastructure comprising hospital patient databases, medical records, and administrative systems. The recent cyber incidents have caused disruptions in service, potential data breaches, and concerns about the integrity of patient information.

Assessment Practical Business Purpose
The incident analysis report you will generate in this assessment will equip you with the skills needed to assess, understand, analyse, and mitigate specific cybersecurity threats, which is essential for organisations aiming to strengthen their security posture.

Assessment Targeted Audience
This assessment is useful to different organisations and people including Security analysts, IT administrators, and organisations looking to enhance their security posture.

Finishing this assessment will equip you with confidence to contribute knowledge about cybersecurity incidents, threats and countermeasures for different roles in different organisations.

Learning outcome 1: Evaluate appropriate countermeasures to mitigate the risk of unauthorised access, hacks and exploits to systems, networks, and applications.

Learning outcome 2: Investigate cyber-attack techniques on computer systems, networks, and web applications.

Learning outcome 3: Evaluate existing defensive security measures.

Assessment instructions for this assessment:

Individually, you are required to analyse two cyber security incidents and the threat's potential impact on the organisation's systems, networks, and applications.

Conduct external research that will give you at least five (5) sources of information from various sources. E.g., websites, social media sites, industry reports, census data, journal articles, and newspaper articles

ChatGPT or other generative AI tools may be used for brainstorming purposes, but your conversation must be attached to your report in an appendix to show the brainstorming process. Any copying and pasting of AI text is a form of plagiarism and will be detected by Turnitin.

You can use any referencing style of your choice, but KBS's Academic Success Centre team can support you in using Kaplan Harvard Referencing.

Suggest a range of defensive security measures to prevent exploitation, enhance network monitoring and segmentation, and implement secure Active Directory configurations.

Finally, prepare a detailed and professional incident analysis report outlining the analysis of each incident technique and recommended countermeasures or proposed defensive strategies.

Present findings in a structured and clear format suitable for organisational stakeholders.

Reference no: EM133812919

Questions Cloud

Understanding employment law is crucial : Understanding employment law is crucial for both employers and employees, as it provides a framework for ensuring that workplace rights
Protracted and expensive litigation : Regarding the FOIA, do you think that the careful weighing of small pieces of information, including protracted and expensive litigation
Defendant is accused of series of child molestations : You are a member of a jury hearing a case in which the defendant is accused of a series of child molestations in his neighborhood.
Write a clear coherent and systematic presentation : POL 507- Write A clear, coherent, and systematic presentation. Adequately and fully addressing all aspects of the homework.
Network exploitation and post-exploitation assessment : Investigate the different methods that the intruders may have used to exploit vulnerabilities in the network, gain unauthorised access, and pivot
European customary law and indigenous law : Common Law (European customary Law) has distorted African Law (indigenous law).
What evidence does the author use to support their claim : What is the author's main point? What evidence does the author use to support their claim, and do you think the evidence is compelling? Why or why not?
Advent of the democratic dispensation : The notion of customary law has occupied the South African courts since the advent of the democratic dispensation
Make resume for data analyst : Prepare resume for Data Analyst - Include links directly in resume like LinkedIn ID, email, contact number and GitHub id

Reviews

Write a Review

Computer Network Security Questions & Answers

  An overview of wireless lan security - term paper

Computer Science or Information Technology deals with Wireless LAN Security. Wireless LAN Security is gaining importance in the recent times. This report talks about how vulnerable are wireless LAN networks without any security measures and also talk..

  Computer networks and security against hackers

This case study about a company named Magna International, a Canada based global supplier of automotive components, modules and systems. Along with the company analysis have been made in this assignment.

  New attack models

The Internet evolution is and is very fast and the Internet exposes the connected computers to attacks and the subsequent losses are in rise.

  Islamic Calligraphy

Islamic calligraphy or Arabic calligraphy is a primary form of art for Islamic visual expression and creativity.

  A comprehensive study about web-based email implementation

Conduct a comprehensive study about web-based email implementation in gmail. Optionally, you may use sniffer like wireshark or your choice to analyze the communication traffic.

  Retention policy and litigation hold notices

The purpose of this project is to provide you with an opportunity to create a document retention policy. You will also learn how to serve a litigation hold notice for an educational institute.

  Tools to enhance password protection

A report on Tools to enhance Password Protection.

  Analyse security procedures

Analyse security procedures

  Write a report on denial of service

Write a report on DENIAL OF SERVICE (DoS).

  Phising email

Phising email It is multipart, what are the two parts? The HTML part, is it inviting the recepient to click somewhere? What is the email proporting to do when the link is clicked?

  Express the shannon-hartley capacity theorem

Express the Shannon-Hartley capacity theorem in terms of where is the Energy/bit and is the psd of white noise.

  Modern symmetric encryption schemes

Pseudo-random generators, pseudo-random functions and pseudo-random permutations

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd