Describe the legal requirements and ethical issues

Assignment Help Basic Computer Science
Reference no: EM13540395

Question:

As a penetration tester, you are hired as a consultant by a small- to mid-sized business that is interested in calculating its overall security risk today, January 1, 2012. The business specializes in providing private loans to college students. This business uses both an e-Commerce site and point-of-sales devices (credit card swipes) to collect payment. Also, there exist a number of file transfer operations where sensitive and confidential data is transferred to and from several external partnering companies. The typical volume of payment transactions totals is approximately $100 million. You decide that the risk assessments are to take into account the entire network of workstations, VoIP phone sets, servers, routers, switches and other networking gear. During your interview with one of the business's IT staff members, you are told that many external vendors want to sell security networking products and software solutions. The staff member also claimed that their network was too "flat." During the initial onsite visit, you captured the following pertinent data to use in creation of the Penetration Test Plan.

Non-stateful packet firewall separates the business's internal network from its DMZ.

All departments--including Finance, Marketing, Development, and IT--connect into the same enterprise switch and are therefore on the same LAN. Senior management (CEO, CIO, President, etc.) and the Help Desk are not on that LAN; they are connected via a common Ethernet hub and then to the switched LAN.

All of the workstations used by employees are either Windows 98 or Windows XP. None of the workstations have service packs or updates beyond service pack one.

Two (2) Web servers containing customer portals for logging in and ordering products exist on the DMZ running Windows 2000 Server SP1, and IIS v5.

One (1) internal server containing Active Directory (AD) services to authenticate users, a DB where all data for the company is stored (i.e. HR, financial, product design, customer, transactions). The AD server is using LM instead of NTLM.

Write a six to eight (6-8) page paper in which you:

Explain the tests you would run and the reason(s) for running them (e.g. to support the risk assessment plan).

Determine the expected results from tests and research based on the specific informational details provided. (i.e., IIS v5, Windows Server 2000, AD server not using NTLM)

Analyze the software tools you would use for your investigation and reasons for choosing them.

Describe the legal requirements and ethical issues involved.

Using Visio or its open source alternative, provide a diagram of how you would redesign this business' network. Include a description of your drawing. Note: The graphically depicted solution is not included in the required page length.

Propose your final recommendations and reporting. Explain what risks exist and ways to either eliminate or reduce the risk.

Use at least three (3) quality resources in this assignment. Note: Wikipedia and similar Websites do not qualify as quality resources.

The specific course learning outcomes associated with this assignment are:

Perform vulnerability analysis as well as external and internal penetration testing.

Demonstrate the ability to describe and perform penetration tests on communication media to include wireless networks, VoIPs, VPNs, Bluetooth and handheld devices.

Use technology and information resources to research issues in penetration testing tools and techniques.

Write clearly and concisely about Network Penetration Testing topics using proper writing mechanics and technical style conventions.

Verified Expert

Reference no: EM13540395

Questions Cloud

Compute the radiation pressure on the mirror : A23.0-mW laser beam of diameter1.85mm is reflected at normal incidence by a perfectly reflecting mirror. Calculate the radiation pressure on the mirror
What is the maximum value of the distance : A uniform plank of length 4.00 m and weight 350 N rests horizontally on two supports, with 1.00 m of the plank hanging over the right support. What is the maximum value of the distance x before the plank begins to tip
Explain the chemical equation must dehydration of water : When the sample is ready to boil, the beaker is removed and the reaction is allowed to settle for a moment. What reaction has taken place. Provide the chemical equation. Since the reaction involves concentrated acid, then it must dehydration of wa..
Find the vertical velocity of the projectile launched : A projectile is launched on an unnamed planet. The projectiles vertical position is y(t)= -5t^2 + 15t +50, find the vertical velocity of the projectile launched
Describe the legal requirements and ethical issues : Determine the expected results from tests and research based on the specific informational details provided and describe the legal requirements and ethical issues involved
What is the buoyant force that acts on the ship : What weight of water is displaced by a 100-ton floating ship? What is the buoyant force that acts on the ship
Obtain what is the voltage across the capacitor : A 9500-pF capacitor holds plus and minus charges of 16.5 x 10^-8. What is the voltage across the capacitor
Explain strength of intermolecular forces of h2o : Arrange the following substances in order of increasing strength of intermolecular forces: H2O, He, I2, and N2.
Evaluate how fast will the electron be moving : An electron starts from rest 32.5 cm from a fixed point charge with Q=-0.125 µC. How fast will the electron be moving when it is very far away

Reviews

Write a Review

Basic Computer Science Questions & Answers

  The assignment has been designed

The assignment has been designed to assess students' understanding of the usage of data communications and computer networking technologies in real life and to demonstrate their engagement with the subject.

  Describe in 200 to 300 words at least two different ways to

explain in 200 to 300 words at least two different ways to secure a wlan. what are the ramifications if a wlan is

  Differentiate computer data state of computer-s electrical

Differentiate between computer data represented by the state of a computer's electrical switches and the meaningful information that is displayed to the user.

  Create a stored procedure

The procedure must insert the next of kin information into the Next of kin table by looking up the student id from the Student table. (will you need a schema? how do I send it to you?) can you use just the tables for the student and next of kin?

  Write a menu driven program

At least the menu, finding the smallest number and calculating the sum are to be functions. Provide an error message if an invalid choice is entered.

  How many entries are there in each of the following

The BTV operating system has a 21-bit virtual address, yet on certain embedded devices, it has only a 16-bit physical address. It also has a 2-KB page size. How many entries are there in each of the following?

  Find pythagorean triplets

Given an array of integers, find Pythagorean triplets. i.e. find a,b and c which satisfies a^2 + b^2 = c^2 Integers could be positive or negative.

  Assume that the input to each statement is the same

Assume that the input to each statement is the same: 5 28 36 a. cin >> x >> y >> ch; b. cin >> ch >> x >> y; c. cin >> x >> ch >> y; d. cin >> x >> y; cin.get(ch);

  Excavated material to the structural fill location

How many dump truck loads, given a dump truck with 18 LCY capacity, will be required for hauling the excavated material to the structural fill location?

  Diversity of approaches

Diversity of Approaches

  Design and code a project to calculate the amount due

Design and code a project to calculate the amount due for rentals. Movies may be in VHS(videotape) format or DVD format. Videotapes rent for $1.80 each and DVDs rent for $2.50.

  How could a business use information technology

How could a business use information technology to increase switching costs and lock in its customers and suppliers? Use business examples to support your answers

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd