Develop a test plan for the penetration test

Assignment Help Other Subject
Reference no: EM131406471

Problem -

You are hired as part of a team of external Penetration Testers to work for a company with a large enterprise network. The organization that hired your team is in the retail industry and processes over 100,000 credit card transactions everyday across 100 store locations. This organization has a very large network infrastructure that connects their retail stores, business offices, and company headquarters. The Chief Information Security Officer (CISO) would like your team to focus on their most critical systems and devices.

Prior to executing the penetration test, the CISO would like to meet with the team as they are nervous about the test potentially bringing their network down. They would like to minimize impacts to their production environment and ensure that their backup systems and devices are not targeted at the same time. They want you to focus on the following: DNS servers, mail servers, web servers, database servers, firewalls, and routers.

Your Team Lead would like you to develop a Test Plan for the penetration test. The Test Plan should be developed using the following outline:

Sections:

1. Introduction

2. Overview of technical approach to conducting the test (high level methodology)

3. Detailed penetration testing (hacking) process

Note: Section 3 should include 1) attacks you will use, 2) tools, 3) timeline (you only have one week), 4) reporting methods if major issues occur or if you identify incidents in their environment. You may make these as sub-sections if you'd like (e.g., 3.1 Attacks Used, 3.2 Tools Used, etc.)

4. Summary

Note: This section should be short, a paragraph or two.

Penetration Test Plan:

You are facing a client who is nervous about you basically "hacking" their system, this is the scenario, and while you cannot dictate exactly what will happen once the testing actually begins you should be able to formulate a good plan of action.

All you are doing here is providing your plan of action, indicating what you believe are possible good tests to complete based off of your current knowledge. Of course as you progress with the actual testing it is possible you could remove or add to your steps.

In the real world no one is going to just give access to their network, they will want to know what you plan and to know what your backup plans are if things go wrong.

This case study is just to provide you an opportunity to explain what you would do in a situation similar to this one, where a client is asking you to provide guidance and potentially solutions. You are not predicting what will happen, so much as providing courses of action.

Reference no: EM131406471

Questions Cloud

Define legal and criminal issues related to data breach : What is data breach. Define legal and criminal issues related to data breach? What are the plan to protect data breach?
How much does diversification reduce the var : What is the 10-day 97.5% value at risk for the portfolio? By how much does diversification reduce the VaR?
Purposes of routing data through interconnection : (1) An address that identifies both a network and a host for the purposes of routing data through interconnection of networks is?
Explain why communication is essential in an organization : Explain why communication is essential in an organization and explain the ways that effective communication improves employee trust and engagement. Focus on comparing/contrasting two types of channels or techniques
Develop a test plan for the penetration test : You are hired as part of a team of external Penetration Testers to work for a company with a large enterprise network. Your Team Lead would like you to develop a Test Plan for the penetration test
How can buffer-overflow attacks be avoided : Research and discuss the principle of exploits based on buffer-overflow attacks.How can buffer-overflow attacks be avoided?
Write to your professor asking them to write a letter : Write to your professor asking them to write a letter on your behalf. Make sure you include all the information your professor will need in order to write you the best reference possible.
Four bytes of the message integrity check : What are the first four bytes of the Message Integrity Check (MIC) in the AP's first packet of the authentication handshake?
What is the volatility of the ft-se 100 : Assume that the dollar/sterling exchange rate is expressed as the number of U.S. dollars per pound sterling. (Hint: When Z = XY, the percentage daily change in T. is approximately equal to the percentage daily change in X plus the percentage daily..

Reviews

len1406471

2/27/2017 3:49:02 AM

Your submission should be 4 to 6 pages long (not including the title page and the reference page) All sections are represented (Sections 1.0 - 4.0). Utilized correct grammar and spelling. In APA format with proper citations and references. In Times New Roman or Arial font, font size 12. Include and cite references as needed. This case study is just to provide you an opportunity to explain what you would do in a situation similar to this one, where a client is asking you to provide guidance and potentially solutions. You are not predicting what will happen, so much as providing courses of action.

Write a Review

Other Subject Questions & Answers

  Analyze whether ethel an intended beneficiary of contract

Analyze whether Ethel an intended beneficiary of the contract? You must explain who or what is an intended beneficiary in your analysis.

  End of the progressive era in the early 1900s

Create a timeline tracking the major themes/paradigm shifts in American history from the development of Sectionalism in the early 1800s through the end of the Progressive Era in the early 1900s.

  How does this loss affect their adjustment to america

In Chapter Eight, after describing Foua's competence as a mother and farmer in Laos, Fadiman quotes her as saying, "I miss having something that really belongs to me." What has Foua lost? Is there anything that still "really belongs" to her? Are t..

  The norms, values and assets that particular event creats

Explain the norms, values and assets that this particular event creates and perpetuates for the community.

  What conclusions can you draw about the countries

What did the conference fail to do for persecuted European Jews. What conclusions can you draw about the 32 countries represented at the conference. Despite the conference's many failures what was its one big accomplishment

  Explain community health interventions or public policy

Select one of these populations (senior citizens, disabled, or children) and write at least two possible health concerns for that population.

  What are some of the implications of fukuyamas view

What are some of the implications of Fukuyama's view that history has ended?

  Schedule and cost variances for a project

Find the schedule and cost variances for a project that has an actual cost at month 22 of $540,000, a scheduled cost of $523,000, and an earned value of $535,000. What is your overall interpretation of this result?

  Develop a conceptual model by outlining

Write a consultancy report about your study considering all of the steps listed below in the given order - The two arrival processes and the service delays have to be modelled stochastically. The model has to provide graphical output for at least o..

  Examine various vendors that sell ehrs in the united states

Your selection recommendation will require you to examine various vendors that sell EHRs in the United States and to select the vendor that you feel will best suit the needs of Yorkshire Clinic.

  How modern liberalism varies from classical liberalism

So who would like to explain how modern liberalism varies from classical liberalism? In addition, in what ways is classical liberalism similar to conservatism today

  Memory-thinking-intelligence

Explain other kinds of forgetting and discuss some strategies that can improve memory consolidation and/or retrieval.

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd