Reference no: EM134035936 , Length: 10 min PPT
Penetration Testing, Penetration Testing Simulation Video Entry
Individual Video Recording Demonstrating a Simulated Penetration
Task
This assessment must be completed individually. Students are required to keep their video on and share their screen throughout the session so that all penetration testing activities are recorded. Pre-recorded penetration testing activities with voiceover are not acceptable for this assessment.
In this assessment, you are tasked with conducting penetration testing of an organisation's IT environment. The objective is to identify and exploit cybersecurity vulnerabilities using a simulated network for the organisation, replicating a real-world scenario. This assessment will cover the fundamental concepts learned in the initial weeks of the subject, focusing on reconnaissance, vulnerability assessments, and footprinting.
Assessment Description
The objective is to assess your practical skills in identifying, analysing, exploiting, documenting, and reporting cyber-attack vulnerabilities, focusing on the content covered in Weeks 1 to 3. This will include the following:
Reconnaissance and Information Gathering
Footprinting and Enumeration
Vulnerability Assessment
Demonstration of Exploitation
In this assessment:
You will simulate a penetration testing exercise using tools and systems relevant to penetration testing in a controlled lab environment that simulates a computer system, network, or web application.
Submit a video recording of the simulated penetration testing exercise.
The simulated exercise will include tasks related to:
Utilising Kali Linux and penetration testing tools to perform the simulated penetration testing scenario.
Conducting Reconnaissance and vulnerability assessments using Kali Linux tools.
Pick only ONE vulnerability based on your vulnerability assessment, exploit the vulnerability, and show the methods and strategies used.
Provide recommended Mitigation measures based on concepts learned from Week 1 to Week 3.
Target System
The simulation will involve a fictional corporate network comprising servers, databases, and web applications. The network is structured with various departments interconnected through a centralised server architecture. This practical work relates closely to Data Communication And Networking concepts.
Assessment Practical Business Purpose
This assessment is designed to equip you with basic practical penetration testing skills which are essential for securing organisations' digital assets and infrastructure.
The assessment aligns with real-world scenarios where penetration testers are tasked with identifying and exploiting vulnerabilities to strengthen an organisation's security posture.
This assessment therefore prepares you for cybersecurity roles that require you to proactively identify, exploit and mitigate security vulnerabilities in different organisations.
Assessment Targeted Audience
This assessment is useful for any aspiring penetration tester, cybersecurity professionals, and organisations looking to strengthen their security teams by hiring individuals with hands-on penetration testing experience.
Doing this assessment will equip you with the necessary hands-on penetration testing experience needed to contribute positively to different roles in different organisations.
This assessment aims to achieve the following subject learning outcomes:
LO1 Evaluate appropriate countermeasures to mitigate the risk of unauthorised access, hacks and exploits to systems, networks, and applications.
LO2 Investigate cyber-attack techniques on computer systems, networks, and web applications.
LO3 Evaluate existing defensive security measures.
Assessment Instructions
Assessment instructions for this assessment:
You are supposed to work individually on this assignment.
You are required to keep your video on and share your screen throughout the session so that all penetration testing activities are recorded. Pre-recorded penetration testing activities with voiceover are not acceptable for this assessment.
You are to perform a simulated penetration testing exercise as described in the assessment description.
Identify only one vulnerability, which may include open ports and potential weak points in the simulated network that you can exploit using Kali Linux tools. You should then record a video to show how you identified and exploited the vulnerability. The video should also show the tools used to identify and exploit the vulnerability.
Briefly explain the potential risks and impact on the organisation network based on the chosen vulnerability.
Include in the video a visual aid (Diagram) to support your submission and any other claims.
Conclude the video by showcasing your recommendations and mitigation strategies. Further context for the underlying IT environment can be found through Information Technology And System topics.