Highlights
Assessment questions and tasks
Your task, as a group of 2 or 3 people, is to redesign the network security infrastructure for Spyon Technologies so that it meets the business requirements for the organization and to write a detailed proposal which you will submit to Spyon Technologies for consideration.
To complete this task, you will submit a final design proposal to Spyon Technologies which will include:
•a detailed list of business requirements that must be met by the network security design
•a complete and detailed discussion of the network security design proposal. This must include complete logical diagrams of the redesigned network and a discussion of the techniques and technologies used, e.g. Clustering, zones, policies, authentication, encryption, and VPN's
•details of how the network security design will meet all the business requirements
Scenario
You are employed by Spyon Technologies, a global business that manufactures weapons and military technology and equipment. You work in the cybersecurity division as a network engineer. Your role is to assist with the planning and implementation of security measures and general network infrastructure.
Company profile
Spyon Technologies is a global security and aerospace company that employs about 120,000 people worldwide and is principally engaged in the research, design, development, manufacture, integration, and sustainment of advanced technology systems, products, and services. The Corporation's sales from continuing operations are $46.5 billion P/A.
The company's primary business is in supplying military equipment to Governments around the world.
The FDDI and DSL WAN connections are provided by a commercial telecommunications carrier.
Question 1
a. Would you describe Spyon Technologies security requirements as high, medium, or low? Why?
b. What types of security measures would you use to address each of the security requirements listed?
Question 2
Spyon Technologies has adopted the following risk evaluation criteria using a qualitative risk assessment methodology.
In order to calculate the risk level for each risk that is to be examined, it is necessary to calculate the impact of the threat occurring and the likelihood (or probability) of the threat occurring.
Question 3
Design the firewall configuration. Ref: How to Design a Secure DMZ
Your design should include the following:
1. The name of each security zone you will create
2.The inter-zone policy objectives including
a. Traffic allowed into the zone
b. Traffic allowed between the zones
c. Other security measures to be implemented in the policy
3.Method of securing traffic from site to site
4.Method of securing traffic to and from the public internet
Question 4
Write the Juniper SRX configuration required to implement all the functionality described in your answer above. You may refer to the SRX lab configurations. You will need to provide your IP addressing scheme as a separate table.
Question 5
Design failover redundancy for the firewall so that a stateful failover of processes and services will occur in the event of system or hardware failure. Provide a diagram of your design and a description of how failover will be achieved in the event of a failure.
Question 6
Provide a typical failover redundancy configuration for a Juniper SRX firewall.
Question 7
Provide a typical site to site VPN configuration for a Juniper SRX firewall.
Question 8
Is the network traffic traversing the IPSEC VPN encrypted using symmetric or asymmetric encryption? Explain the difference between these 2 methods. Compare 3 algorithms that could be used to encrypt the IPSEC VPN traffic. List the tests you will perform to verify that your security measures and VPN are functioning as expected.
Question 9
You want to encrypt email communications between all company staff and business associates. What program could you use to do this? What are the advantages of this program? What type of encryption would be used? What encryption algorithms could be used?
Question 10
You want to ensure the integrity of email and other digital communication. How can this be achieved? What algorithms could be used?
Question 11
What authentication processes could you use to verify the identity of the person from who you are receiving email and other digital communication and to verify your identity to people you are sending communications to? What algorithms could be used?
Question 12
Evaluate the following providers of digital certificates and create a comparison table. The table should compare the cost and advantages of the certificate services offered by each.
•Thawte
•Go, Daddy
•Comodo
•GlobalSign
•GeoTrust
•Symantec
Question 14
Provide a brief summary of Kerberos and NTLM Authentication. Describe the benefits of Kerberos Authentication. Ref: Module 10_ Securing Windows(r) 8
Question 15
Provide a brief summary of Biometrics for Authentication. Describe the benefits of using Biometrics for Authentication. List 3 devices you could use to provide Biometric Authentication? Ref: Module 10_ Securing Windows(r) 8
Question 16
Explain the concept of digital certificates and how they work including:
The relationship between user certificates and root certificates and the function of root certificates
•The role of Certificate Authorities
•The role of Registration Authorities
•The function of a digital certificate repository
Question 17
What are the factors that contribute to encryption strength?
Question 18
You are reviewing help desk records and discover that emails to some recipients are not able to be encrypted while emails to other recipients are. What is the cause of this and how could it be resolved?
Question 19
Explain what a replay attack is and describe 2 methods of protection. Ref: https://www.kaspersky.com/resource-center/definitions/replay-attack
Question 20
Describe 5 security threats that can be caused by issues within the organization. Ref: https://www.zdnet.com/article/the-top-five-internal-security-threats/
Question 21
Explain the difference between WEP, WPA, and WPA2.
Question 22
Explain authentication, authorization, and accounting (AAA). Your explanation should include the functions of a RADIUS server and it role in the resource accounting process.
Question 23
Describe the function and operation of both IPSEC and MPLS VPNs. Compare these 2 technologies in terms of their ability to provide QoS, guaranteed bandwidth, and changing security requirements like the need for secure voice or video. Ref: https://community.fs.com/blog/vpn-vs-mpls-difference.html
Question 24
Describe and compare CHAP and PAP authentication protocols.
Question 25
Write your proposal to Spyon Technologies.
Submission requirements
1. The written tasks must be completed on a word processor and uploaded to the learning portal. You must clearly indicate which question each answer relates to.
2. Device configurations should be included as separate files which are clearly named.
3. The Visio diagram should be saved as a pdf and uploaded.
4. All files must have your name in the file name.
5. You must click the 'Submit' button
This Business Assignment has been solved by our Business Experts at My Uni Paper. Our Assignment Writing Experts are efficient to provide a fresh solution to this question. We are serving more than 10000+ Students in Australia, UK & US by helping them to score HD in their academics. Our experts are well trained to follow all marking rubrics & referencing style.
Be it a used or new solution, the quality of the work submitted by our assignment experts remains unhampered. You may continue to expect the same or even better quality with the used and new assignment solution files respectively. There’s one thing to be noticed that you could choose one between the two and acquire an HD either way. You could choose a new assignment solution file to get yourself an exclusive, plagiarism (with free Turnitin file), expert quality assignment or order an old solution file that was considered worthy of the highest distinction.
© Copyright 2026 My Uni Papers – Student Hustle Made Hassle Free. All rights reserved.