Vulnerability and Penetration Testing (VAPT) Assessment

Download Solution Order New Solution

Assignment Task

Introduction

Regular penetration testing is essential to help identify and eliminate gaps in security defences. This assignment is the simulation of a company that is new to penetration testing. The company (NewBizz Ltd) we are simulating does not have a great deal of experience in cyber security. The manager and senior manager are keen to understand how secure their system is.  The management team intend to share this report with software developers, SOC analysts and the IT manager. Only the senior management team is aware that the penetration testing is ongoing. As a penetration tester, you are authorised to perform a full exploitation of the network.  

Tasks to perform during the technical testing  

  1. Appraise the security posture of a network by analysing the network configuration and application security using appropriate tools where necessary. 
  2. Critically evaluate the configuration of network security devices to achieve a desired security posture recommending adjustments where appropriate. 
  3. Critically evaluate the security posture of web applications to achieve a desired security posture recommending adjustments where appropriate. 
  4. Demonstrate a comprehensive understanding of vulnerability exploitation techniques. 
  5. Assess the results of system security tests and recommend appropriate mitigation strategies – which may include possible design and configuration changes.  

Presentation and Reporting 

  • The report should demonstrate that you understand how to plan, prepare and execute a report.  
  • You should prepare a report that is suitable for all the audience as described in the general description of the penetration test (i.e., consider the technical and non-technical audience)  

You will not receive marks for presentation; however, your submission will be explicitly penalised for presentation errors. Your submission must be professionally presented and must follow a consistent formatting/presentation scheme. Ensure that you follow the guidance outlined below. This guidance is not intended to be conclusive.  

The PMA should be presented as a typical penetration testing report with the following recommended sections. You are free to deviate from this plan if the objectives are specified below are reached. 

Executive report  

Executive summary that presents the risk evaluation of the entire estate in a language that speaks to the senior executive. This executive summary should be the trigger to policy changes. You will also present and discuss the high-level outcomes in which you will present summary of findings based on their level of risk severity. The executive summary should clearly present any risk associated with inability to meet regulations such as GDPR and any other regulation that applies to the business sector in which the client operates. You should also discuss prioritised recommendation based on areas of concerns. The objective of this section is to empower senior management to drive strategic change in the way they handle and manage the risk of their organisation.  

Scope and methodology 

The scope of the penetration testing should be clearly defined to indicate what systems were subject to testing and the type of tests were performed. These methodologies should be agreed beforehand with the client. In this section, you will also specify which tools were used and their usage during the penetration testing. The overall methodology should be clearly explained so that management and technical teams are clear on what methods were used during the penetration testing. The objective of this section is to help the management and the technical teams to acquire the tools, when possible, to reproduce selected tests when needed and where possible, in order to reach the best possible remediation.  

Test details 

This section should clearly provide a comprehensive demonstration on how all tests were performed. The tests should be grouped by similarities, when possible, to avoid unnecessary repetitions. After a clear demonstration of the test performed for each vulnerability (please note that this is not a tutorial exercise), the report should present the risk of the given vulnerability, it’s impact on the overall security of the estate under penetration testing, remediation recommendation with appropriate references. The references can be given as links, as endnotes. The objective of this section is twofold. Firstly, to provide technical details that will allow the technical team to fully understand the specific commands used to exploit any weakness. The technical team should be able to reproduce the attack providing that they have the system build for it, as described in the ‘scope and methodology’ section. Secondly, to provide easy to understand remediation instructions to allow the technical team to improve the security posture of the estate. These changes will, of course, a consequence of the strategic direction set by the senior management.  

Conclusion

The conclusion should present a summary of the technical finding but more so, a summary of the remediations. The remediations should be organised by priorities. It is acceptable to limit the remediation to the top 10 priorities. These priorities should be justified.  The objective of this section is to present a summary of what was achieved and specially to provide for manager and technical teams a quick access to the list of prioritised remediations.

This IT Computers Science has been solved by our PhD Experts at My Uni Paper.

Get It Done! Today

Country
Applicable Time Zone is AEST [Sydney, NSW] (GMT+11)
+

Every Assignment. Every Solution. Instantly. Deadline Ahead? Grab Your Sample Now.