A Penetration Tester evaluates the security of an information infrastructure by intentionally, and safely, exploiting vulnerabilities. Take on the role of Penetration Tester for the organization you


CMGT 400 Grading Rubric Individual – Week 2 Penetration Testing Plan
MEETS CRITERIA?

Penetration Testing Plan

PTs

Grade

COMMENTS

Content (10 points)

Take on the role of Penetration Tester for the organization you chose in Week 1. Use the Penetration Testing Plan Template to create a 3- to 4-page Penetration Testing Plan for the organization you chose.

10

Research and include the following:

  • Pentest Pre-Planning (20pts)

    • Engagement timeline: Tasks and who performs them

    • Team location: Where will the penetration team execute their tests?

    • Organization locations tested: multiple locations, countries (Export restrictions and government restrictions)

    • Which pentest technologies will be used? Consider the following as you research options:

      • Scanning Tools: Nmap, Nikto

      • Credential Testing Tools: Hashcat, Medussa, John the Ripper, Cain and Abel

      • OSINT Tools: Whois, TheHarvester

      • Wireless Tools: Aircrack-ng, Kismet

      • Networking Tools: Wireshark, Hping

    • What client personal are aware of the testing?

    • What resources provided to pentest team?

    • Test Boundaries:

      • What is tested?

      • Social engineering test boundaries? What is acceptable?

      • What are the boundaries of physical security tests?

      • What are the restrictions on invasive pentest attacks?

      • What types of corporate policy affect your test?

    • Gain Appropriate authorization (Including third-party authorization)

  • Pentest Execution Planning: Given the scope and constraints you developed in your Pentest Pre-Plan, plan the following pentest execution activities (20pts)

    • Reconnaissance

    • Scanning

    • Gaining Access

    • Maintaining Access

    • Covering Tracks

  • Pentest Analysis and Report Planning: (20pts)

    • Analyze pentest results

    • Report pentest results 

60

X out of 70

Research

Assignment has research depth including at least two outside relevant peer reviewed references from course material and/or the library.

10

Organization

Assignment is organized appropriately covering all required topics in a logical sequence and applies the Penetration Test Template. Title, introduction, body, conclusion and references are included in required sequence.

10

Quality and APA:

Assignment projects professional, quality image, meets academic integrity requirements. Includes Power Point and MS Word document required by the assignment in APA format with label. Include title page and reference section. References in APA format. No spelling errors - the paper has obviously been proofread. Title and reference slides/pages do not count toward the length requirement.

10

TOTAL POINTS FOR RESEARCH, ORGANIZATION, QUALITY, AND APA REQUIREMENTS

X out of 30

TOTAL POINTS

(X out of 100 possible points) 04-28-19 rpg