CSEC5003 Penetration Test Incident Response Summative Coursework Brief 2024-25 | DMU

Published: 24 Mar, 2025
Category Coursework Subject Computer Science
University De Montfort University Module Title CSEC5003 Penetration Test Incident Response
Title of the assessment Penetration Test and Incident Response:
Cohorts 1, 2 and 3
This coursework item is Summative

Tasks to be Undertaken:

Please read all sections of this specification carefully. This specification comprises two clearly separated parts. This coursework is to be an individual piece of work. You may NOT work with a colleague.

Part A – Penetration Test

The business manager of a local SME has requested a penetration test to be carried out against their newly developed web application, The Bodgelt Store.

Requirements

This assessment focuses on your ability to report your findings after completing a penetration test:

  • You need to complete a scan of the target web application to identify all existing vulnerabilities and misconfigurations. For each one, present a summary, including the risk level, risk matrix, and recommendation to mitigate the vulnerability.
  • You need to conduct a comprehensive exploit attempt of the vulnerabilities and misconfigurations. The authoritative exploitation and post-exploitation processes need to be replicable. You are to use any TTP allowed by scope, including existing exploits and your bespoke scripts.
  • Produce a Final Penetration Test Report based on the TTPs you used and the results of your exploitations. Provide evidence (i.e., screenshots, test outputs) of all the steps you carry out, and document the commands you use during the test.

Do You Need CSEC5003 Assignment of This Question

Order Non-Plagiarized Assignment

Scope

The scope of the penetration test is limited to the website using only ports 80 and 443. The Rules of Engagement allow to use any TTP, including existing exploits, and your own bespoke scripts. However, the use of the tool SQLmap is out of scope. Similarly, the implementation of cross-site scripting or Cross-Site Request Forgery is out of scope. Any offline attacks on the victim's Virtual Hard Disk are out of scope. Interacting with the GRUB loader on the coursework VM is out of scope. You should not look at files directly on the coursework VM, and interaction with the target should always occur through the network. Your client has also requested no cross referencing between the Executive Summary, Technical Summary, and Assessment Summary. Each of these documents should address the relevant audience, and be written using the adequate narrative. The technical summary must include a table summarising the vulnerabilities uncovered.

During the pre-engagement meetings, your client has requested using the ATT&CK matrix and risk matrices to describe each vulnerability exploited (attack.mitre.org), supporting the technical summary with an attack flow diagram, and only including recommendations from the MITRE ATT&CK framework.

You will need to download a compressed file (victim_web_app.zip) from the link provided on the Learning Zone shell. You will need VMWare Player to run both VMs, the one containing the web application and the other running Kali Linux.

You need to ascertain the IP address of the victim machine, and then access it with a browser. Point the browser from the test environment at the home page of the website in the VM. This VM contains multiple websites – you need to select The Bodgelt Store from the list.

Part B – Incident Response

Scope

Based on the findings of your penetration test, your client is now well aware of the cyber security risk posed to their operation and are thinking about setting up its own Security Operations Centre, but is unsure whether or to commit the resources required. You have been asked to provide advice on the matter and to present a business case to support your advice. You are required to provide:

  • A recommended SOC solution (internal or external) and a justification of this choice
  • Draft NIST processes AND the policies that should be implemented to support your recommended solution
  • An outline of the resources required to support your solution
  • If the architecture of The Bodgelt Store is as shown below, identify any improperly implemented features and propose improvements

CSEC5003 Penetration Test Incident Response Summative Coursework

Buy Answer of This CSEC5003 Assignment & Raise Your Grades

Request to Buy Answer

When completed you are required to submit your coursework via:

  • Report: Electronic submission on Blackboard/Turnitin

If you need any support or advice on completing this coursework please visit the Student Matters tab on the CEM Blackboard shell.

The learning outcomes that are assessed by this coursework are:

  • LO1 Produce penetration testing plans
  • LO2 Apply penetration testing techniques to identify vulnerabilities
  • LO3 Propose an appropriate response to a computer security incident

Get expert coursework help for CSEC5003 Penetration Test Incident Response from our professional team! We specialize in offering high-quality assignment help in the UK, with an option for students to pay our experts to take on their coursework challenges. Need a reference? We also provide a free list of assignment example samples to help you get started. With years of experience, our writers deliver 100% plagiarism-free content and offer unlimited revisions to meet your needs. Trust us to help you excel in your studies!

Health Project Management Coursework Brief 2025 | Arden University

Health Project Management: Identify an area of practice from your review of the evidence that needs to change and is potentially within your power to influence.

MN-M534 Business Analytics Assignment 2 Coursework Brief | Swansea University

The second assignment follows on from the data analysis conducted in assignment 1 and will focus more specifically on presenting the data in a coherent report that conveys the meaning of the results you have provided.

BE562-7-SP Marketing & Innovation Coursework 2 Brief | UoE

For this coursework, you should assume the role of the director of marketing and sales. You are asked to develop a marketing strategy plan that is focused on your business’s innovative strengths and ultimately results in sustainable competitive advantage (SCA).

BE555 Consumer Behaviour Coursework 2 Brief | UoE

This coursework is a continuation of coursework 1, where you have developed journal entries by reflecting on your three personal consumption patterns and experiences. For this coursework, you must choose a single entry from your introspective diary from coursework

Analysis and Design of a Steel Frame Structure Using Computer Applications Coursework2 Brief

A clear space must be provided within the performance area of the theatre, bounded by gridlines 1 and 3 and gridlines B and C. No permanent structure may be provided in this space. At either end of the theatre space, there is a service zone where there are no structural restrictions.

Level 7 Knowledge Transfer Coursework Assessment Brief | Bournemouth University

Knowledge Transfer: The literature relating to organisational structure, how this affects knowledge transfer, and the layout of organisational facilities on the quality of ideas generation. The literature covering design protection across the globe.

MAN5066 Venue Operations and Supply Chain Management Coursework Brief | BCU

To stop you panicking about your coursework To remind you how to reference correctly To ensure you know how to format a professional report with style

FY026 Preparing for Success at University: Knowledge and Creativity Assignment Brief

Assignment Task of FY026: Write a reflective journal of 1000 words on your experience during Preparing for Success at University: Knowledge and Creativity (PSKC) module.

SBU300 Academic and Personal Development L3 Coursework Assessment Brief | SU

You will also complete formative assessment tasks, which do not count towards your grade. They are designed to help you learn and will assist you towards completion of the summative assessment

7IR002 Research Design and Practice Coursework 01 Research Proposal | University of Wolverhampton

A research proposal is a comprehensive document that outlines the planned research study, providing a detailed and structured overview of the research project.

Online Assignment Help in UK