CSEC5003 Penetration Test Incident Response Summative Coursework Brief 2024-25 | DMU

Published: 24 Mar, 2025
Category Coursework Subject Computer Science
University De Montfort University Module Title CSEC5003 Penetration Test Incident Response
Title of the assessment Penetration Test and Incident Response:
Cohorts 1, 2 and 3
This coursework item is Summative

Tasks to be Undertaken:

Please read all sections of this specification carefully. This specification comprises two clearly separated parts. This coursework is to be an individual piece of work. You may NOT work with a colleague.

Part A – Penetration Test

The business manager of a local SME has requested a penetration test to be carried out against their newly developed web application, The Bodgelt Store.

Requirements

This assessment focuses on your ability to report your findings after completing a penetration test:

  • You need to complete a scan of the target web application to identify all existing vulnerabilities and misconfigurations. For each one, present a summary, including the risk level, risk matrix, and recommendation to mitigate the vulnerability.
  • You need to conduct a comprehensive exploit attempt of the vulnerabilities and misconfigurations. The authoritative exploitation and post-exploitation processes need to be replicable. You are to use any TTP allowed by scope, including existing exploits and your bespoke scripts.
  • Produce a Final Penetration Test Report based on the TTPs you used and the results of your exploitations. Provide evidence (i.e., screenshots, test outputs) of all the steps you carry out, and document the commands you use during the test.

Do You Need CSEC5003 Assignment of This Question

Order Non-Plagiarized Assignment

Scope

The scope of the penetration test is limited to the website using only ports 80 and 443. The Rules of Engagement allow to use any TTP, including existing exploits, and your own bespoke scripts. However, the use of the tool SQLmap is out of scope. Similarly, the implementation of cross-site scripting or Cross-Site Request Forgery is out of scope. Any offline attacks on the victim's Virtual Hard Disk are out of scope. Interacting with the GRUB loader on the coursework VM is out of scope. You should not look at files directly on the coursework VM, and interaction with the target should always occur through the network. Your client has also requested no cross referencing between the Executive Summary, Technical Summary, and Assessment Summary. Each of these documents should address the relevant audience, and be written using the adequate narrative. The technical summary must include a table summarising the vulnerabilities uncovered.

During the pre-engagement meetings, your client has requested using the ATT&CK matrix and risk matrices to describe each vulnerability exploited (attack.mitre.org), supporting the technical summary with an attack flow diagram, and only including recommendations from the MITRE ATT&CK framework.

You will need to download a compressed file (victim_web_app.zip) from the link provided on the Learning Zone shell. You will need VMWare Player to run both VMs, the one containing the web application and the other running Kali Linux.

You need to ascertain the IP address of the victim machine, and then access it with a browser. Point the browser from the test environment at the home page of the website in the VM. This VM contains multiple websites – you need to select The Bodgelt Store from the list.

Part B – Incident Response

Scope

Based on the findings of your penetration test, your client is now well aware of the cyber security risk posed to their operation and are thinking about setting up its own Security Operations Centre, but is unsure whether or to commit the resources required. You have been asked to provide advice on the matter and to present a business case to support your advice. You are required to provide:

  • A recommended SOC solution (internal or external) and a justification of this choice
  • Draft NIST processes AND the policies that should be implemented to support your recommended solution
  • An outline of the resources required to support your solution
  • If the architecture of The Bodgelt Store is as shown below, identify any improperly implemented features and propose improvements

CSEC5003 Penetration Test Incident Response Summative Coursework

Buy Answer of This CSEC5003 Assignment & Raise Your Grades

Request to Buy Answer

When completed you are required to submit your coursework via:

  • Report: Electronic submission on Blackboard/Turnitin

If you need any support or advice on completing this coursework please visit the Student Matters tab on the CEM Blackboard shell.

The learning outcomes that are assessed by this coursework are:

  • LO1 Produce penetration testing plans
  • LO2 Apply penetration testing techniques to identify vulnerabilities
  • LO3 Propose an appropriate response to a computer security incident

Get expert coursework help for CSEC5003 Penetration Test Incident Response from our professional team! We specialize in offering high-quality assignment help in the UK, with an option for students to pay our experts to take on their coursework challenges. Need a reference? We also provide a free list of assignment example samples to help you get started. With years of experience, our writers deliver 100% plagiarism-free content and offer unlimited revisions to meet your needs. Trust us to help you excel in your studies!

CST 3510 Windows Memory Analysis Coursework 2 Brief 2025

This piece of coursework will require you to perform an analysis of an infected memory sample acquired from a Windows operating system. In learning week 7 you will be placed into groups of five students and will be provided with an infected memory sample. Using this your group will carry out a series of tasks and answer several questions related to analysis of a specific area of the Windows operating system.

MTRN4010 Advanced Autonomous Systems Coursework Brief 2025

The course is aimed at learning basic and advanced techniques that are necessary for sensing and control of autonomous mechatronic systems. Contents covered in this course include Bayesian state estimation / Sensor data fusion, and certain relevant techniques (Dynamic Programming, Optimization, PSO).

PE7007 Construction Economics Coursework Brief SEM1 | Northumbria University

Critically analyze the key strategic technical, legal, and financial frameworks and theories underpinning construction development and procurement. Critically appraise and evaluate the tools and professional procedures used in the cost management of construction projects.

MANG3006 Management Accounting 3 Group Coursework Brief SEM2

This assignment aims to reinforce your understanding of the theoretical concepts module as applied in practice and gain essential employability skills. By applying your knowledge and skills to provide advice to the board, you will be able to experience the meaning of theoretical concepts when applied in practice and be able to advise with confidence.

5026CEM Operational Research and Simulation CW2 Assignment Brief | CU

Demonstrate understanding of the principles and techniques associated with simulation modelling and business process and logic modelling languages. Develop a working knowledge of a discrete-event simulation software package such as Simul8/ARENA.

COM745 Big Data & Infrastructure CWK Assessment Brief | Ulster University

Demonstrate a comprehensive understanding of what is meant by big data and how a variety of database/data storage paradigms may be applied to address the challenges it presents.

FY027: Preparing for Success at University: Self Development and Responsibility CW1—Portfolio

FY027 PSSR : LO1: Demonstrate effective communication skills, applicable to academic and professional contexts, LO3: Identify own academic and professional development needs and create an action plan.

CE6012 Sustainable Infrastructure and Environment Coursework Assessment Brief - KUL

CE6012: The aim of the coursework is to analyse an existing T junction (Intersection of Brighton Road/Victoria Road in Surbiton, Surrey) and propose a new design which would accommodate an increased traffic.

402LEG CW1 Criminal Law and Mooting  Assignment Brief

[Solved] Assignment Task, You are to assume that you are a newly qualified solicitor, employed by a busy Crown Court team of a renowned criminal defence firm.

6002CEM CW2 Mobile App Development Assignment Brief | CU

6002CEM CW2 Assignment Brief: You are required to design and build a .NET Maui app that demonstrates your proficiency in the skills that have been taught during the module.

Online Assignment Help in UK