Management overview, risk assessment, methodology and vulnerability reporting
A good report should typically answer questions and provide the following information:
Summary
Reports should be targeted at both CEOs who want a high-level overview and technical teams who want to know about specific vulnerabilities found. The summary includes an assessment of the risks facing the organization, clear risk priorities, and other relevant information that we believe the organization should be aware of, as well as how management should address the findings. It should contain clear recommendations. handle. Risk assessment
A recognized risk assessment system should be used to assess vulnerabilities. Regardless of which risk assessment system is used, it is necessary to define impact and abuse criteria, the number of levels and their meaning. For example, if you use CVSSv3 as your scoring matrix, you should clearly explain the differences between low-risk, medium-risk, and high-risk scoring systems.
Methodology (30 points)
We describe the methodology used for each of the two (web/architecture) tests. For each step of the methodology, we explain:
Vulnerability report (50 points)
This section of the report contains a description of the vulnerabilities found.
(a) System vulnerability test (45 points)
You must identify, test, and report vulnerabilities in any of your customer’s systems.
Eventually you will need to gain “root” access to your system. Points are awarded for every valid step taken to reach this point. Penetration Test 05 Machines are rated as moderate or hard and provide a penetration test report.
The report must include a description of any network configuration changes that may help resolve the vulnerability.
(b) Network configuration (5 points)
The report must include a description of any network configuration changes that may help resolve the vulnerability. Firewall rules should be recommended to reduce the risk of exploitation. You must use IPTables to create all recommended rules. Even if you select Windows computers in this section, you still need to create IPTable rules to reduce the risk of exploitation. Windows machines do not use IPTable rules for filtering, so you can use the Linux-based calculator used in the tutorial to create these rules.
Select your paper details and see how much our professional writing services will cost.
Our custom human-written papers from top essay writers are always free from plagiarism.
Your data and payment info stay secured every time you get our help from an essay writer.
Your money is safe with us. If your plans change, you can get it sent back to your card.
We offer more than just hand-crafted papers customized for you. Here are more of our greatest perks.
Get instant answers to the questions that students ask most often.
See full FAQ