Answered step by step
Verified Expert Solution
Link Copied!

Question

1 Approved Answer

Please answer the highlighted questions. They are from my Penetration Testing class. Thank you! Activity 1-2 Scenario After being evaluated by multiple prospective clients, your

image text in transcribed

Please answer the highlighted questions. They are from my Penetration Testing class. Thank you!

Activity 1-2 Scenario After being evaluated by multiple prospective clients, your pen testing group has been hired by Greene City Physicians Group, or GCPG. GCPG is a medium-sized health care provider in the fictitious city and state of Greene City, RL. GCPG is a relatively young and inexperienced business, and their IT department has been given few resources or mandates with which to shore up the organization's defenses. This has led to a spate of recent attacks. Now, the executive physicians at GCPG have finally decided to get serious when it comes to cybersecurity. In the past, the confidential health data and other personal data of its patients have been stolenthis has led to a significant amount of legal trouble and lost business due to low consumer confidence in the organization. GCPG can tolerate this risk no longer, and has reached out to you and your team for help. Like any important task, the pen test must begin at the planning phase. Answer the following questions: It's important to consider the target audience of your test results before getting started. Assuming your tests will be comprehensive and cover multiple types, what stakeholders might you need to consider in your reports? Because GCPG has provided little financial support and resources to its own IT team, your pen test will be treated similarly. In other words, your budget is limited and you must rely on your own resources during the test. You need to make sure GCPG understands the effect this will have on the test. What do you tell them? Because of budgetary constraints, you're faced with at least one majortechnical constraint. You had planned on using Metasploit Pro, a powerfulpen test management tool built on the popular Metasploit Framework. ThePro version comes with a great deal of functionality and can make it easier fora pen tester to launch and automate specific types of attacks, as well asmanage an overall pen test project. However, GCPG won't cover the price ofthe Pro version. How might you compensate for this lost functionality? GCPG maintains the health data of thousands of patients, and as a result,has emphasized the importance of keeping this data confidential. How mightthis requirement affect what you discover during the test? You want to work with GCPG to draft some rules of engagement (ROE).Given what you know about GCPG's business, its customers, and its securitysituation, what rules might you want to include

Step by Step Solution

There are 3 Steps involved in it

Step: 1

blur-text-image

Get Instant Access to Expert-Tailored Solutions

See step-by-step solutions with expert insights and AI powered tools for academic success

Step: 2

blur-text-image

Step: 3

blur-text-image

Ace Your Homework with AI

Get the answers you need in no time with our AI-driven, step-by-step assistance

Get Started

Recommended Textbook for

Database Design Query Formulation And Administration Using Oracle And PostgreSQL

Authors: Michael Mannino

8th Edition

1948426951, 978-1948426954

More Books

Students also viewed these Databases questions

Question

What do Dimensions represent in OLAP Cubes?

Answered: 1 week ago