Short answer questions

profileGaurav8200
ICTNWK608_UnitAssessmentStudentPack.docx

ICTNWK608 – Configure Network Devices for a Secure Network Infrastructure

Student Assessment Pack

Student and Trainer/Assessor Details

Student ID

Student name

Contact number

Email address

Trainer/Assessor name

.

Course and Unit Details

Course code

ICT60215

Course name

Advanced Diploma of Network Security

Unit code

ICTNWK608

Unit name

Configure network devices for a secure network infrastructure

Assessment Submission Method

☐ By hand to trainer/assessor

☐ By email to trainer/assessor

☐ Online submission via Learning Management System (LMS)

Student Declaration

· I certify that the work submitted for this assessment pack is my own. I have clearly referenced any sources used in my submission. I understand that a false declaration is a form of malpractice;

· I have kept a copy of this assessment pack and all relevant notes, attachments, and reference material that I used in the production of the assessment pack;

· For the purposes of assessment, I give the trainer/assessor of this assessment the permission to:

· Reproduce this assessment and provide a copy to another member of staff; and

· Take steps to authenticate the assessment, including communicating a copy of this assessment to a checking service (which may retain a copy of the assessment on its database for future plagiarism checking).

Student signature: ________________________________

Date: ____/_____/______________

Assessment Plan

To demonstrate competence in this unit, you must be assessed as satisfactory in each of the following assessment tasks.

Evidence recorded

Evidence Type/ Method of assessment

Sufficient evidence recorded/Outcome

Unit Assessment Task 1

Unit Knowledge Test (UKT)

S / NS (First Attempt)

S / NS (Second Attempt)

Unit Assessment Task 2

Unit Project (UP)

S / NS (First Attempt)

S / NS (Second Attempt)

Unit Assessment Task 3

Unit Project (UP)

S / NS (First Attempt)

S / NS (Second Attempt)

Final result

C/NYC

Date assessed

Trainer/Assessor Signature

Assessment Conditions

Unit purpose/application

This unit describes the skills and knowledge required to use software tools, equipment and protocols to configure network devices in the design of the infrastructure of a secure network.

It applies to individuals with advanced information and communications technology (ICT) skills who adapt router and switch operating system capabilities to mitigate attacks.

No licensing, legislative or certification requirements apply to this unit at the time of publication

What the student can expect to learn by studying this unit of competency

· Implement layer 2 security

· Configure router OS intrusion prevention system (OS-IPS) to mitigate threats to network resources

· Configure virtual private networks (VPNs) to provide secure connectivity for site-to-site and remote access communications

· Implement network foundation protection (NFP)

Training and assessment resources required for this unit of competency

The student will have access to the following:

· Learner guide

· PowerPoint presentation

· Unit Assessment Pack (UAP)

· Access to other learning materials such as textbooks

The resources required for these assessment tasks also included:

· Access to a computer, the Internet and word-processing system such as MS Word.

· A site where deployment of network security solution may be conducted

· A live network (LAN)

· Servers and computers

· Switches and routers

· Hardware and software security technologies

· Security policies and guidelines (as per scenario)

Simulated assessment environments must simulate the real-life working environment where these skills and knowledge would be performed, with all the relevant equipment and resources of that working environment.

Submission instructions

Your trainer/assessor will confirm assessment submission details for each assessment task.

Academic integrity, plagiarism and collusion

Academic Integrity

Academic Integrity is about the honest presentation of your academic work. It means acknowledging the work of others while developing your own insights, knowledge and ideas.

As a student, you are required to:

· undertake studies and research responsibly and with honesty and integrity

· ensure that academic work is in no way falsified

· seek permission to use the work of others, where required

· acknowledge the work of others appropriately

· take reasonable steps to ensure other students cannot copy or misuse your work.

Plagiarism

Plagiarism means to take and use another person's ideas and or manner of expressing them and to pass them off as your own by failing to give appropriate acknowledgement. This includes material sourced from the internet, RTO staff, other students, and from published and unpublished work.

Plagiarism occurs when you fail to acknowledge that the ideas or work of others are being used, which includes:

· Paraphrasing and presenting work or ideas without a reference

· Copying work either in whole or in part

· Presenting designs, codes or images as your own work

· Using phrases and passages verbatim without quotation marks or referencing the author or web page

· Reproducing lecture notes without proper acknowledgement.

Collusion

Collusion means unauthorised collaboration on assessable work (written, oral or practical) with other people. This occurs when a student presents group work as their own or as the work of someone else.

Collusion may be with another RTO student or with individuals or students external to the RTO. This applies to work assessed by any educational and training body in Australia or overseas.

Collusion occurs when you work without the authorisation of the teaching staff to:

· Work with one or more people to prepare and produce work

· Allow others to copy your work or share your answer to an assessment task

· Allow someone else to write or edit your work (without rto approval)

· Write or edit work for another student

· Offer to complete work or seek payment for completing academic work for other students.

Both collusion and plagiarism can occur in group work. For examples of plagiarism, collusion and academic misconduct in group work please refer to the RTO’s policy on Academic integrity, plagiarism and collusion.

Plagiarism and collusion constitute cheating. Disciplinary action will be taken against students who engage in plagiarism and collusion as outlined in RTO’s policy.

Proven involvement in plagiarism or collusion may be recorded on students’ academic file and could lead to disciplinary action.

Other Important unit specific Information

N/A

Unit outcome

· This unit is not graded and the student must complete and submit all requirements for the assessment task for this cluster or unit of competency to be deemed competent.

· Students will receive a 'satisfactorily completed' (S) or 'not yet satisfactorily completed (NS) result for each individual unit assessment task (UAT).

· Final unit result will be recorded as competency achieved/competent (C) or competency not yet achieved/not yet competent (NYC).

Unit Assessment Task (UAT) -1

Assessment Task 1 - Unit Knowledge Test (UKT)

Assessment type:

· Written Questions

Instructions:

· This is an individual assessment.

The purpose of this assessment task is to assess the students’ knowledge required to ensure secure file encryption is selected, implemented and monitored on a computer network or local environment.

· To make full and satisfactory responses you should consult a range of learning resources, other information such as handouts and textbooks, learners’ resources and slides.

· All questions must be answered in order to gain competency for this assessment.

You may attach a separate sheet if required.

You must include the following particulars in the footer section of each page of the attached sheets:

· Student ID or Student Name

· Unit ID or Unit Code

· Course ID or Course Code

· Trainer and assessor name

· Page numbers

You must staple the loose sheets together along with the cover page.

You must attach the loose sheets chronologically as per the page numbers.

· Correction fluid and tape are not permitted. Please do any corrections by striking through the incorrect words with one or two lines and rewriting the correct words.

Resources required to complete the assessment task:

Learner guide

PowerPoint presentation

Unit Assessment Pack (UAP)

Access to other learning materials such as textbooks

Access to a computer, the Internet and word-processing system such as MS Word.

1. Answer the following questions.

(A). What is VLAN and how will you configure VLAN? Write basic commands to configure the VLAN.

(B). What are the steps involved in the verification and troubleshooting for the virtual local area (VLAN) switching? Use screenshots if required to explain the steps.

Question 1: What are the steps involved in the configuration, verification and troubleshooting for inter-switching communications? Use screenshots if required to explain the steps.

1. Explain the five (5) key features of deployment schemes. Write your answer in 200-250 words.

1. What are the ten (10) steps involved in setting and securing a firewall?

1. Summarise the following each in 150-200 words.

1. iDevice operating system (iOS)

1. Internet Protocol (IP) Networking Model

1. Explain the steps involved in implementation of the following.

1. Local Area Network (LAN)

1. Wide Area Network (WAN)

1. A) What is your understanding of Network Address Translation (NAT)? Write your response in 140-170 words.

B) Based on the following figure, write configuration commends for NAT.

image0.jpg

1. Answer the following questions.

A) What is Network Topology? Also, summaries five (5) models of network topology. Write your response in 240-270 words.

B) Explain the following terms, each in 100-150 words.

1. Network Architectures

2. Network Elements

1. Summarise the following terms use 100-150 words for each.

1. Network Standards

1. Network protocols

1. Explain the following terms using 100-150 words for each.

1. Secure Connectivity

1. Remote Access Communication

1. Answer the following questions.

A) Explain Security Protocol in 130-160 words

B) Summarise Secure Socket Layer (SSL) in detail. Write your response in 100-150 words.

1. Summarise the threat mitigation strategies in 50-100 words.

1. What is a tunneling protocol? Explain the different types of tunneling protocols. Write your response in 250-300 words.

1. Summarise the following:

1. VPN

1. EasyVPN

1. Dynamic Multipoint VPN (DMVPN)

1. Virtual Private Network technologies.

1. Answer the following questions.

A) Summarise the process of configuration, verification and troubleshooting of a Cisco router operation.

B) What are the steps involved in configuring, verifying and troubleshoot routing.

1. Explain Identity-based networking services (IBNS) in terms of network security and write down the advantages of IBNS as well. Write your response in 100-150 words.

1. What are the three (3) benefits of deploying an identity and access management solution? Write your answer in 150-200 words

1. Answer the following questions.

A) Summarise the term Router’s operating system and its two (2) types. Write your response in 100-150 words

B) What are the four (4) types of approaches used by IPS for securing the network from intrusions? Write your response in 150-200 words

C) Summarise two (2) basic types of IPS signatures, each in 50-80 words.

1. Answer the following questions.

A) What is your understanding of Context-Based Access Control (CBAC)? Write your response in 100-150 words.

(B) What is the importance of Network Address Translation to mitigate the threats to the network? Write your response in 100-150 words.

(C) Summarise the benefits of implementing a Zone Based Firewall in 50-100 words.

1. Answer the following questions.

A) Summarise Network Foundation Protection (NFP) and its features. Write your response in 100-150 words.

(B)What are the benefits of management plane, data plane and control plane in terms of network security? Write your answer in 180-220 words.

Unit Assessment Task (UAT) -2

Assessment Task 2 – Unit Project (UP)

Assessment type:

Unit Project (UP)

Instructions to complete this assessment task:

· Please write your responses in the template provided.

· You may attach a separate sheet if required.

· You must include the following particulars in the footer section of each page of the attached sheets:

· Student ID or Student Name

· Unit ID or Unit Code

· Course ID or Course Code

· Trainer and assessor name

· Page numbers

· You must staple the loose sheets together along with the cover page.

· You must attach the loose sheets chronologically as per the page numbers.

· Correction fluid and tape are not permitted. Please do any corrections by striking through the incorrect words with one or two lines and rewriting the correct words.

· The premise of the project must be closely related to the previous assessment task.

· This submission must be well presented and follow the guidelines and instructions provided.

· Please follow the format as indicated in the template section below.

· One of the most important steps that you can take: proofread your project.

· Project must be of 500-800 words in length, using 11-point font, double-spaced, and must include a cover page, table of contents, introduction, body, summary or conclusion, and works cited.

· Appropriate citations are required.

· All RTO policies are in effect, including the plagiarism policy.

Scenario: -

HELMA Finance Company is one of the leading finance companies in Australia and provides its services to a number of corporate clients. The information relating to the financial activities of all the clients is of immense importance for the company and the business relies on the trust developed for customers in regard of the integrity of the information. HELMA has always tried to provide best possible solutions to protect its information. The company’s head office is situated in the CBD while it has regional offices in Geelong and Ballarat. All the employees know the importance of the information on which they are working, along with the integrity and the security implemented on the information system and the network. All the employees and users accessing the information work on the following principles:

· Consider the sensitivity of the information they handle

· Protect information in proportion to its sensitivity by ensuring that information, whatever its format, is secured by physical or approved electronic means

· Ensure that they take appropriate action within the appropriate procedures when there is a breach of policy

For the security and integrity of the information substantial information security measures have been implemented. The company also have well defined Information Security policies and procedures and all the employees are obliged to follow these policies and procedures. Information security is of great importance to the company to ensure compliance with legislation and demonstrate that the Company understands and applies proportionate guidance and process to recording, storing, processing, exchanging and deleting information. Should this not be achieved the Company can risk, at worst, the safety of individuals, loss of financial information, breach of commercial confidentiality and subsequent financial penalties from the clients.

There are three main principles to the information security policy:

All staff must consider the sensitivity of the information they handle.

All staff must protect information in proportion to its sensitivity by ensuring that information, whatever its format, is secured by physical means (such as locking paperwork away or appropriately archiving it when no longer current) or by using approved electronic means (such as only using Company IT equipment).

Managers must ensure this policy is applied within their areas of work and should also lead by example. This policy is mandatory.

Any breach of the policy may result in disciplinary action being taken under the Company’s Disciplinary Procedure. Any breaches of security (non-compliance with this Policy) must be reported to the Information Technology Department.

The mandatory requirements of this core policy is based on the three elements of information security as per the Australian Information Security legislation:

· Confidentiality: ensuring that information is only accessible to those authorised to access it

· Integrity: safeguarding the accuracy and integrity of information and processing methods

· Availability: ensuring that authorised users have access to information and associated assets when required.

It is the policy of the company to ensure:

· Information is protected against unauthorised access.

· Confidentiality of information is maintained.

· Information is not disclosed to unauthorised persons through deliberate or negligent action.

· The integrity of information is maintained by protection from unauthorised modification

· Information is available to authorised users when needed.

· Regulatory and legislative requirements are met.

· Contingency plans are produced and tested as far as is practicable to ensure business continuity is maintained.

· Information Security training is provided for all staff.

· All breaches of information security and suspected weaknesses are reported, investigated and appropriate action taken.

· Sharing of information with other organisations/agencies is permitted providing it is done within the remit of a formally agreed information sharing protocol.

· That there is a fair and consistent approach to the enforcement of standards of conduct expected from employees when using social media sites.

· Security incidents must be reported within two business days

· Incident report must be completed if you lose or damage any ICT equipments

The IT infrastructure is updated according to the requirements of the information security. But the main threat is to the network of the information system. The information system comprises of Data Servers, Server for Financial ERP suite, desktops, Laptops, Cisco Routers and Switches all connected in LAN at head office and also a WAN is established for the connectivity across the head office and regional office. The IT department is responsible for managing the whole network and Allen-Network Engineer specialises in the implementation of the IT resources across the network.

The Information Security Officer along with the Network Engineer ensures that all the users follow the policies and procedures related to network security. The Users/Employers are supposed to oblige by the personal device policy especially those who use their personal hand-held devices or laptops should not bypass the network security policies.

Personal device policy includes:

· Home worker strictly use home network or pocket Wi-Fi provided by the organisation

· Do not download unauthorised software’s and files

· Do antivirus check for all the external data storage devices

· Do not write your password in the computer

· Do not share your password with anyone

· Change computer and other devices password within 60 days

Also, no such personal email IDs to be used, social network sites have already been blocked also downloads to any personal drives or torrents are strictly prohibited. System policies to prevent these personal downloads and uploads have already been implemented on the networked resources using the authentication server. Failure to oblige information security policy will result in strict actions. Also, if any user/employee comes to know about any information leakage or breach, he/she needs to inform the IT department or by filling the online form of security incident reporting.

For better security across the network and information system along with the mitigation of the attacks at Layer 2 and 3, the services of Mcgrath have been acquired. He is the new Information Security Officer-ISO. Mcgrath will be responsible for implementing information security and maintaining the secure network environment.

The job description of Mcgrath includes the following:

· Actively ensure appropriate administrative, physical and technical safeguards are in place to protect network from internal and external threats

· Meticulously identify, introduce and implement appropriate procedures, including checks and balances, are in place to test these safeguards on a regular basis

· Make it a priority to see that disaster recovery and emergency operating procedures are in place on network and tested on a regular basis

· Act as the committed owner of the network security incident and vulnerability management processes from design to implementation and beyond

· Define and implement secure network configuration baseline standards

· Support and administer firewall environments in line with Network security policy

While the Job description of Allen the Network Engineer includes:

· Establish the networking environment by designing system configuration, directing system installation and defining, documenting and enforcing system standards

· Design and implement new solutions and improve resilience of the current environment

· Maximise network performance by monitoring performance, troubleshooting network problems and outages, scheduling upgrades and collaborating with network architects on network optimisation

· Undertake data network fault investigations in local and wide area environments using information from multiple sources

Activity 1: (Analysing Network Security System Requirements)

After having the detail look at the scenario given above, you need to analyse the requirements for the Network Security System requirements for the company including the following:

· Purpose

· Network security requirements

· Physical security requirements

· Computer security requirements

· Mobile workers and home Workers

· Use of the internet

· Security Incident Reporting

You may need to research related to network security requirements on the internet. You must complete the network security requirements template given below for the company as a part of the activity.

HELMA Network Security Requirements

Purpose

Network Security Requirements

Physical Security Requirements

Computer Security Requirements

Mobile workers and home Workers

Use of the internet

Security Incident Reporting

Performance criteria checklist for unit assessment task:

Trainer/ Assessor to complete

Assessment activities to be completed

· Analysing Network Security System Requirements

· For a full project outline, please refer to the student assessment instructions

Does the candidate meet the following criteria

Yes

No

Trainer/Assessor Comments

Understood the give scenario and company requirements for network security

Defined Requirements for security relevant to network security including the following:

· Purpose

· Network Security

· Physical Security

· Computer Security

· Mobile workers and home Workers

· Use of the internet

Defined the security incident reporting

Activity 2: (Implementation of the Layer 2 and 3 Security)

Note: This activity is in continuation of activity 1.

After the analysis of the requirements for the network security in activity 1, now, you are required to implement the Layer 2 and 3 security on the network to mitigate against the expected security attacks. This implementation will not only help to protect the data but will also define the security parameters while configuring the routers and switches. You will act as Mcgrath, the Information Security Officer and are required to perform the following tasks:

· Configuration of the router operating system

· Configure the interface of the router along with the serial interface

· Configure the hostname and password of the router

· Verify the connectivity

· Configure the router using the Access Control List

· Implementation of the Identity-based Management System on the network switches using Access control System as the authentication server

· At the end, you need to ping from host to router and switches to check the connectivity

· Troubleshoot connectivity issues if any

For configuration and implementing security parameters on the network along with the mitigation of threats to the network, consider the following Network diagram to understand the network topology and components of the network being implemented at HELMA.

This activity is continuation of activity 1. You are required to participate in a practical demonstration task. You need to complete this activity in 3 to 5 hours. Additional time will be given to you for the preparation.

Note: For This activity RTO/Assessor will provide you the following:

· A site where deployment of network security solution may be conducted

· A live network (LAN)

· Servers and computers

· Switches and routers

· Hardware and software security technologies

· Security policies and guidelines (as per scenario)

You will work in coordination with the Network Engineer, Allen which will be performed by the Trainer/assessor, and he will provide you all the required network infrastructure, router and switches.

Student must follow vendor instruction for configuration of Router and implementation of IBMS using ACS.

Your trainer and assessor will observe you during the activity and complete the performance checklist.

RTO may use only two network computers to check the connectivity and other performance criteria.

Performance criteria checklist for unit assessment task:

Trainer/ Assessor to complete

Assessment activities to be completed

· Implementation of the Layer 2 and 3 Security

· For a full project outline, please refer to the student assessment instructions

Does the candidate meet the following criteria

Yes

No

Trainer/Assessor Comments

Configured the router operating system of the given network diagram

Configured:

· Switches

· Allocated IP address to host and other devices

· Router

· Connect all the devices appropriately

· Interface of the router

Implementation of the Identity-based Management System on the network switches using Access control System as the authentication server

Ping from host to router and switches to check the connectivity

Troubleshoot connectivity issues if any

Activity 3: (Configuration of the Intrusion Prevention System)

Note: This activity is in continuation of activity 1 and 2.

Now, you are the Information Security Officer-Mcgrath, and you need to configure the intrusion prevention system to the network to mitigate against the network attacks. It is required to implement the firewall on the router that will act as the intrusion prevention system for the traffic coming from the internet to the LAN. The firewall is of immense importance and will help to mitigate attacks by identifying the threats. Therefore, you need to implement the firewalls for the better protection of the networked resources and complete the following tasks for the successful completion of this activity:

· Configure and verify IPS firewall after its analysis to identify the threats and best way to block them.

· Create, update and tune IPS signature to avoid attacks

· To mitigate against the threats and probable attacks on the network, configure and verify CBAC and NAT.

· Also configure and verify Zone Based firewall using Uniform Resource Locator (URL) filtering for better network security.

This activity is continuation of activity 1 and 2. You are required to participate in a practical demonstration task. You need to complete this activity in 3 to 4 hours.

Note: For This activity RTO/Assessor will provide you the following:

· A site where deployment of network security solution may be conducted

· A live network (LAN)

· Servers and computers

· Switches and routers

· Hardware and software security technologies

· Security policies and guidelines (as per scenario)

You will work in coordination with the Network Engineer, Allen which will be performed by the Trainer/assessor, and he will provide you all the required network infrastructure, router and switches.

Your trainer and assessor will observe you during the activity and complete the performance checklist.

Performance criteria checklist for unit assessment task:

Trainer/ Assessor to complete

Assessment activities to be completed

· Configuration of the Intrusion Prevention System

· For a full project outline, please refer to the student assessment instructions

Resources required for the unit assessment task

· Unit assessment guide template

Does the candidate meet the following criteria

Yes

No

Trainer/Assessor Comments

Configured and verify IPS firewall after its analysis to identify the threats and best way to block them.

Created, updated and tuned IPS signature to avoid attacks

configured and verified CBAC and NAT.

configured and verified Zone Based firewall using Uniform Resource Locator (URL) filtering for better network security.

Unit Assessment Task (UAT) -3

Assessment Task 3 – Unit Project (UP)

Assessment type:

Unit Project (UP)

Instructions to complete this assessment task:

· Please write your responses in the template provided.

· You may attach a separate sheet if required.

· You must include the following particulars in the footer section of each page of the attached sheets:

· Student ID or Student Name

· Unit ID or Unit Code

· Course ID or Course Code

· Trainer and assessor name

· Page numbers

· You must staple the loose sheets together along with the cover page.

· You must attach the loose sheets chronologically as per the page numbers.

· Correction fluid and tape are not permitted. Please do any corrections by striking through the incorrect words with one or two lines and rewriting the correct words.

· The premise of the project must be closely related to the previous assessment task.

· This submission must be well presented and follow the guidelines and instructions provided.

· Please follow the format as indicated in the template section below.

· One of the most important steps that you can take: proofread your project.

· Project must be of 500-800 words in length, using 11-point font, double-spaced, and must include a cover page, table of contents, introduction, body, summary or conclusion, and works cited.

· Appropriate citations are required.

· All RTO policies are in effect, including the plagiarism policy.

Activity 1 (Configuration of VPN)

This activity is continuation of assessment task 2. You are required to participate in a practical demonstration task. You need to complete this activity in 3 to 4 hours. Additional time will be provided for analysis and preparing documentation.

Note: For This activity your RTO/Assessor will provide you with the following:

· A site where deployment of network security solution may be conducted

· A live network (LAN)

· Servers and computers

· Switches and routers

· Hardware and software security technologies

· Security policies and guidelines (as per scenario)

Once Layer 2 and Layer 3 have been secured, as you are Information Security Officer, you are required to implement Virtual Private Network for remote access of the network resources and information system. The implementation of the VPN will provide:

· Enhanced security

· Remote Control

· Sharing Files anytime easily

· Online Anonymity

· Unblock websites and bypass filters

· Better performance

Also, A VPN can save a company money in several situations:

· eliminating the need for expensive long-distance leased lines

· reducing long-distance telephone charges

· offloading support cost

Using VPN, each employee must possess the appropriate networking software or hardware support on their local network and computers. When set up properly, VPN solutions are easy to use and sometimes can be made to work automatically as part of network sign on.

VPN technology also works well with Wi-Fi local area networking. For HELMA, the use of VPNs will secure wireless connections to their local access points when working inside the office. These solutions provide strong protection without affecting performance excessively.

You are required to implement VPN across the network to ensure secure connectivity for site to site (head office and regional offices) and remote access communication. You need to perform the following tasks:

· Analyse and evaluate the features and functions of Internet security protocol-IPSec and Generic routing encapsulation-GRE along with Dynamic Multipoint VPN (DMVPN)

· Configure VPN for site to site secured communication and also verify its operations

· Implement Secure network access using Secure Socket Layer (SSL) VPN to deliver remote access

· Analyse, configure and verify Easy VPN on the router

· Implement group encrypted transport (GET) for management of VPN

Complete the template below for analysis of features and functions of IPSec, GRE and DMVPN

Template for features and Functions

Features

Functions

IPSec

Generic Routing Encapsulation GRE

Dynamic Multipoint VPN (DMVPN)

Performance criteria checklist for unit assessment task:

Trainer/ Assessor to complete

Assessment activities to be completed

· Configuration of VPN

· For a full project outline, please refer to the student assessment instructions

Does the candidate meet the following criteria

Yes

No

Trainer/Assessor Comments

Evaluated the features and functions of IPSec, GRE and DMVPN

Completed the given Template

Configured site to site VPN and verified its operations

Implemented SSL VPN

Analysed, configured and verified Easy VPN

Implement group encrypted transport (GET) for management of VPN

Activity 2: (Implementing Network Foundation Protection)

This activity is continuation of activity 1, you need to implement Network foundation protection of the company’s network resources to provide the secured network as per the requirements and the security policies defined in the scenario. So, under the supervision of the trainer/assessor complete the following tasks:

· Analyse the network foundation protection features and functions

· Use Router OS features for securing management plane, data plane and control plane

· Ensure the integrity of the control plane such that only legitimate control plane traffic is processed by the network element

· Ensure that other IP traffic plane packets are properly used in network

· Ensure that one service type does not impact any other service type

· Ensure that other IP traffic planes do not impact services plane traffic

Also, fill the template given below for the analysis of NFP.

You need to complete this activity in 2 to 3 hours. Additional time will be provided for analysis and preparing documentation.

Note: For This activity RTO/Assessor will provide you the following:

· A site where deployment of network security solution may be conducted

· A live network (LAN)

· Servers and computers

· Switches and routers

· Hardware and software security technologies

· Security policies and guidelines (as per scenario)

Template for Features and Functions of NFP

Features

Functions

Network Foundation Protection

Performance criteria checklist for unit assessment task:

Trainer/ Assessor to complete

Assessment activities to be completed

· Implementing Network Foundation Protection

· For a full project outline, please refer to the student assessment instructions

Does the candidate meet the following criteria

Yes

No

Trainer/Assessor Comments

Implemented NFP

Analysed features and functions of NFP

Secured Management plane, data plane and control plane using Router OS

Completed the given template

End of the Assessment

ICTNWK608-Student Assessment Pack V1.0 September 2019