|
Articulation of Response (clarity, organization, mechanics)
|
|
(0) Unsatisfactory
|
(1) Does Not Meet Standard
|
(2) Minimally Competent
|
(3) Competent
|
(4) Highly Competent
|
|
The candidate provides unsatisfactory articulation of response.
|
The candidate provides weak articulation of response.
|
The candidate provides limited articulation of response.
|
The candidate provides adequate articulation of response.
|
The candidate provides substantial articulation of response.
|
|
Criterion Score: 3.00
|
|
A1. Footprinting Analysis Findings
|
|
(0) Unsatisfactory
|
(1) Does Not Meet Standard
|
(2) Minimally Competent
|
(3) Competent
|
(4) Highly Competent
|
|
The candidate does not provide a logical summary of the findings of the footprinting analysis performed on the chosen organization.
|
The candidate provides a logical summary, with no detail, of the findings of the footprinting analysis performed on the chosen organization.
|
The candidate provides a logical summary, with limited detail, of the findings of the footprinting analysis performed on the chosen organization.
|
The candidate provides a logical summary, with adequate detail, of the findings of the footprinting analysis performed on the chosen organization.
|
The candidate provides a logical summary, with substantial detail, of the findings of the footprinting analysis performed on the chosen organization.
|
|
Criterion Score: 0.00
Comments on this criterion: 4/23/2015 - A summary of footprinting analysis is included on slide 2. Revision is required including additional details defining the process to acquire information about the organization and the technical information that was acquired. Revise including a detailed discussion defining the footprinting process and acquired information.
|
|
A2. Attack Discussion
|
|
(0) Unsatisfactory
|
(1) Does Not Meet Standard
|
(2) Minimally Competent
|
(3) Competent
|
(4) Highly Competent
|
|
The candidate does not provide a logical discussion of how the information gathered during the footprinting analysis could be used to initiate an attack against the organization.
|
The candidate provides a logical discussion, with no detail, of how the information gathered during the footprinting analysis could be used to initiate an attack against the organization.
|
The candidate provides a logical discussion, with limited detail, of how the information gathered during the footprinting analysis could be used to initiate an attack against the organization.
|
The candidate provides a logical discussion, with adequate detail, of how the information gathered during the footprinting analysis could be used to initiate an attack against the organization.
|
The candidate provides a logical discussion, with substantial detail, of how the information gathered during the footprinting analysis could be used to initiate an attack against the organization.
|
|
Criterion Score: 0.00
Comments on this criterion: 4/23/2015 - A general summary of possible attacks are included. Revision is required including specific attacks that can be targeted against the organization using the information acquired during the footprinting analysis. Revise including additional details defining how specific attacks can be targeted.
|
|
A3. Social Engineering Techniques
|
|
(0) Unsatisfactory
|
(1) Does Not Meet Standard
|
(2) Minimally Competent
|
(3) Competent
|
(4) Highly Competent
|
|
The candidate does not provide a logical discussion of social engineering techniques that could be utilized to gather information regarding the organization’s computer systems.
|
The candidate provides a logical discussion, with no detail, of social engineering techniques that could be utilized to gather information regarding the organization’s computer systems.
|
The candidate provides a logical discussion, with limited detail, of social engineering techniques that could be utilized to gather information regarding the organization’s computer systems.
|
The candidate provides a logical discussion, with adequate detail, of social engineering techniques that could be utilized to gather information regarding the organization’s computer systems.
|
The candidate provides a logical discussion, with substantial detail, of social engineering techniques that could be utilized to gather information regarding the organization’s computer systems.
|
|
Criterion Score: 1.00
Comments on this criterion: 4/23/2015 - Social engineering techniques are included in the presentation. Revision is required including details defining each of the identified techniques. Revise including a discussion defining each of the identified social engineering techniques.
|
|
A3a. Social Engineering Countermeasures
|
|
(0) Unsatisfactory
|
(1) Does Not Meet Standard
|
(2) Minimally Competent
|
(3) Competent
|
(4) Highly Competent
|
|
The candidate does not present appropriate countermeasures that should be used to combat such social engineering techniques.
|
The candidate presents, with no detail, appropriate countermeasures that should be used to combat such social engineering techniques.
|
The candidate presents, with limited detail, appropriate countermeasures that should be used to combat such social engineering techniques.
|
The candidate presents, with adequate detail, appropriate countermeasures that should be used to combat such social engineering techniques.
|
The candidate presents, with substantial detail, appropriate countermeasures that should be used to combat such social engineering techniques.
|
|
Criterion Score: 1.00
Comments on this criterion: 4/23/2015 - General mitigation strategies are included in the paper. Revision is required including specific recommendations to mitigate the identified issues. Revise including specific details defining mitigation strategies to alleviate the risk of social engineering for the organization.
|
|
A4. Footprinting Countermeasures
|
|
(0) Unsatisfactory
|
(1) Does Not Meet Standard
|
(2) Minimally Competent
|
(3) Competent
|
(4) Highly Competent
|
|
The candidate does not prescribe a series of countermeasures and remedies that could be utilized to counter this type of footprinting attack.
|
The candidate prescribes, with no detail, a series of countermeasures and remedies that could be utilized to counter this type of footprinting attack.
|
The candidate prescribes, with limited detail, a series of countermeasures and remedies that could be utilized to counter this type of footprinting attack.
|
The candidate prescribes, with adequate detail, a series of countermeasures and remedies that could be utilized to counter this type of footprinting attack.
|
The candidate prescribes, with substantial detail, a series of countermeasures and remedies that could be utilized to counter this type of footprinting attack.
|
|
Criterion Score: 0.00
Comments on this criterion: 4/23/2015 - This aspect is not readily identifiable in the submission. Revision is required including specific details defining countermeasures to mitigate the availability of information that can be acquired using footprinting techniques. Revise defining specific strategies to mitigate the availability of information that is available using specific footprinting techniques.
|
|
A5. Web Server Vulnerabilities
|
|
(0) Unsatisfactory
|
(1) Does Not Meet Standard
|
(2) Minimally Competent
|
(3) Competent
|
(4) Highly Competent
|
|
The candidate does not present common web server vulnerabilities that the organization is most susceptible to.
|
The candidate presents, with no detail, common web server vulnerabilities that the organization is most susceptible to.
|
The candidate presents, with limited detail, common web server vulnerabilities that the organization is most susceptible to.
|
The candidate presents, with adequate detail, common web server vulnerabilities that the organization is most susceptible to.
|
The candidate presents, with substantial detail, common web server vulnerabilities that the organization is most susceptible to.
|
|
Criterion Score: 0.00
Comments on this criterion: 4/23/2015 - Common web server vulnerabilities are included in the submission. Revision is required including details defining specific web server vulnerabilities for Apple. Revise including details defining web server vulnerabilities that are specific to the organization.
|
|
A6. Web Application Threats
|
|
(0) Unsatisfactory
|
(1) Does Not Meet Standard
|
(2) Minimally Competent
|
(3) Competent
|
(4) Highly Competent
|
|
The candidate does not present common threats against web applications that pose the greatest risk to the organization’s web applications.
|
The candidate presents, with no detail, common threats against web applications that pose the greatest risk to the organization’s web applications.
|
The candidate presents, with limited detail, common threats against web applications that pose the greatest risk to the organization’s web applications.
|
The candidate presents, with adequate detail, common threats against web applications that pose the greatest risk to the organization’s web applications.
|
The candidate presents, with substantial detail, common threats against web applications that pose the greatest risk to the organization’s web applications.
|
|
Criterion Score: 0.00
Comments on this criterion: 4/23/2015 - This aspect is not readily identifiable in the paper. Revision is required including details defining web application threats that are specific to Apple. Revise including details defining vulnerabilities that are specific to Apple.
|
|
A7. SQL Injection
|
|
(0) Unsatisfactory
|
(1) Does Not Meet Standard
|
(2) Minimally Competent
|
(3) Competent
|
(4) Highly Competent
|
|
The candidate does not illustrate how SQL injection could be used to obtain or destroy information from a web application’s database.
|
The candidate illustrates, with no detail, how SQL injection could be used to obtain or destroy information from a web application’s database.
|
The candidate illustrates, with limited detail, how SQL injection could be used to obtain or destroy information from a web application’s database.
|
The candidate illustrates, with adequate detail, how SQL injection could be used to obtain or destroy information from a web application’s database.
|
The candidate illustrates, with substantial detail, how SQL injection could be used to obtain or destroy information from a web application’s database.
|
|
Criterion Score: 1.00
Comments on this criterion: 4/23/2015 - A general overview of SQL injection is included. Details defining how SQL injection can be used to compromise the web application database could not be located. Revise including specific details defining how SQL injection can be used to compromise the web application database.
|
|
A8. SQL Injection Techniques
|
|
(0) Unsatisfactory
|
(1) Does Not Meet Standard
|
(2) Minimally Competent
|
(3) Competent
|
(4) Highly Competent
|
|
The candidate does not provide a logical discussion of how SQL injection techniques could pose a potential threat to the organization’s web applications.
|
The candidate provides a logical discussion, with no detail, of how SQL injection techniques could pose a potential threat to the organization’s web applications.
|
The candidate provides a logical discussion, with limited detail, of how SQL injection techniques could pose a potential threat to the organization’s web applications.
|
The candidate provides a logical discussion, with adequate detail, of how SQL injection techniques could pose a potential threat to the organization’s web applications.
|
The candidate provides a logical discussion, with substantial detail, of how SQL injection techniques could pose a potential threat to the organization’s web applications.
|
|
Criterion Score: 1.00
Comments on this criterion: 4/23/2015 - An overview of SQL injection as a potential threat is included in the presentation. A more robust discussion defining the threat of SQL injection is required. Revise including additional details defining the threat of SQL injection.
|
|
B. Sources
|
|
(0) Unsatisfactory
|
(1) Does Not Meet Standard
|
(2) Minimally Competent
|
(3) Competent
|
(4) Highly Competent
|
|
When the candidate uses sources, the candidate does not provide in-text citations and references.
|
When the candidate uses sources, the candidate provides only some in-text citations and references.
|
When the candidate uses sources, the candidate provides appropriate in-text citations and references with major deviations from APA style.
|
When the candidate uses sources, the candidate provides appropriate in-text citations and references with minor deviations from APA style.
|
When the candidate uses sources, the candidate provides appropriate in-text citations and references with no readily detectable deviations from APA style, OR the candidate does not use sources.
|
|
Criterion Score: 0.00
Comments on this criterion: 4/23/2015 - References are included in the submission. In-text citations could not be located for each reference. Revise including in-text citations for each reference.
|