Objective 1

This project involved designing and documenting a secure network infrastructure for Desert Shield Technologies using Cisco Packet Tracer. The network included routers, switches, servers, workstations, wireless devices, proper IP addressing, and security features such as firewalls and WPA2 wireless protection. The completed design demonstrated an understanding of network architecture, physical connectivity, communication with external networks, and the implementation of basic operational and security components required for a secure business environment.

This report evaluates the initial network design for Dana Trades, identifies its strengths and limitations, and proposes improvements to enhance security, scalability, performance, and reliability as the company grows. The recommendations include implementing employee security training, a honeypot, an intrusion detection system (IDS), additional routing, load balancing, and continuous network optimization to create a more secure and efficient network infrastructure.

Objective 2

This project demonstrated the installation, configuration, and testing of the Uncomplicated Firewall (UFW) on an Ubuntu AWS EC2 instance to secure remote SSH access and strengthen cloud server security. It highlighted the importance of firewall management by implementing access controls, verifying firewall functionality, and documenting the configuration process to help protect systems from unauthorized access.

This project demonstrated the configuration and testing of Simple Network Management Protocol (SNMP) on a Cisco router using Cisco Packet Tracer. The lab showed how to configure SNMP community strings, remotely monitor and manage network devices through the MIB Browser, and verify successful communication, highlighting the importance of network monitoring, configuration management, and secure administrative access.

Objective 3

This project developed an automated Windows Security Audit tool using PowerShell to evaluate system security settings, generate a risk score, and produce detailed HTML, TXT, and CSV reports. The script automated tasks such as auditing Windows Firewall, Microsoft Defender, user accounts, password policies, installed updates, network ports, and event logs, demonstrating practical scripting and security assessment skills.

This project developed a menu-driven Bash script that automated the collection of important system inventory information, including system time, logged-in users, disk space, network information, CPU details, and login history through an interactive menu. The script demonstrated the use of variables, loops, conditional statements, regular expressions, and Linux system commands to simplify routine system administration tasks while providing an efficient computer inventory tool.

This project developed an automated AWS CLI Bash script to launch, monitor, retrieve information from, and terminate an Amazon EC2 instance, demonstrating efficient cloud infrastructure management through automation. It also emphasized security best practices by using IAM roles, avoiding hardcoded credentials, and incorporating CloudTrail and CloudWatch logging to improve security, accountability, and operational efficiency.

Objective 4

This project developed an Incident Response Policy for Desert Shield Technologies that established procedures for identifying, containing, eradicating, and recovering from cybersecurity incidents while defining employee and IT responsibilities. The policy also outlined incident severity levels, reporting procedures, and continuous improvement practices to help protect company assets and maintain business operations during security events.

This security plan established a comprehensive framework for protecting Dana Inc.'s assets, data, and operations through risk assessments, security policies, technical and physical controls, continuous monitoring, and incident response procedures. It also emphasized ongoing security improvements, employee awareness training, regular assessments, and documented communication processes to maintain a strong and adaptive security posture.

Objective 5

This report examined the legal and ethical responsibilities of information security professionals while discussing important security regulations, industry standards, and best practices for protecting sensitive information. It also emphasized the importance of compliance, ethical decision-making, and security controls such as least privilege, multi-factor authentication, patch management, and employee training to help organizations maintain a strong security posture.

 

This presentation explains how organizations can implement NIST SP 800-70 by using standardized security configuration checklists to strengthen system security, reduce misconfigurations, and improve compliance with industry standards. It also outlines a 12-week implementation plan, highlighting the benefits of system hardening, standardized configurations, automation, and reduced operational risk.

 

Objective 6

This report researched, tested, and evaluated several current cybersecurity threats, including phishing, ransomware, and Living-off-the-Land techniques, while examining encryption technologies and their role in protecting sensitive information. Safe security tests involving file hashing, ransomware protection, event log analysis, and BitLocker encryption demonstrated how layered security controls help preserve the confidentiality, integrity, and availability of organizational data.

This project demonstrated the use of OpenStego to securely conceal a text message inside an image using steganography while protecting the hidden data with AES-256 encryption and password authentication. It highlighted how cryptography and steganography work together to improve data confidentiality by hiding sensitive information within a cover file and preventing unauthorized access.