CIS 4200 - Security Penetration Testing
College of Computer & Information Technology
Credit(s): 3
Contact Hours: 47
Contact Hours: 47
Effective Term Spring 2022 (600)
Requisites
Prerequisite CIS 2352 with a minimum grade of C and
(Admission to Technology Development and Management (Bachelor of Applied Science) (TMGT-BAS)
Subplan- CSDR or
Admission to Cybersecurity (Bachelor of Applied Science) (CYSEC-BAS))
(Admission to Technology Development and Management (Bachelor of Applied Science) (TMGT-BAS)
Subplan- CSDR or
Admission to Cybersecurity (Bachelor of Applied Science) (CYSEC-BAS))
Course Description
This course covers penetration testing and vulnerability assessment. Topics include compliance-based assessment planning and scoping, information gathering & vulnerability identification, attacks & exploits, penetration testing tools, and reporting and communication. This course contains foundational coverage in preparing for CompTIA's PenTest+. Students will need remediation to ensure success on the exam.
Learning Outcomes and Objectives
- Students will plan and score an assessment by:
- Explaining the importance of planning for an engagement
- Explaining key legal concepts
- Explaining the importance of scoping an engagement properly
- Students will perform vulnerability scanning and penetration testing using appropriate tools and techniques by:
- Conducting information gathering using appropriate techniques
- Performing a vulnerability scan
- Analyzing vulnerability scan results
- Explaining the process of leveraging information to prepare for exploitation
- Explaining weaknesses related to specialized systems
- Students will analyze attacks by:
- Comparing and contrasting social engineering attacks
- Exploiting network-based vulnerabilities
- Exploiting wireless and RF-based vulnerabilities
- Exploiting application-based vulnerabilities
- Exploiting local host vulnerabilities
- Students will master penetration testing tools by:
- Using nmap to conduct information gathering exercises
- Comparing and contrasting various use cases of tools
- Analyzing tool output or data related to a penetration test
- Analyzing a basic script
- Students will produce a written report of proposed remediation techniques by:
- Using report writing and handling best practices
- Explaining post-report delivery activities
- Recommending mitigation strategies for discovered vulnerabilities
- Explaining the importance of communication during the penetration testing process
Criteria Performance Standard
Upon successful completion of the course the student will, with a minimum of 70% accuracy, demonstrate mastery of each of the stated objectives through classroom measures developed by individual course instructors.
History of Changes
C&I Approval: 09/05/2019, BOT Approval: 09/24/2019, Effective Term: Spring 2020 (570).
C&I Approval: , BOT Approval: , Effective Term: Summer 2021 (590).
C&I Approval: , BOT Approval: , Effective Term: Spring 2022 (600)
Related Programs
- Cybersecurity (CYSEC-BAS) (610) (Active)
