cyber security enginner
cyber security enginner
Engineer
Sample
Assessment Brief
Version 1.0 September 2024 Visit ncfe.org.uk Call 0191 239 8000
NCFE Level 4 Diploma: Cyber Security Engineer: sample assessment – full unit 2
Student name / ID
number
Unit 05 Risk assessment in cyber security (J/651/0937)
Unit number, title and
LO1: Examine operating system security features
learning outcomes (LOs)
LO2: Assess risk management in cyber security
Assignment title Risk within cyber security
Scenario
You have recently joined a company as a cyber security intern. This small non-profit
organisation provides support and advocacy for victims of domestic abuse. They rely
heavily on donations and have a very limited IT budget.
Key details
Staff: five full-time employees and several volunteers. Some staff members are less tech-
savvy than others.
Data: sensitive donor information (names, addresses, contact details, and sometimes
financial information). Additionally, they store case notes with potentially identifying
information about the people they help.
Operations: heavy reliance on email, web browsing for research and outreach, and basic
office software. Volunteers sometimes use their personal devices to access the
organisation's shared file storage.
Challenges
Compliance: there is a concern about potential compliance issues with data protection
regulations, as their practices are not very formalised.
Threats: the sensitive nature of their work makes them a potential target for cyber attacks
aimed at disrupting services or stealing information.
Tasks
Task 1
Write a report describing the security features of Windows Professional (7 and 10). Ensure
you recommend specific security features of the operating system for the company. You
may consider including the use of third-party applications, such as antivirus software.
Task 2
You have been given access to a simulated environment mirroring your company network
and systems. Conduct a risk assessment, paying close attention to vulnerabilities
stemming from outdated operating systems, user practices (personal devices), and
potential lack of security awareness. Create a prioritised mitigation plan with specific
recommendations, keeping in mind the cost constraints.
Version 1.0 September 2024 Visit ncfe.org.uk Call 0191 239 8000
NCFE Level 4 Diploma: Cyber Security Engineer: sample assessment – full unit 3
Evidence requirements
You must provide:
• a written report
• risk assessment documentation, including a mitigation plan.
Unit learning outcomes (LOs)
LO1: Examine operating system security features
LO2: Assess risk management in cyber security
Grading criteria
Resources
Example vulnerabilities:
• outdated operating systems – Windows 7 and Windows Server 2010 R2 are no longer
supported by Microsoft, making them highly vulnerable to known exploits
• personal devices (bring your own device) – unmanaged personal devices connecting to
the network introduce risks of malware infection and unauthorised data access
• lack of security awareness – staff might be susceptible to phishing scams, poor
password practices, or accidental data leaks.
Version 1.0 September 2024 Visit ncfe.org.uk Call 0191 239 8000