Develop procedures for ensuring a malware-free environment.
This course-wide project introduces you to a variety of tasks and skills that are required for an entry-level security administrator who is tasked with securing systems in a Microsoft Windows environment.
The following tools and resources will be needed to complete this project:
§ Course textbook
§ Access to the Internet
Learning Objectives and Outcomes
You will be able to:
§ Describe the impact of adding Active Directory to an existing Windows network.
§ Develop procedures for changing access controls.
§ Develop procedures for ensuring a malware-free environment.
§ Recommend Group Policy Objects for a Windows environment.
§ Develop procedures for auditing security in a Windows system.
§ Develop procedures for restoring a failed Windows system.
§ Recommend Windows hardening techniques.
§ Describe security goals and write policies for securing Windows applications.
§ Ensure the integrity of all evidence collected in a Windows environment.
Overall Project Scenario
Always Fresh Foods Inc. is a food distributor with a central headquarters and main warehouse in Colorado, as well as two regional warehouses in Nevada and Virginia.
The company runs Microsoft Windows 2019 on its servers and Microsoft Windows 10 on its workstations. There are 2 database servers, 4 application servers, 2 web servers, and 25 workstation computers in the headquarters offices and main warehouse. The network uses workgroups, and users are created locally on each computer. Employees from the regional warehouses connect to the Colorado network via a virtual private network (VPN) connection.
Due to a recent security breach, Always Fresh wants to increase the overall security of its network and systems. They have chosen to use a solid multilayered defense to reduce the likelihood that an attacker will successfully compromise the company’s information security. Multiple layers of defense throughout the IT infrastructure makes the process of compromising any protected resource or data more difficult than any single security control. In this way, Always Fresh protects its business by protecting its information.
Project Part 1: Active Directory Recommendations
Assume you are an entry-level security administrator working for Always Fresh. You have been asked to evaluate the option of adding Active Directory to the company’s network.
Create a summary report to management that answers the following questions to satisfy the key points of interest regarding the addition of Active Directory to the network:
1. System administrators currently create users on each computer where users need access. In Active Directory, where will system administrators create users?
2. How will the procedures for making changes to the user accounts, such as password changes, be different in Active Directory?
3. What action should administrators take for the existing workgroup user accounts after converting to Active Directory?
4. How will the administrators resolve differences between user accounts defined on different computers? In other words, if user accounts have different settings on different computers, how will Active Directory address that issue? (Hint: Consider security identifiers [SIDs].)
§ Internet access
§ Course textbook
§ Format: Microsoft Word (or compatible)
§ Font: Arial, size 12, double-space
§ Citation Style: Follow your school’s preferred style guide
§ Length: 2 to 4 pages
§ I addressed all questions required for the summary report.
§ I created a well-developed and formatted report with proper grammar, spelling, and punctuation.
§ I followed the submission guidelines