联系我们: 手动添加方式: 微信>添加朋友>企业微信联系人>13262280223 或者 QQ: 1483266981
MIS761 Cyber Security Strategies
Trimester 2 2025
Mock EXAM
DUE DATE AND TIME: The start date and time will be as per the University Exam T2 2025 Exam timetable available via StudentConnect.
PERCENTAGE OF FINAL GRADE: 50%
HURDLE DETAILS: Not Applicable
SUGGESTED WRITING TIME: 2 hours
WORD COUNT: 2000 words
Instructions
This end of unit assessment task is available for 24 hours, with a suggested writing time of 2 hours. You may choose when to complete the task within this time frame.
You are allowed to access all resources during the assessment, except for contract cheating sites, artificial intelligence content generation sites, resources that undermine the purpose of the assessment, and help from peers or others (unless specified otherwise in the assessment instructions). It is important that you complete this task individually. Your submission will be reviewed to detect contract cheating, collusion, and/or plagiarism.
The end of unit assessment task will be released in the CloudDeakin unit site under a dedicated End of Unit Assessment module at the date and time scheduled in the University Exam T2 2025 Exam timetable.
This end of unit assessment task constitutes 50% of your assessment in this unit.
This end of unit assessment task comprises 3 questions. You are required to answer ALL 3 questions.
Download this assessment paper and record all your answers in the provided spaces for each question. Save your answer document on your computer using the following naming convention: [Student ID]_[Unit Code]_EOUA. For example: 216123123_UNITCODE_EOUA. Once completed, submit the answer document to the End of Unit Assessment Submission folder on the CloudDeakin unit site.
Late submissions and/or submissions in a file format other than Microsoft Word (.docx) will not be marked.
Remember to save your work regularly. If you encounter any technical issues with CloudDeakin, please contact the IT Service Desk online or via phone (1800 463 888; +61 5227 8888 if calling from outside Australia) and record your ticket number. This evidence is necessary for any Special Consideration application due to technical issues during the end-of-unit assessment period.
MIS761 Cyber Security Strategies
Trimester 2 2025
Mock EXAM
Case Study
Zenith Consulting Group, a mid-sized management consultancy based in Sydney with offices in Melbourne and Brisbane, employs around 200 professionals and specializes in providing strategic advice, business transformation, and digital solutions across diverse sectors such as retail, hospitality, and education. Over the years, Zenith has expanded its services to include digital marketing and customer engagement strategies, leveraging digital channels like email marketing, telemarketing, and social media campaigns. The firm’s success relies heavily on its extensive database of customer information, which is used to tailor marketing campaigns and deliver personalized services. As such, Zenith’s operations depend on its ability to manage and utilize data effectively while maintaining trust with its clients and their customers.
In its pursuit of growth, Zenith has consistently adapted to market trends, achieving an average annual revenue increase of 8% over the past five years. However, this expansion into digital marketing has introduced new complexities, particularly in aligning marketing activities with legal and ethical standards. The consultancy industry is highly competitive, and Zenith recognizes the importance of managing operational risks, including those related to data security and regulatory compliance, to safeguard its reputation and market position. This evolving landscape necessitates a careful examination of how Zenith can refine its internal policies, assess the cost-effectiveness of risk management strategies, and prepare for potential cybersecurity incidents.
Despite its growth, Zenith faces challenges in balancing expansion with sustainable operational management. The firm operates on a moderate budget, with substantial portions allocated to staff salaries, business development, and client management. The budget for IT and cybersecurity remains limited, accounting for only about 5% of overall expenditures, which primarily supports basic IT infrastructure such as servers, networking equipment, and essential software. Consequently, there is minimal room for investment in advanced cybersecurity measures or comprehensive staff training.
Operationally, Zenith relies on its digital platforms and client databases to deliver consulting and marketing services. However, the rapid growth into digital marketing has highlighted gaps in its IT infrastructure and data management practices. Zenith’s IT environment is currently basic, with an on-premises data center and limited cloud services. The cybersecurity framework is also underdeveloped, featuring only standard antivirus software, firewalls, and a basic intrusion detection system. A cohesive, company-wide cybersecurity strategy is lacking, and the small IT team, comprising just five members, is frequently overwhelmed by both routine operations and security management tasks.
Zenith’s current security measures are rudimentary, including basic access controls and periodic password updates, but there is no formal incident response plan or regular vulnerability assessments. Employee security awareness is low, with infrequent training sessions that cover only generic threats such as phishing. Management acknowledges that while the existing IT and security measures have been adequate to date, they may not suffice to protect the company’s expanding digital footprint and sensitive data from more sophisticated cyber threats.
With its growth ambitions and the increasing complexity of cyber threats, Zenith must evaluate the cost-effectiveness of potential cybersecurity investments and develop a stronger risk management strategy that aligns with both its operational needs and budget constraints. This scenario sets the stage for exploring how Zenith can enhance its security policies, conduct a cost-benefit analysis for risk management, and establish effective incident response strategies to safeguard its assets and maintain client trust in a cost-efficient manner.
Question 1.
Zenith recently completed a major digital transformation project for a key client. Shortly after the project was finalized, the company’s internal network was compromised by a ransomware attack. The attackers encrypted critical business files, including sensitive client data and ongoing project documents, demanding a significant ransom payment for decryption keys. The attack brought Zenith’s operations to a standstill, preventing access to essential files and disrupting all digital services for several days. As a result, client projects were delayed, and some clients reported concerns over the potential exposure of their confidential information, leading to reputational damage and a loss of trust.
a)In plain language, describe what a ransomware attack is and discuss the various forms it can take. Explain the potential impacts of the attack could have on a business.
[8 Marks]
Answer below here
b)Select three criteria recommended by the National Institute of Standards and Technology (NIST) that Zenith should consider when evaluating a potential containment strategy for their incident response plan. Provide a brief explanation of why each criterion is important for Zenith’s specific operational context.
[15 Marks]
Answer below here
c)Identify and describe three methods that Zenith could use to effectively test their business continuity and disaster recovery plans. In your answer, consider the agency’s operational needs and budget constraints. Explain how each method would help ensure the agency’s preparedness for potential disruptions.
[11 Marks]
Answer below here
Question 2.
Zenith has implemented a Data Breach Notification Policy to address incidents involving unauthorized access to personal information. Your task is to analyze the policy to determine if it meets the legal obligations for data breach notifications.
Data Breach Notification Policy
Policy Objective: To notify affected individuals and the public of any data breaches involving personal information that may result in serious harm.
Notification Procedure:
In the event of a data breach, Zenith Consulting Group will publish a notice on its official website.
The notice will be placed on a dedicated “Data Security” page accessible via the website footer.
The notification will include a brief description of the breach, the type of information compromised, and steps taken to address the breach.
No direct communication (e.g., email, phone calls) will be made to affect individuals regarding the breach.
The notification will not be published on the homepage or in any prominent location to avoid unnecessary alarm.
The notification will remain on the website for a minimum of 30 days before being archived.
Review and Approval: This policy is subject to review and approval by the Chief Information Officer (CIO) and will be updated as necessary to comply with applicable laws and regulations.
a)Does the current Data Breach Notification Policy meet the legal requirements for handling data breaches Provide a detailed explanation, considering whether the policy meets the criteria for eligible notifications and the adequacy of the chosen notification methods.
[15 Marks]
Answer below here
b)After reviewing the Policy, Zenith decides to make certain amendments. To manage the change associated with the policy updates, it is crucial to communicate effectively with the users within the entity. You may need to develop a SETA program to address potential concerns. Select three design factors you would prioritize when designing this program and explain how they would help in managing the change and addressing user concerns.
[10 Marks]
Answer below here
c)The personal information of Zenith business clients and staff has recently been accessed in a data breach that exposed more than 30,000 files held on its businesses IT systems. The breach has affected both business clients with exposure of financial details including credit card details and staff information such as usernames, passwords, email addresses, driver’s licence, superannuation account details and tax file numbers.
Please outline what principles are affected in this breach. Use the CIA Triad to answer this question.
[10 Marks]
Answer below here
Question 3.
a) As Zenith transitions toward offering cloud-based solutions and expanding its digital operations, it is critical to prioritize the company’s information assets based on various risk factors. Below is a table outlining Criterion Weights for three key criteria and the importance of each asset in relation to those criteria. Calculate the Weighted Score for each asset, rank them in order of priority, and provide a justification for your ranking.
Answer below here
Asset Criteria 1 Critical to Success Criteria 2
Cost to Replace/Protect Criteria 3 Public Image Weighted Score
Criterion Weight (1-100) 40 30 30 100
Client Database 0.9 0.8 1.0
Proprietary Software Modules 0.8 0.9 0.7
Cloud Infrastructure 1.0 0.9 0.9
Employee Personal Data 0.6 0.7 0.8
Financial Systems 0.7 0.8 0.9
[10 Marks]
b) As part of your cybersecurity assessment for Zenith, you are required to evaluate the potential risks associated with various assets. The following table outlines the vulnerabilities identified for three key assets, along with their likelihood and impact scores.
Calculate the Risk Rating for each vulnerability by multiplying the Likelihood by the Impact. Rank the vulnerabilities based on the Risk Rating.
Answer below here
Asset Vulnerability Likelihood (1-10) Impact (1-10) Risk Rating (Likelihood × Impact)
Client Database Phishing Attacks 8 9
Unauthorized Access 5 7
Proprietary Software Modules Unpatched Software 6 8
Software Exploits 7 7
Cloud Infrastructure DDoS Attacks 6 9
Poor Access Control 4 8
[10 Marks]
c) In plain language, describe what is Network Segmentation.
[4 Marks]
Answer below here
d) Review the screenshot of the promotional SMS below. Identify any potential violations of relevant regulations and explain the implications for the business.
[7 Marks]
Answer below here


发表评论