This manual is for IT-FPX3358 Assessment 1, start to submission. The opening deliverable in this course usually asks for analysis before advice: what the organization holds, what could go wrong with it, how likely and how damaging that is, and only then what to do. Reverse those and the submission fails, because safeguards with no analysis in front of them answer a question the guide never asked. What follows is the method our tutors use, a structure keyed to the criteria, and an annotated model excerpt. Rather delegate it? Send the case and a premium original sample comes back inside 24 to 48 hours, revised free until every row is met. Your courseroom may print this as IT FPX 3358 Assessment 1 or IT3358 Assessment 1; it is the same deliverable, and IT-FPX3358 Assessment 1 is what this manual walks through.
One honesty note before the manual: Capella revises courses and scoring guides over time, so always write to the exact scoring guide attached to your assessment in the courseroom. The course identity above is verified on capella.edu; the method and structure below are our tutors' approach to it, not Capella's official rubric text.
How IT-FPX3358 Assessment 1 is scored
FlexPath marks each criterion at one of four levels and never as a percentage. The wording of the level is the brief:
| Level | What it means on a risk analysis submission |
|---|---|
| Distinguished | Threats and weaknesses are kept apart, each rating is reproducible from stated reasoning, and residual risk is named after the controls are applied. Saying what the analysis cannot settle is the extra move. |
| Proficient | Assets, threats, and ratings are all present and the ordering is defensible. Complete, with the method left implicit. |
| Basic | A competent essay about security in general with the organization mentioned twice. The single commonest result in this course. |
| Non-performance | A required element is absent, most often the likelihood and impact reasoning, so the criterion that pays for analysis has nothing to read. |
Vocabulary discipline decides more rows here than technical depth. A threat is the actor or event, a weakness is what it would use, risk is the combination of how likely that is and what it would cost, and an exploit is the working method. A paper that treats those four as synonyms loses the analysis row before the recommendations begin.
The IT-FPX3358 Assessment 1 method, step by step
-
Read the guide, then read the scenario twice
Set the criteria out as headings first, then mine the case for what an analysis actually needs: what data exists, where it sits, who touches it, what the organization does for money, what has already gone wrong, and what it is legally obliged to protect. Anything the case does not say becomes a declared assumption in a short list at the front.
-
Inventory and rank the assets before naming a single threat
List what is worth protecting and rank it by what losing it would cost. A school district running roughly four hundred lab machines on an operating system that no longer receives security updates holds student records, staff credentials, and the testing schedule, and those three are not equally valuable. Say which one you would protect first if the budget covered only one.
-
Pair each threat with the weakness it would use
Write the pairing explicitly, one sentence each, because an unpaired threat is a hazard list and a paired one is analysis. An unsupported operating system on machines students use daily pairs with credential theft and with malware that no longer meets a patched defense.
-
Rate likelihood and impact so a reader could reproduce you
State your scale before you use it and define each level in a line. Then rate each pairing and show the reasoning: what activity you observed, what exposure exists, what the consequence would be. A qualitative rating is defensible when the reasoning is visible, and it is worth more than a number with no basis behind it.
-
Show the arithmetic once, then say what it assumed
Work one quantitative example through so the analysis criterion has method to mark. Value the asset, estimate the share a single event destroys, multiply for the loss from one event, multiply again by how often you expect it in a year, and compare that annual figure with what a control costs. Then admit every input was an estimate, and say which view you would take to a superintendent.
-
Order the risks, state residual risk, and self-score
Rank the findings and defend the top three over the rest. Attach the control you would apply and the risk that survives it, because no safeguard removes a risk entirely and pretending otherwise reads as inexperience. Then mark yourself against each row and submit early, since an evaluated attempt can take two business days to return.
A structure that maps to the criteria
The word counts here are planning targets our tutors use for a risk analysis at this level, not Capella rules; expand whichever section your scoring guide weights most.
| Section | What it must do | Guide |
|---|---|---|
| Scope and assumptions | The organization, the systems in scope, what you excluded and why, and every assumption you had to make. | ~200 words |
| Assets | What is worth protecting, ranked by consequence, with the ranking justified rather than asserted. | ~200 words |
| Threats and weaknesses | Threat sources named from cited reporting, weaknesses identified, and each pairing stated in a sentence. | ~300 words |
| Risk analysis | The scale defined, each pairing rated for likelihood and impact, the reasoning shown, the results ordered. | ~350 words |
| Controls and residual risk | The safeguard for each top risk, who owns it, and the exposure that remains afterwards. | ~250 words |
| Sources | Framework and control documents cited by revision, sector figures dated in the sentence, current APA. | as needed |
Annotated sample excerpt
A model excerpt from our team, showing what a risk statement reads like when it is written for a reader who will rank it against other risks.
Roughly four hundred lab machines across eleven schools run an operating system the vendor stopped issuing security fixes for last year, and they share one local administrator password set during the original imaging.1 Likelihood is moderate: the machines are used by students daily, they reach the internet without filtering on the guest network, and the district logged two malware cleanups on that image in the previous term. Impact is high, because the same credential opens every machine in the estate and the image holds cached staff logins from parent evenings.2 The recommended controls are a staged migration to a supported version before the autumn term and unique local administrator credentials in the interim, and residual risk stays moderate until the migration finishes because an unpatched machine remains unpatched whatever the password is.3
- 1Opens with counts and a named weakness rather than with a claim that the district is vulnerable. Numbers are what let a reader rank this against the next finding.
- 2Gives likelihood and impact separate reasoning, each drawn from something in the scenario. A rating with visible reasoning is reproducible, which is exactly the criterion.
- 3Names the control, the sequence, and the risk that survives it. Residual risk stated honestly is the move the top column is written around.
The full premium sample for your exact assessment, written fresh to your scoring guide and issue, is free to request. Study it, revise it into your own voice, and submit work you understand.
The five mistakes that cost Distinguished
- Controls recommended before any risk is stated. A shopping list of safeguards with no analysis in front of it answers a question the guide did not ask.
- Threat and weakness used as the same word. The pairing is the analysis, and collapsing the two terms removes the thing being marked.
- Ratings with no scale and no reasoning. High and low mean nothing until the levels are defined and the evidence behind each rating is shown.
- Residual risk left at zero. Every control leaves something behind, and a paper that implies otherwise reads as inexperienced.
- Framework citations carrying no revision number. Control documents are living publications, and an undated reference cannot be checked by anyone.
Pre-submission checklist
- Assumptions declared in a list at the front rather than buried in the text
- Assets ranked by consequence with the ranking defended
- Every threat paired in writing with the weakness it would use
- The rating scale defined before use, and each rating supported by evidence from the case
- One quantitative example worked through, with its assumptions admitted
- Residual risk stated for each top control, self-scored per row, submitted early in the week
Risk analysis due and the case is a wall of text?
Send the scenario and the criteria attached to it. You get an asset ranking with reasoning, threats paired to weaknesses, ratings a reader could reproduce, and residual risk stated rather than rounded away, inside 24 to 48 hours. Revisions run free until the guide is satisfied and the first premium sample carries no charge.