This manual is for IT-FPX3358 Assessment 2, start to submission. The middle deliverable in this course usually turns to safeguards, and it is graded on distinctions rather than on products: which access control model you chose and why, what encryption protects, and where hashing belongs instead. Precision is the currency, because one slip between hashing and encryption tells an evaluator the reading was skimmed. Here you get the method, a structure built from the criteria, and an annotated excerpt from a model. Prefer backup? Hand over the case and a premium original sample lands within 24 to 48 hours, revised at no cost until the guide is met. Your courseroom may print this as IT FPX 3358 Assessment 2 or IT3358 Assessment 2; it is the same deliverable, and IT-FPX3358 Assessment 2 is what this manual walks through.
One honesty note before the manual: Capella revises courses and scoring guides over time, so always write to the exact scoring guide attached to your assessment in the courseroom. The course identity above is verified on capella.edu; the method and structure below are our tutors' approach to it, not Capella's official rubric text.
How IT-FPX3358 Assessment 2 is scored
Four levels per criterion, and the level description is the only rubric that matters to your draft:
| Level | What it means on an access control and cryptography submission |
|---|---|
| Distinguished | The model is named and defended against a named alternative, encryption at rest and in transit are treated as separate controls, and key custody is discussed as the thing that decides both. The paper says what each safeguard fails to cover. |
| Proficient | The right controls appear, correctly described, tied to the right risks. Accurate, and describing rather than choosing. |
| Basic | A tour of security technologies with the organization attached at the end. Where a submission lands when the reading was summarized rather than applied. |
| Non-performance | A required element is absent, or a definition is wrong in a way that undoes the section, most often hashing described as reversible. |
One paragraph earns more here than any other: the one about keys. Algorithm choice is settled by standards you can cite, so it is rarely where a real deployment fails. Who holds the key, where it lives, who can request it, and what happens when the person who generated it leaves are the questions that decide whether encryption protected anything at all.
The IT-FPX3358 Assessment 2 method, step by step
-
Turn the criteria into headings and label each row
Write the criteria out, then mark each one as a definition row, an application row, or a recommendation row. Definition rows want precision, application rows want the organization in the case, and recommendation rows want an owner and a cost. Answering an application row with a definition is the commonest way to lose points you had.
-
Describe who needs what, before choosing a model
A three-branch insurance agency with twenty-two staff has claims handlers who need current client files, one compliance reviewer who needs everything and should change nothing, and two owners who want unrestricted access and do not need it. Write that out first, because access requirements decide the model rather than the other way round.
-
Name the access control family and defend it
Say which family you are recommending and what it buys here. Rights attached to a job rather than to a person survives staff turnover, which matters in an agency where a producer leaves every year and their replacement inherits a copy of their permissions. Then name the alternative you rejected and the condition that would change your mind, such as a need to decide access from context at request time.
-
Apply least privilege and separation of duties to real jobs
Principles score only when they touch named roles. Say that the compliance reviewer gets read access and no delete right, that the person who adds a new vendor is not the person who approves its payment, and that the shared drive folder every branch can reach is the control failure the scenario already contains.
-
Get the cryptography distinctions exactly right
Hashing is one way and encryption is reversible, so a stored password is salted and hashed with a deliberately slow function and never encrypted, because anything encrypted can be decrypted by whoever holds the key. Symmetric work is fast and leaves you with key exchange, asymmetric pairs solve exchange and run slower, and everyday transport protocols use both. In transit and at rest answer different threats.
-
Attach owners and residual exposure, then self-score
Give each control an owner, a rough cost, a sequence, and a way to tell whether it worked. Say what survives it: full disk encryption protects a stolen laptop and nothing at all about a signed-in user copying files to a personal drive. Then mark yourself row by row and submit with time for one revision inside a two business day evaluation window.
A structure that maps to the criteria
Planning targets our tutors use for a controls deliverable of this size, not Capella rules; let your own scoring guide set the real proportions.
| Section | What it must do | Guide |
|---|---|---|
| Access requirements | Every role in the scenario with what it must reach, what it must not, and who approves the difference. | ~250 words |
| Model and rationale | The access control family chosen, what it buys in this organization, and the alternative rejected with its case. | ~250 words |
| Principles applied | Least privilege and separation of duties written against named jobs rather than as definitions. | ~200 words |
| Cryptography decisions | Hashing against encryption, at rest against in transit, algorithm class, and where the keys live. | ~350 words |
| Controls, owners, and gaps | Each safeguard with an owner, a sequence, a measure of success, and what it leaves uncovered. | ~250 words |
| Sources | Standards and control catalogs cited by revision, peer-reviewed work for human claims, current APA. | as needed |
Annotated sample excerpt
An excerpt from a model our team wrote, showing the level of precision a cryptography criterion is actually checking for.
Client documents on the shared drive are encrypted at rest with keys held in a managed service rather than in a file beside the archive, because an archive and its key stored together are one theft, not two.1 Portal passwords are never encrypted; they are salted and hashed with a deliberately slow function, since encryption is reversible by whoever holds the key and a password store should be unreadable even to the agency.2 Encryption in transit is a separate control answering a separate threat, so the branch link carries a current protocol version and the write-up states plainly that at-rest encryption does nothing about a claims handler who is already signed in and copying files to a personal drive.3
- 1Puts key custody in the first sentence instead of the algorithm name, which is where a marker who has run systems will look first.
- 2States the one-way property and the reason it matters here. This single distinction decides a criterion in almost every security course.
- 3Refuses to let one control stand in for another, then names what the safeguard does not cover. Stating the gap is the top-column habit.
The full premium sample for your exact assessment, written fresh to your scoring guide and issue, is free to request. Study it, revise it into your own voice, and submit work you understand.
The five mistakes that cost Distinguished
- Hashing described as a kind of encryption. The two are not interchangeable, and the slip signals to an evaluator that the reading was skimmed.
- Encryption treated as a single control. At rest and in transit answer different threats, and key custody is what decides whether either worked.
- An access model asserted with no alternative considered. The criterion rewards a choice tied to the roles in the case, not a definition of the model you picked.
- Principles stated without touching a job title. Least privilege applied to nobody in particular is a glossary entry rather than a recommendation.
- Controls with no owner and no measure. A safeguard nobody is assigned and nobody can verify is a wish, and the recommendation row reads it that way.
Pre-submission checklist
- Each criterion labeled as definition, application, or recommendation, and answered in kind
- Every role's access need written down before a model is chosen
- The chosen access control family defended against a named alternative
- Hashing and encryption kept distinct, with key custody addressed in its own sentences
- At rest and in transit treated as separate controls answering separate threats
- Owner, sequence, measure, and remaining exposure stated per control, then self-scored per row
Controls section due and the definitions are slippery?
Send the organization in your case and the criteria beside it. You get an access model defended against its alternative, cryptography distinctions written precisely, key custody addressed, and every safeguard given an owner and a gap, inside 24 to 48 hours. Free revision until the guide is met, and no fee on the opening premium sample.