This manual is for IT-FPX4070 Assessment 1, start to submission. The opening deliverable in Cyber Defense and Countermeasures usually asks you to describe the ground before defending it: the estate drawn in zones, the assets that would hurt to lose, the adversary the estate invites, and the boundaries you would put between them. Nothing gets bought in this deliverable, because a countermeasure recommended before a threat is named collapses the analysis row. Here you get the method, a structure built from the criteria, and an annotated model excerpt. Rather hand it across? Send the scenario and a premium original sample returns inside 24 to 48 hours, revised free until every row is met. Your courseroom may print this as IT FPX 4070 Assessment 1 or IT4070 Assessment 1; it is the same deliverable, and IT-FPX4070 Assessment 1 is what this manual walks through.
One honesty note before the manual: Capella revises courses and scoring guides over time, so always write to the exact scoring guide attached to your assessment in the courseroom. The course identity above is verified on capella.edu; the method and structure below are our tutors' approach to it, not Capella's official rubric text.
How IT-FPX4070 Assessment 1 is scored
FlexPath scores criterion by criterion at four levels with no letter grade anywhere. Read the level you are aiming at as the writing brief:
| Level | What it means on an environment and threat model submission |
|---|---|
| Distinguished | Zones are justified by what crosses their boundaries, adversary behavior comes from cited reporting for the sector, and the assumptions the case did not answer are declared. What the model leaves out is stated rather than hidden. |
| Proficient | The estate, the assets, and a threat model are all present and the boundaries make sense. Sound, with the reasoning left for the reader to infer. |
| Basic | A drawing of the network with a paragraph about hackers. This is where a submission lands when the threat model was written from general knowledge. |
| Non-performance | A required element is absent, most often the asset ranking or the data flow between zones, so the criterion built on it cannot be marked. |
One discipline separates the top two columns here: every later recommendation has to point at something on your drawing. Number the components, refer to those numbers in the prose, and keep the figure to what a control could sit on. Desk-level detail nobody will grade only makes the picture unreadable.
The IT-FPX4070 Assessment 1 method, step by step
-
Turn the criteria into headings, then build a threat table
Four questions produce a usable model: what would an attacker want here, how would they get in given what the case describes, what would they do once inside, and what would that cost. Answer them in a short table before writing prose, and the rest of the deliverable has a spine to hang on.
-
Describe the estate as zones rather than as an inventory
A payments startup standing up its first production environment has a public edge that accepts card requests, an application tier that must never accept an inbound connection from the internet, a data tier that holds tokenized card references, and an administrative path that only engineers use. Four zones, four different levels of trust, and the boundary between each pair is where your later controls will live.
-
Rank assets by what losing them would actually cost
Not everything in the case matters equally. The token vault, the settlement records, and the deployment credentials are the three whose loss ends the company, and the marketing site is not among them. Say so plainly, because an unranked asset list produces a defense that spends evenly and protects nothing well.
-
Let a constraint decide the region, and write the reasoning down
Choosing where the environment runs is a security decision as much as a latency one. Say which constraint decided it: where the card data may legally reside, which region the acquiring bank sits closest to, and whether the provider offers the isolation and logging services the design depends on in that region. Name the option you rejected and the cost of rejecting it, because a choice with a rejected alternative reads as engineering.
-
Draw the boundaries once, then state what crosses each one
For every boundary, write the traffic that is allowed, the direction it flows, and who owns the exception list. Default deny in both directions is the posture to state explicitly, and outbound rules deserve their own sentences, since traffic leaving is how stolen data and command channels travel. An estate with no egress position has left the exit unattended.
-
Declare assumptions, self-score, and submit early
Anything the case does not tell you becomes a declared assumption at the front, because an announced assumption is analysis and a hidden one is invention. Then mark your own draft against each row, rewrite whatever sits below the top level, and upload early in the week given a two business day evaluation.
A structure that maps to the criteria
The word counts below are planning targets our tutors use for a defensive design of this size, not Capella rules; expand whichever section your guide weights heaviest.
| Section | What it must do | Guide |
|---|---|---|
| Scope and assumptions | What you are defending, what is out of scope, and every gap in the case you had to fill. | ~200 words |
| The estate in zones | Each zone, what it holds, the trust you place in it, and the traffic crossing its boundaries. | ~300 words |
| Assets ranked | What would hurt to lose, ordered by consequence, with the ordering defended in a line each. | ~200 words |
| Threat model | Adversary type, likely entry, likely behavior inside, and the reporting you drew it from. | ~300 words |
| Boundary positions | Default posture, allowed flows in both directions, exception owners, and review dates. | ~250 words |
| Sources | Control catalogs by revision, behavior references by identifier, threat figures dated in the sentence, current APA. | as needed |
Annotated sample excerpt
An excerpt from a model our team wrote, showing how a zone boundary reads when the reasoning is on the page rather than in the author's head.
The application tier accepts connections only from the public edge and only on the single port the payment service listens on, and it initiates nothing outbound except to the token vault and the log collector.1 That outbound restriction is the point of the boundary: an application server with unrestricted egress can reach an attacker's collection host as easily as it reaches the vault, and a startup with no dedicated operations staff will not notice the difference in traffic.2 Administrative access does not cross this boundary at all, arriving instead through a jump host in its own zone, so the number of paths into the tier stays at two and both are logged.3
- 1States the allowed traffic in both directions in one sentence. A boundary described only inbound is half a boundary and marks as half.
- 2Explains why the restriction exists using a fact from the scenario, which is what a criterion about justified segmentation is written to find.
- 3Counts the paths. A number a reader can check beats an adjective about hardening every time.
The full premium sample for your exact assessment, written fresh to your scoring guide and issue, is free to request. Study it, revise it into your own voice, and submit work you understand.
The five mistakes that cost Distinguished
- A flat estate described as segmented. Zones that all trust each other are one zone with internal labels, and a marker will read them that way.
- Countermeasures recommended in the first deliverable. Naming products before naming threats answers a criterion from a later stage and skips this one.
- Assets listed without ranking. An even list produces an even defense, and the criterion asks which loss the organization could not absorb.
- No egress position anywhere. Blocking arrivals while ignoring departures leaves the path stolen data takes wide open.
- A threat model written from general knowledge. Behavior claims need a cited reference for that sector, or the model is a list of things you have heard of.
Pre-submission checklist
- Assumptions declared at the front, each one tied to a gap in the case
- Every zone described with what it holds and the trust placed in it
- Assets ranked by consequence with the ordering defended
- Threat behaviors drawn from cited reporting rather than from memory
- Allowed traffic stated in both directions for every boundary, with exception owners named
- Components numbered and referenced in the prose, then self-scored per row
Threat model due and the scenario is vague?
Send the case, the criteria, and any network detail you are permitted to share. You get zones justified by what crosses them, an asset ranking with reasoning, and a threat model built from cited reporting, back inside 24 to 48 hours. Revision stays free until the guide is met and the first premium sample costs nothing.