How to write IT-FPX4070 Assessment 2

The short answer

This manual is for IT-FPX4070 Assessment 2, start to submission. The middle deliverable in this course usually asks for the defenses themselves: layers that differ in kind, each measure labeled by the function it performs, each one tied to a behavior it interrupts, and each one priced against what it removes. Defense in depth is graded as an argument rather than as a phrase, so two firewalls in series will not count as two layers. Ahead: the method, a structure keyed to the criteria, and one annotated model excerpt. Want it built alongside you? Hand over the case and a premium original sample lands in 24 to 48 hours, revised at no charge until the guide is satisfied. Your courseroom may print this as IT FPX 4070 Assessment 2 or IT4070 Assessment 2; it is the same deliverable, and IT-FPX4070 Assessment 2 is what this manual walks through.

One honesty note before the manual: Capella revises courses and scoring guides over time, so always write to the exact scoring guide attached to your assessment in the courseroom. The course identity above is verified on capella.edu; the method and structure below are our tutors' approach to it, not Capella's official rubric text.

IT-FPX4070 Assessment 2 grading scale at Capella FlexPath, the criterion levels this assessment is scored on, from Capella Tutors
How Capella FlexPath grades IT-FPX4070 Assessment 2, visualized by Capella Tutors.

How IT-FPX4070 Assessment 2 is scored

Four levels per criterion and no percentages. What the level says is what your recommendation section has to do:

LevelWhat it means on a layered countermeasures submission
DistinguishedLayers differ in kind, each carries its function label and the behavior it interrupts, and each has a bypass you have already thought about with a compensating measure beside it. Naming the bypass is the move being paid for.
ProficientThe right controls appear, tied to the right risks, sequenced sensibly. Defensible, with the failure modes unexamined.
BasicA list of security measures with severity marked critical throughout. Where a submission lands when nothing was prioritized.
Non-performanceA required element is absent, most often the control functions or the outbound rules, so the criterion resting on it has nothing to score.

Label every recommendation with its function and the section starts reading as engineering. Preventive measures stop the action, detective measures notice it, corrective measures undo the damage, and compensating measures substitute for something the organization cannot deploy. A paper that calls all four security reads as a summary of the textbook.

The IT-FPX4070 Assessment 2 method, step by step

  1. Build the criteria into headings and inherit the threat model

    Restate the adversary behavior you are defending against in a short paragraph, then treat that paragraph as the test every later recommendation must pass. A control that interrupts nothing in your own model is scope you added for the sake of length.

  2. Size the defense to the organization actually in the case

    A brewery running two shifts with a two-person technology team cannot operate what a bank can. Recommend measures that survive that constraint: managed services rather than appliances somebody must tune, automatic patching rather than a monthly review meeting, and a default configuration that fails closed. A design nobody in the scenario can run scores as a design nobody will run.

  3. Choose layers that differ in kind, and say why they differ

    A boundary control, a host control, an identity control, and a monitoring control are four layers, because an attacker who defeats one meets an unfamiliar obstacle at the next. Two products doing the same job in sequence are one layer purchased twice. State the kind of each layer and the step in the attack path it interrupts.

  4. Write the outbound rules, not only the inbound ones

    Give egress its own section. Say which systems may initiate outbound sessions at all, which destinations are permitted, and what happens to everything else. In a brewery that means the production line controllers reach nothing outside their own segment, and the office network reaches the internet through one filtered path. Outbound restriction is what shortens an incident once prevention has already failed.

  5. Give each control a bypass and a compensating measure

    Every safeguard fails a particular way, and naming it first is what makes the recommendation credible. Multifactor authentication reduces credential theft and does nothing about a stolen session token, so session lifetime and reauthentication for sensitive actions belong in the same paragraph. Application allowlisting stops unsigned binaries and not a signed interpreter running a hostile script, so script logging sits beside it.

  6. Price it, sequence it, then self-score and submit

    Attach a rough cost, a position in the order of work, and a way to tell whether each measure worked. Where the cost exceeds the exposure removed, say so and recommend acceptance with a named accepting authority, unless a regulator requires the control regardless or the consequence would end the business. Then mark yourself against every row and submit early inside the two business day window.

A structure that maps to the criteria

Planning targets our tutors use for a countermeasure deliverable at this level, not Capella rules; let your own guide decide the weighting.

SectionWhat it must doGuide
Behavior being defended againstThe attack path restated, step by step, as the test each recommendation has to pass.~200 words
ConstraintsStaff, budget, uptime, and skills available in the case, and what those rule out.~150 words
The layersEach layer with its kind, its function label, and the step in the path it interrupts.~350 words
Outbound controlWho may initiate sessions outward, to where, and what happens to everything else.~250 words
Bypasses and compensating measuresHow each control fails, and the measure that covers the gap it leaves.~250 words
Cost, sequence, and sourcesRough cost, order of work, success measure per control, and references in current APA.~200 words

Annotated sample excerpt

One recommendation from a model our team produced, at the length and register the top column describes in a countermeasure section.

Sample excerpt: a layered recommendation Original model · Capella Tutors

Preventive, at the identity layer: phishing-resistant multifactor authentication on the remote access path and on the accounting application, which interrupts the credential-reuse step in the attack path described above and costs two hours of setup per user group.1 The bypass is a session token stolen after a successful sign-in, which no authentication control can stop, so a fifteen-minute idle timeout and reauthentication before any payment change sit beside it as compensating measures.2 Success is measured by the share of remote sessions using the strong factor, reported monthly, with a target of every account inside one quarter and a named owner in the two-person technology team.3

  • 1Opens with the function and the layer, then the behavior interrupted. Three facts before any product could have been named, which is the order the criterion rewards.
  • 2Concedes the failure mode and covers it in the same breath. A defender who names the gap sounds like somebody who has run a network.
  • 3Attaches a measure, a target, and an owner, so the recommendation can be funded and checked rather than only admired.

The full premium sample for your exact assessment, written fresh to your scoring guide and issue, is free to request. Study it, revise it into your own voice, and submit work you understand.

Get the full sample free

The five mistakes that cost Distinguished

  • Two of the same control called two layers. Layers have to differ in kind, or an attacker who defeats one has defeated both.
  • Products named where functions were asked for. A criterion about countermeasures wants the capability and the reason, not a brand and a datasheet.
  • Recommendations the case could never operate. A tool that needs a full-time analyst is not a recommendation for a two-person team.
  • Every measure rated critical. Uniform severity tells a reader that no prioritization happened anywhere in the analysis.
  • No bypass admitted for any control. Every safeguard fails a particular way, and pretending otherwise is the fastest way to sound inexperienced.

Pre-submission checklist

  • The attack path restated and used as the test for every recommendation
  • Constraints from the case stated, with what they rule out
  • Layers differing in kind, each labeled preventive, detective, corrective, or compensating
  • Outbound rules written with a default posture and a named exception owner
  • A bypass and a compensating measure recorded for each significant control
  • Cost, sequence, success measure, and owner attached, then self-scored per row

Countermeasure section due and everything reads critical?

Send the scenario, the criteria, and any tooling the organization already runs. You get layers that differ in kind, functions labeled, outbound rules written, and a bypass with a compensating measure for each control, inside 24 to 48 hours. Free revision until the guide is met, and no charge on the first premium sample.

Keep going

Online now