How to write IT-FPX4071 Assessment 2

The short answer

This manual is for IT-FPX4071 Assessment 2, start to submission. The middle deliverable in this course usually covers the gathering stages of an authorized test: what is publicly discoverable about the client, what is live once you are permitted to look, and what each result actually implies. Raw output earns nothing here, because a scanner report is the input to analysis and pasting it shows none happened. Here you get the method, a structure taken from the criteria in order, and an annotated excerpt from a model. Prefer support? Hand over the scenario and a premium original sample lands within 24 to 48 hours, revised at no cost until the guide is met. Your courseroom may print this as IT FPX 4071 Assessment 2 or IT4071 Assessment 2; it is the same deliverable, and IT-FPX4071 Assessment 2 is what this manual walks through.

One honesty note before the manual: Capella revises courses and scoring guides over time, so always write to the exact scoring guide attached to your assessment in the courseroom. The course identity above is verified on capella.edu; the method and structure below are our tutors' approach to it, not Capella's official rubric text.

IT-FPX4071 Assessment 2 grading scale at Capella FlexPath, the criterion levels this assessment is scored on, from Capella Tutors
How Capella FlexPath grades IT-FPX4071 Assessment 2, visualized by Capella Tutors.

How IT-FPX4071 Assessment 2 is scored

Four levels per criterion, no percentages, and the level text is the instruction:

LevelWhat it means on a reconnaissance and enumeration submission
DistinguishedPassive work is separated from active work, every result carries an interpretation, and the authorization that permits the active portion is referenced where the active portion begins. What the gathering did not reveal is stated too.
ProficientPublic information and live findings are both gathered and correctly described. Accurate, with the implications left for the reader to draw.
BasicTool output arranged under headings. This is where the deliverable lands when collection was mistaken for analysis.
Non-performanceA required stage is missing, or active work appears with no reference to the authorization that permits it.

Keep two columns in your head throughout: what you learned, and what it means for an attacker. A version banner is a fact. A version banner on a system that faces the public and has not been updated since the client's last staffing change is a finding, and only the second one earns the analysis row.

The IT-FPX4071 Assessment 2 method, step by step

  1. Set the criteria as headings and restate your authority

    Open with a short paragraph referencing the signed scope, the window, and the systems permitted, because everything below it depends on that reference. Then divide the document into passive gathering and active gathering, since the boundary between them is a permissions boundary as much as a technical one.

  2. Gather what is public before touching anything

    Registration records, certificate transparency logs, published documents with metadata still attached, and job advertisements naming the systems a department runs. A municipal parks department that advertises for an administrator familiar with a specific reservation platform has told you which platform to read about, and none of that required a single packet sent to the client.

  3. Say what each public finding implies, one line each

    A subdomain in a certificate log implies a service the department may have forgotten. An author name in a published permit document implies a username convention. Write the implication next to the fact, because a list of discoveries with no interpretation is the exact shape of a Basic submission in this course.

  4. Cross the boundary into active work deliberately

    Mark the point where you begin sending traffic, restate that the systems below are inside the authorized scope and the window, and then enumerate hosts, services, versions, and any accounts the scope permits. Anything discovered that sits outside the authorized list is recorded and not touched, and the document says so.

  5. Keep your practice environment lawful and your notes contemporaneous

    Where the assessment expects hands-on evidence, run it against systems you own, virtual machines you built, or a platform that publishes an invitation to test. Snapshot before each exercise, log what you ran and when, and never point a scanner at a network you do not administer, since permission is the only thing separating an academic exercise from an offense. If a prompt seems to require more access than you hold, describe the technique and its expected result and label the demonstration as simulated.

  6. Summarize the attack surface, then self-score and submit

    Close with the surface as a short list ordered by what an attacker would try first, plus a sentence on what the gathering did not reveal, since scope limits are part of the finding. Then mark yourself against each row and upload early inside the two business day evaluation window.

A structure that maps to the criteria

Planning targets our tutors use for a gathering deliverable at this level, not Capella rules; follow your own guide where it asks for more.

SectionWhat it must doGuide
Authority restatedThe signed scope, the window, and the systems permitted, referenced before any activity is described.~150 words
Passive gatheringPublic sources used, what each produced, and the implication of each result in a line.~300 words
The boundaryThe point where sending traffic begins, and the authorization that permits everything after it.~150 words
Active enumerationHosts, services, versions, and accounts within scope, with method and tool versions named.~300 words
Attack surface summaryThe surface ordered by what an attacker would try first, plus what the gathering did not reveal.~250 words
SourcesMethodology and tool documentation cited, statutes cited primarily, current APA reconciled both ways.as needed

Annotated sample excerpt

A model excerpt from our team, showing how a gathered result reads once the interpretation is attached to it.

Sample excerpt: an interpreted finding Original model · Capella Tutors

Certificate transparency logs list a hostname for a seasonal campsite booking service that does not appear in the department's own navigation and resolves to a provider the main site does not use.1 The implication is a service commissioned for one summer and never decommissioned, which matters because nobody owns an application they have forgotten and unowned applications do not get patched.2 The hostname sits inside the authorized address range, so it was enumerated during the permitted window; a second hostname discovered in the same log resolves outside that range and was recorded without being touched, because it is not covered by the signed scope.3

  • 1Names the source and the fact separately, so a reader can reproduce the discovery without taking the tester's word for it.
  • 2Turns the fact into a consequence in one sentence. Interpretation attached to every result is the difference between the top two columns.
  • 3Handles the out-of-scope discovery explicitly. Recording rather than touching is the professional habit the course is trying to install.

The full premium sample for your exact assessment, written fresh to your scoring guide and issue, is free to request. Study it, revise it into your own voice, and submit work you understand.

Get the full sample free

The five mistakes that cost Distinguished

  • Scanner output pasted as analysis. A report is input to the work, and copying it in shows the interpretation step never happened.
  • Passive and active work mixed together. The boundary is a permissions boundary, and blurring it makes the authorization impossible to audit.
  • Active findings with no reference to the scope. Every host you touched has to be traceable to the signed list, or the record cannot defend you.
  • A discovery outside scope investigated anyway. Curiosity is not authorization, and the document has to show the restraint.
  • No statement of what was not covered. A scoped exercise is not a clean bill of health, and the limitation belongs in the summary.

Pre-submission checklist

  • Authority restated before any activity is described
  • Passive gathering kept in its own section, ahead of anything active
  • An implication written beside every public and live result
  • The boundary into active work marked, with the permission that covers it
  • Out-of-scope discoveries recorded and demonstrably untouched
  • Attack surface ordered by likely first attempt, limits stated, then self-scored per row

Enumeration write-up due and it reads like a tool log?

Send the scenario, the criteria, and any notes you have taken. You get passive work separated from active, an implication attached to every result, out-of-scope discoveries handled properly, and an attack surface a reader can act on, inside 24 to 48 hours. Revision continues free until the guide is met, and the opening premium sample costs nothing.

Keep going

Online now