CyOFTS_II_Section_L_Attachment_2_.docx
DOCX document 15 KB Posted
- Attached to
- Cyber Operations Formal Training Support (CyOFTS II) Federal contract opportunity
- Solicitation number
- FA8773-17-R-8005
About this file
Section L, Attachment 2
View the file
Other files for this federal contract opportunity
Show all 18
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Section L, Attachment 2 Training Task List This requirement is to create a one hour cognitive lesson and a one hour hands-on lesson. The cognitive lesson should cover the incident response process as defined by the National Institute of Standards and Technology (NIST) (Additional sources may be used for amplification), and how this process is applied across the USAF Enterprise network through the AF Cyber Weapon Systems. The weapon systems should be defined and it should be thoroughly explained their specific responsibilities and how they work together to respond to incidents within the AF network. Additionally, the lesson should define how understanding the configuration of the systems in the environment can aid the incident response process through the creation of baseline documentation.
The one hour hands-on lesson must cover the considerations for creating a host baseline for Windows systems. The lesson must cover the necessary Windows command-line commands and select components of the Sysinternals Suite and how they can be used for conducting a host baseline on local and remote Windows systems located within a small domain.
Lesson Parts I, II, III, and IV must be included.
The Virtual Environment configuration should be set-up as follows:
1. Setup a Windows 2012 R2 Server as a Domain Controller with the following parameters:
Domain Accounts
1. 10 - Domain user accounts
2. 1 - Domain administrator account Services enabled on the Domain Controller
1. DNS
2. DHCP with a Subnet of 10.0.0.0/24 providing dynamic leases to one of the windows 7 workstation.
3. Active Directory
4. Active Directory with LDAP integration Services that must be enabled/disabled within the domain by GPO:
1. Enable – SMB
2. Enable – RDP
3. Enable – NetBios
4. Enable – WinRM
5. Enable – Remote Registry
6. Enable – Firewall only allowing connections within the domain to utilize the above listed services.
7. Disable – Network Discovery
8. Disable – Windows Defender 2 - Windows 7 Service Pack 1 connected to the domain First Windows 7 Workstation
1. Added to the Domain
2. All GPO’s Applied
3. Set with Static IP Second Windows 7 Workstation
1. Added to the Domain
2. All GPO’s Applied
3. Dynamic IP from DHCP Server 1 – CentOS 6.0 Workstation connected to the domain with dynamic IP set.
The Training Task List (TTL) is as follows:
| Task |
| Knowledge Level |
| Performance Level |
| A01: Incident Response |
| B |
| N/A |
| A02: USAF Cyber Weapon Systems |
| B |
| N/A |
| A03: Windows OS Baseline |
| B |
| 2b |
| A03a: Windows command-line |
| B |
| 2b |
| A03b: Sysinternals Autoruns and Autorunsc |
| B |
| 2b |
| A03c: Sysinternals TCPView and TCPvcon |
| B |
| 2b |
File details come from the government source that posted it. Updated .