CyOFTS_II,_Section_L,__Attachment_2.docx
DOCX document 18 KB Posted
- Attached to
- Solicitation Notice Federal contract opportunity
- Solicitation number
- FA8773-17-R-8005
About this file
Training Task List
View the file
Other files for this federal contract opportunity
Show all 50
Solicitation Notice has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Section L, Attachment 2 Training Task List This requirement is to create a one hour cognitive lesson and a one hour hands-on lesson. The cognitive lesson should cover the incident response process as defined by the National Institute of Standards and Technology (NIST) (Additional sources may be used for amplification), and how this process is applied across the USAF Enterprise network through the AF Cyber Weapon Systems. Additionally, the lesson should define how understanding the configuration of the systems in the environment can aid in the incident response process through the creation of baseline documentation.
The one hour hands-on lesson must cover the considerations for creating a host baseline for Windows systems. The lesson must cover the necessary Windows command-line commands and select components of the Sysinternals Suite and how they can be used for conducting a host baseline on local and remote Windows systems located within a small domain.
Lesson Parts I, II, III, and IV student and instructor version must be included (see attachment 2 examples).
The Virtual Environment configuration should be set-up as follows:
1. Setup a Windows 2012 R2 Server as a Domain Controller with the following parameters:
Domain Accounts
1. 10 - Domain user accounts
2. 1 - Domain administrator account Services enabled on the Domain Controller
1. DNS
2. DHCP with a Subnet of 10.0.0.0/24 providing dynamic leases to one of the windows 7 workstation.
3. Active Directory
4. Active Directory with LDAP integration Services that must be enabled/disabled within the domain by GPO:
1. Enable – SMB
2. Enable – RDP
3. Enable – NetBios
4. Enable – WinRM
5. Enable – Remote Registry
6. Enable – Firewall only allowing connections within the domain to utilize the above listed services.
7. Disable – Network Discovery
8. Disable – Windows Defender
2 - Windows 10 Workstation (with the latest patch) connected to the domain First Windows 10 Workstation
1. Added to the Domain
2. All GPO’s Applied
3. Set with Static IP Second Windows 10 Workstation
1. Added to the Domain
2. All GPO’s Applied
3. Dynamic IP from DHCP Server 1 – CentOS 6.0 Workstation connected to the domain with dynamic IP set.
| The Master Training Task List (MTTL) is as follows: | Comment by BRAZELTON, RANDALL L GG-13 USAF AFSPC 39 IOS/DOX: Updated Table LOL |
| Task | |
| Knowledge Level | |
| Performance Level |
| A01: NIST Incident Response |
| B |
| N/A |
| A02: USAF Enterprise Network Incident Response |
| B |
| N/A |
| A03: Windows OS Baseline |
| B |
| 2b |
| A03a: Windows command-line |
| B |
| 2b |
| A03b: Sysinternals Autoruns and Autorunsc |
| B |
| 2b |
| A03c: Sysinternals TCPView and TCPvcon |
| B |
| 2b |
File details come from the government source that posted it. Updated .