Unit 2 Assignment 1: Calculate the Window of Vulnerability
Learning Objectives and Outcomes
You will learn how to calculate a window of vulnerability (WoV).
Assignment Requirements
You are reviewing the security status for a small Microsoft workgroup LAN. The workgroup contains many
distinct separations in the network determined by group memberships. An example of the network
divisions is as follows:
Windows laptops: Traveling salespeople, remote suppliers, branch offices
Windows desktops: Accounting group, developer group, customer service group
Windows servers: Administrative server, Microsoft SharePoint server, Server Message Block
(SMB) server
A security breach has been identified in which the SMB server was accessed by an unauthorized user
due to a security hole. The hole was detected by the server software manufacturer the previous day. A
patch will be available within three days. The LAN administrator needs at least one week to download,
test, and install the patch. Calculate the WoV for the SMB server.
Required Resources
None
Submission Requirements
Format: Microsoft Word
Font: Arial, Size 12, Double-Space
Length: 1 page
Due By: Unit 3
Self-Assessment Checklist
I have accurately calculated the WoV.
Based on this information, the window of vulnerability is 8 days. In this case it doesnt
say what day or time the attack was found, only that the server software detected it the previous
day. Lets say the attack was on a Monday morning. The software company will be releasing a
patch for the attack in three days. We will receive the patch either Thursday or Friday. When we
get the patch we will need to install and test the patch, this will take at least one week. Once the
patch is installed we will need to push the update companywide to all machines that access the
network. We will need to send out an email message to all employees to either leave the PCs on
so that we can remotely install the updates. From the day we found the security hole to the time
we fix the security hole, it will take approximately take 8 weeks to complete the whole process.