Quiz: Module 6 Assignment: The Mini-Pentest & Report Assignment Overview In this module, you learned that a penetration test is only as good as the report documenting it. For this assignment, you will execute a small, structured attack in your isolated virtual lab and then write a professional, mini-penetration test report based on your findings. Objective: Demonstrate your understanding of the 5 phases of pentesting, successfully execute an exploit using Metasploit, and format the results into a professional report deliverable. Important Warning: You must perform this assignment strictly inside your VirtualBox lab (Kali Linux attacking Metasploitable 2). Do not point Metasploit at any external IP address. Part 1: The Rules of Engagement (10 Points) Before touching any tools, a professional defines the boundaries. Task: Create a brief, 3-bullet-point “Rules of Engagement” snippet for the following scenario: Scenario: You have been hired by a local accounting firm to test their main external web server. Requirements: Define the exact Scope (IP/URL), one Out-of-Scope rule, and the Time Window for the test. Part 2: The Exploitation (40 Points) Put your hands on the keyboard. Task: Boot your Kali Linux and Metasploitable 2 VMs. Follow the exact steps from Lesson 6.2 to exploit the UnrealIRCd backdoor and gain a Meterpreter session. Deliverable for Part 2: Provide two clear screenshots: A screenshot showing the msfconsole prompt right after you successfully run the exploit and receive the meterpreter > prompt. (Ensure your IP settings are visible if possible). A screenshot showing the output of the sysinfo command executed inside your Meterpreter session. Part 3: The Professional Report (50 Points) This is the most critical part of the assignment. Open a Word document or Google Doc. You are going to write a condensed, professional report based only on the UnrealIRCd exploit you just performed in Part 2. Document Structure Required: 1. Executive Summary (Approx. 3-4 sentences): Write a summary for the “CEO” of Metasploitable Corp. Explain what you did, what you gained access to, and the ultimate business risk (in plain English—no technical jargon like “TCP payloads” or “Metasploit”). 2. Technical Finding: Format your finding exactly like this: Title: [Create a professional title] Severity: [Critical, High, Medium, or Low?] Description: (2 sentences explaining what the UnrealIRCd backdoor is). Business Impact: (2 sentences explaining what an attacker could do with root access on this specific machine). Proof of Concept: (A simple 3-step list of how you exploited it, referencing the screenshots you took in Part 2). Remediation: (1 highly specific sentence telling the IT team exactly how to fix this specific issue). Submission Instructions Save your Part 1 text, Part 2 screenshots, and Part 3 report into a single PDF document. Name the file: Module6_Assignment_YourName.pdf Upload the PDF to the LMS. Grading Rubric Part 1 (10 pts): Demonstrates a clear understanding of scope and legal boundaries. Part 2 (40 pts): Screenshots prove successful navigation of the Metasploit framework and a live Meterpreter session. Part 3 – Executive Summary (15 pts): Written for a non-technical audience, focusing on business risk rather than technical steps. Part 3 – Technical Finding (25 pts): Follows the exact requested structure. Impact and Remediation are specific and actionable, not vague. - The Acinge Network

Partner with us to develop
something extraordinary

Navigation Links

Subscribe to The Acinge Newsletter

Join our mailing list for thoughtful articles, case studies, and practical guidance on building reliable digital systems.

You have been successfully Subscribed! Ops! Something went wrong, please try again.

© 2026 Copyright. The Acinge. All Rights Reserved

Scroll to Top