Assessment Evidence
Guide
For
Level 4&5&5
“DIT”
Networking and Cyber Security
Develop Scalable Addressing Schemes
(Formative assessment)
Date 13-17 November, 2023
Lahore
National Vocational & Technical
Training Commission
1
Instruction Sheet for the Candidate
Qualification NVC Level 4&5 - Networking and Cyber Security
Competency 2 -Develop Scalable Addressing Schemes
Standard
Purpose of
Assessment
Formative Assessment
Name______________________________________________________
Candidate
Details
Registration/Roll Number_______________________________________
To meet this standard, you are required to complete the following
within 2 Hrs. time frame (for practical demonstration & assessment):
1. Identify network segments of an organization and allocate
Guidance for IP space
Candidate 2. Perform Inter-Network Communications between
applications
3. Secure a Small Network
During a practical assessment, under observation by an assessor, you are
Time: 2 Hrs.
required to
1. Identify network segments of an organization and allocate IP
Minimum space
Evidence • Assess Network for Scalability
Required • Identify network segments based on requirements.
• Select IP Addressing Scheme for each segment.
• Calculate IP Address space.
• Implement VLSM to save IP address space wastage.
• Allocate public and private addresses to network interfaces.
• Implement DHCP for each segment or network.
• Create documentations as per the SOPs
2. Perform Inter-Network Communications between
applications
Configure hosts and intermediary devices for inter-network
data exchange/communication.
Choose the appropriate network protocols and services for
inter-network communication.
Establish network connections.
Implement mechanisms for addressing and discovery of
applications.
Develop error handling mechanisms to deal with network
issues, such as dropped packets or timeouts
3. Secure a Small Network
Perform security audit of the designed network.
2
Secure the devices as per the standard SOPs.
Develop security policies for safe data handling.
Update the firmware and software.
Install and configure intrusion detection and prevention system.
Segment the network into different zones to isolate sensitive data
and limit the impact of potential breaches.
Implement backup of critical data to prevent data loss.
Implement security measures such as authentication and
authorization.
Implement Encryption and Data Integrity
3
Self-Assessment Checklist
Candidate Name
Registration No.
Qualification NVC Level 4&5 - Networking and Cyber Security
Competency [Link] Scalable Addressing Schemes
Standard
Purpose of
Assessment
Formative Assessment
1. Identify network segments of an organization and
allocate IP space
2. Perform Inter-Network Communications between
Assessment Task applications
3. Secure a Small Network
I can……………….
Performance Criteria Yes No
1. Assess Network for Scalability
2. Identify network segments based on requirements.
3. Select IP Addressing Scheme for each segment.
4. Calculate IP Address space.
5. Implement VLSM to save IP address space wastage.
6. Allocate public and private addresses to network interfaces.
7. Implement DHCP for each segment or network.
8. Create documentations as per the SOPs
9. Configure hosts and intermediary devices for inter-network data
exchange/communication.
10. Choose the appropriate network protocols and services for inter-
network communication.
11. Establish network connections.
12. Implement mechanisms for addressing and discovery of
applications.
13. Develop error handling mechanisms to deal with network issues,
such as dropped packets or timeouts
14. Perform security audit of the designed network.
15. Secure the devices as per the standard SOPs.
16. Develop security policies for safe data handling.
17. Update the firmware and software.
18. Install and configure intrusion detection and prevention system.
19. Segment the network into different zones to isolate sensitive data
4
and limit the impact of potential breaches.
20. Implement backup of critical data to prevent data loss.
21. Implement security measures such as authentication and
authorization.
22. Implement Encryption and Data Integrity
Candidate’s Signature__________________ Assessor’s Signature____________________
Date: _______________________________
Assessors Judgment Guide
5
Qualification NVC Level 4&5 - Networking and Cyber Security
Competency [Link] Scalable Addressing Schemes
Standard
Purpose of
Assessment
Formative Assessment
Candidate Name: ______________________________________________________________
Details
Registration/Roll Number: ______________________ Signature: _______________
COMPETENT NOT YET COMPETENT
Name of the Assessor________________________________________________
Assessment
Outcome Assessor’s code: ____________________________________________________
Signature: ________________________________
Assessment Summary (to be filled by the assessor)
Activity Method Result
Competent
Competent
Not Yet
Observation
Role Play
Portfolio
Nature of Activity
Written
Oral
Practical Skill Demonstration
Knowledge Assessment
Other Requirement
6
Observation Checklist
1. Identify network segments of an organization and
allocate IP space
2. Perform Inter-Network Communications between
Assessment Task
applications
3. Secure a Small Network
During the practical assessment, candidate demonstrated the
following:
Yes No Remarks
1. Assessed Network for Scalability
2. Identified network segments based on requirements.
3. Selected IP Addressing Scheme for each segment.
4. Calculated IP Address space.
5. Implemented VLSM to save IP address space
wastage.
6. Allocated public and private addresses to network
interfaces.
7. Implemented DHCP for each segment or network.
8. Created documentations as per the SOPs
9. Configured hosts and intermediary devices for inter-
network data exchange/communication.
10. Choose the appropriate network protocols and
services for inter-network communication.
11. Established network connections.
12. Implemented mechanisms for addressing and
discovery of applications.
13. Developed error handling mechanisms to deal with
network issues, such as dropped packets or timeouts
14. Performed security audit of the designed network.
15. Secured the devices as per the standard SOPs.
16. Developed security policies for safe data handling.
17. Updated the firmware and software.
18. Installed and configure intrusion detection and
prevention system.
7
Segmented the network into different zones to
19.
isolate sensitive data and limit the impact of potential
breaches.
20. Implemented backup of critical data to prevent data
loss.
21. Implemented security measures such as
authentication and authorization.
22. Implemented Encryption and Data Integrity
Competent Not Yet Competent
8
Knowledge Assessment
Qualification NVC Level 4&5 - Networking and Cyber Security
Competency
Standard
[Link] Scalable Addressing
Purpose of
Assessment
Formative Assessment
Candidate Name: ______________________________________________________________
Details
Registration/Roll Number: _________________ Candidate Signature: ___________
COMPETENT NOT YET COMPETENT
Assessment Name of the Assessor: ________________________________________________
Outcome
Assessor’s code: ____________________________________________________
Signature of the Assessor: _______________________
Candidate’s response is not required to be identical, but similar concepts and/or keywords must be used. Oral
questioning may be used to clarify candidate understanding of topic and its application.
Questions (Candidate confidently answered questions correctly and demonstrated Not
Satisfactory
understanding of the topics and their application) Satisfactory
Define VLSM and differentiate between Subnetting and
1. VLSM
2. Differentiate between IPV4 and IPV6
9
Define Private IP Addresses and Loop back testing
3.
Define DHCP and File transfer Protocol
4.
Define IDS and Security zones
5.
10
Feedback to the Candidate
Candidate’s Signature__________________ Assessor’s Signature _________________
11
Assessment Tasks
Candidate Name
Registration No.
Qualification NVC Level 4&5 - Networking and Cyber Security
Competency
Standard
2-Develop Scalable Addressing Schemes
Purpose of
Assessment
Formative Assessment
1. Design an IP addressing scheme for an organization
Assessment Task 2. Implement the addressing schemes using DHCP and verify
12
Answer Key
1. Define VLSM and differentiate between Subnetting and VLSM
VLSM stands for Variable Length Subnet Masking. It is a technique used in
networking to allocate IP address spaces more efficiently by allowing different
subnets to have different subnet mask lengths, thereby using address space more
effectively for avoiding wastage of Addresses space
Subnetting, on the other hand, is the process of dividing a larger IP network into
smaller, more manageable sub-networks. It involves creating subnets with fixed-size
subnet masks.
In summary:
VLSM allows for subnets within subnets, enabling more flexibility in allocating IP
addresses.
Subnetting is the general practice of dividing a network into smaller sub-networks,
but it typically involves using fixed-size subnet masks for simplicity. VLSM is a
specific form of subnetting that introduces variable-sized subnet masks for more
efficient use of IP address space.
2. Differentiate between IPV4 and IPV6
IPv4 (Internet Protocol version 4) and IPv6 (Internet Protocol version 6) are two
different versions of the Internet Protocol, which is the set of rules that govern how
data is sent and received over the internet. Here are some key differences:
Address Length:
IPv4 addresses are 32-bit and format (e.g., [Link]).
IPv6 addresses are 128-bit and format (e.g.,
2001:0000:0000:9abc:0000:8a2e:0000:0001).
Address Space:
IPV4 contain 4,29,49,67,295 addresses and have 4 octets
And IPV6 has unlimited Addresses and have 8 Groups
Subnetmask
010 IPV4 used subnet mask
011 IPV6 used prefix mask
012
3. Define Private IP Addresses and Loop back testing
Private IP Addresses:
License free Reserved addresses for networks (e.g., [Link]
[Link] and [Link]
Loopback Testing:
Using the loopback interface ([Link]) to check a system's network functionality,
often done with commands like ping [Link].
4. Define DHCP and File transfer Protocol
Dynamic Host Configuration Protocol (DHCP):
13
DHCP is a network protocol that automates the assignment of IP addresses and
other network configuration parameters to devices in a network, ensuring efficient
and dynamic resource allocation.
File Transfer Protocol (FTP):
FTP is a standard network protocol used for transferring files between a client and a
server on a computer network. It allows for the uploading and downloading of files,
providing a simple and reliable means of file exchange over the Internet or an
intranet.
5. Define IDS and Security zones
IDS (Intrusion Detection System) is a security tool that monitors network or system
activities for suspicious behavior or patterns, alerting administrators to potential
security threats.
Security zones are network segments or areas with distinct security requirements
and policies, designed to control and monitor traffic flow, ensuring a secure and
organized network architecture.
14