Skip to main content

Device Security Analysis

Bakery order server: guessed password and a database search box

  • Units 3, 4 and 5
  • 14 points
  • About 50 minutes

You get several sources from one device, such as its firewall rules, system and web logs, a file listing with permissions, and its acceptable use policy. You explain how the policy protects the device, find the evidence of attacks in the logs, read and write file permissions with chmod, change a firewall rule and say what that changes, and suggest ways to stop the attack. On the exam: The only free-response question: Section II, 1 question in 50 minutes, 30% of the exam score, taken in Bluebook (fully digital) after the 60-question, 80-minute multiple-choice section. The CED sample gives 6 sources about one device and has parts A to E with 14 one-point subparts (A 2, B 2, C 3, D 3, E 4). It assesses Mitigate Risk and Detect Attacks, and you must cite specific evidence, like log line numbers, IP addresses, file names and rule numbers.

The question and its sources

The following sources all come from the same device, the online order server at Larkspur Bakery (IP address 192.0.2.20), and were gathered during a security review. Use them to answer parts A, B, C, D and E. Label each subpart (i, ii, iii, iv) in your answer, and cite specific evidence such as source numbers, line numbers, IP addresses, file names and rule numbers.

Source 1: Device firewall settings

RuleActionSourceDestinationDirectionPortService
1AllowALL192.0.2.20Inbound443HTTPS
2AllowALL192.0.2.20Inbound80HTTP
3Allow192.0.2.0/24192.0.2.20Inbound22SSH
4Allow192.0.2.40192.0.2.20Inbound3306MySQL
5AllowALL192.0.2.20Inbound21FTP
6DenyALLALLInboundALLALL

Source: Hypothetical device records written for this practice question

Source 2: Authentication log (sudo tail -n 19 /var/log/auth.log)

LineEntry
1Mar 14 01:58:02 orders sshd[1120]: Server listening on port 22.
2Mar 14 02:13:40 orders vsftpd[2301]: Failed login for user mreyes from 198.51.100.66 port 21 ftp
3Mar 14 02:13:41 orders vsftpd[2303]: Failed login for user mreyes from 198.51.100.66 port 21 ftp
4Mar 14 02:13:42 orders vsftpd[2305]: Failed login for user mreyes from 198.51.100.66 port 21 ftp
5Mar 14 02:13:43 orders vsftpd[2307]: Failed login for user mreyes from 198.51.100.66 port 21 ftp
6Mar 14 02:13:44 orders vsftpd[2309]: Failed login for user mreyes from 198.51.100.66 port 21 ftp
7Mar 14 02:13:45 orders vsftpd[2311]: Failed login for user mreyes from 198.51.100.66 port 21 ftp
8Mar 14 02:13:46 orders vsftpd[2313]: Failed login for user mreyes from 198.51.100.66 port 21 ftp
9Mar 14 02:13:47 orders vsftpd[2315]: Failed login for user mreyes from 198.51.100.66 port 21 ftp
10Mar 14 02:13:48 orders vsftpd[2317]: Failed login for user mreyes from 198.51.100.66 port 21 ftp
11Mar 14 02:13:49 orders vsftpd[2319]: Failed login for user mreyes from 198.51.100.66 port 21 ftp
12Mar 14 02:13:51 orders vsftpd[2321]: Accepted login for user mreyes from 198.51.100.66 port 21 ftp
13Mar 14 02:14:30 orders vsftpd[2321]: mreyes downloaded /var/www/orders/orders_export.csv (482113 bytes)
14Mar 14 02:15:02 orders kernel: [UFW BLOCK] IN=eth0 OUT= SRC=198.51.100.66 DST=192.0.2.20 PROTO=TCP DPT=3306
15Mar 14 07:58:10 orders sshd[2410]: Accepted publickey for tchen from 192.0.2.35 port 50122 ssh2
16Mar 14 07:58:44 orders sudo: tchen : TTY=pts/0 ; PWD=/home/tchen ; USER=root ; COMMAND=/usr/bin/apt update
17Mar 14 08:01:02 orders CRON[2455]: pam_unix(cron:session): session opened for user root by (uid=0)
18Mar 14 09:12:30 orders kernel: [UFW BLOCK] IN=eth0 OUT= SRC=192.0.2.41 DST=192.0.2.20 PROTO=TCP DPT=3306
19Mar 14 09:12:31 orders sudo: tchen : TTY=pts/0 ; PWD=/home/tchen ; USER=root ; COMMAND=/usr/bin/tail -n 40 /var/log/auth.log

Source: Hypothetical device records written for this practice question

Source 3: Web server access log (sudo tail -n 11 /var/log/nginx/access.log)

LineEntry
1192.0.2.35 - tchen [14/Mar/2026:08:05:12 -0500] "GET /admin/orders HTTP/1.1" 200 5120 "-" "Mozilla/5.0 (Windows NT 10.0)"
2198.51.100.23 - - [14/Mar/2026:10:21:03 -0500] "GET / HTTP/1.1" 200 4380 "-" "Mozilla/5.0 (iPhone)"
3198.51.100.23 - - [14/Mar/2026:10:21:09 -0500] "GET /menu.html HTTP/1.1" 200 6211 "-" "Mozilla/5.0 (iPhone)"
4198.51.100.23 - - [14/Mar/2026:10:23:40 -0500] "POST /order/new HTTP/1.1" 302 88 "-" "Mozilla/5.0 (iPhone)"
5203.0.113.77 - - [14/Mar/2026:10:31:15 -0500] "GET /order/status?id=10482 HTTP/1.1" 200 712 "-" "python-requests/2.31"
6203.0.113.77 - - [14/Mar/2026:10:31:18 -0500] "GET /order/status?id=[order number followed by a single quote character] HTTP/1.1" 500 231 "-" "python-requests/2.31"
7203.0.113.77 - - [14/Mar/2026:10:31:22 -0500] "GET /order/status?id=[order number followed by an always-true OR condition and an SQL comment marker] HTTP/1.1" 200 48211 "-" "python-requests/2.31"
8203.0.113.77 - - [14/Mar/2026:10:31:29 -0500] "GET /order/status?id=[order number followed by SQL keywords (UNION, SELECT, FROM) naming the customers table] HTTP/1.1" 200 96544 "-" "python-requests/2.31"
9198.51.100.140 - - [14/Mar/2026:10:40:52 -0500] "GET /cakes.html HTTP/1.1" 200 5530 "-" "Mozilla/5.0 (Macintosh)"
10198.51.100.140 - - [14/Mar/2026:10:41:30 -0500] "GET /order/status?id=10490 HTTP/1.1" 200 698 "-" "Mozilla/5.0 (Macintosh)"
11192.0.2.35 - tchen [14/Mar/2026:11:02:44 -0500] "GET /admin/logout HTTP/1.1" 302 51 "-" "Mozilla/5.0 (Windows NT 10.0)"

Source: Hypothetical device records written for this practice question. Bracketed text describes request content that has been removed

Source 4: File listing

$ ls -l /var/www/orders

-rw-r--r-- 1 tchen www-data 412 Mar 10 16:20 db.conf

-rw-rw-rw- 1 tchen www-data 482113 Mar 14 01:00 orders_export.csv

-rwxr-xr-x 1 tchen tchen 2210 Mar 02 11:47 backup.sh

-rwx------ 1 tchen tchen 1874 Mar 02 11:50 deploy.sh

-rw-r----- 1 tchen www-data 1704 Feb 27 09:12 tls_private.key

-rw-r--r-- 1 tchen www-data 6211 Mar 12 14:03 menu.html

Source: Hypothetical device records written for this practice question

Source 5: Larkspur Bakery server use policy

Required:

• Staff must sign in with a password of at least 12 characters that they do not use for any other account.

• The server's software must be updated within 30 days after a security patch is released.

Permitted:

• Staff may use the order dashboard from the bakery's tablets.

• The owner may connect to the server with SSH from the bakery's office network.

Prohibited:

• Staff may not share accounts or write passwords near the register.

• Staff may not install software on the server without the owner's approval.

• Staff may not use the server to browse the web or read email.

Source: Hypothetical device records written for this practice question

Suggested time: 50 minutes

Your answers are saved in this browser as you type.

Something wrong with this question?

What's wrong?

Please don't include personal details.

Part (A)

2 points

(i) Explain how one rule in the server use policy in Source 5 protects the device from a specific threat. (ii) Explain how one rule that is already in the server use policy could be changed to make the device more secure. Give a specific example of the changed rule.

0 / 2,500 characters

Part (B)

2 points

Source 2 contains evidence of an online password attack. (i) Describe the evidence in the log that indicates a password attack. Cite specific line numbers and entries. (ii) Identify the IP address of the adversary.

0 / 2,500 characters

Part (C)

3 points

(i) Choose one file in /var/www/orders (Source 4). Explain what its owner, its group and all other users can each do with the file, and how its permission string shows this. Name the file. (ii) Without removing every permission from every user, describe one change to the permissions of one file in Source 4 that would limit access for some users. Name the file. (iii) Write one or more chmod commands that make the change you described in part C (ii).

0 / 2,500 characters

Part (D)

3 points

(i) Explain why one connection attempt recorded in the logs was blocked by the device's firewall. Cite the log entry and the firewall rule involved. (ii) Other than allowing all traffic on all ports, describe a change to one existing rule in Source 1 that would let the connection you identified in part D (i) through. (iii) Besides letting that connection through, describe one other effect your change in part D (ii) would have on network traffic to or from the device.

0 / 2,500 characters

Part (E)

4 points

Besides the password attack in part B, the web server log shows a second attack. (i) Determine the type of attack. (ii) Describe the specific information in the sources that indicates this attack. Cite the source and line numbers. (iii) Describe one way an automated system could stop this attack while it is happening. (iv) Other than a firewall, an IDS, an IPS or an AI tool, identify one countermeasure that could prevent, mitigate or deter this attack.

0 / 2,500 characters

Checking scoring…

Scoring it yourself shows you the rubric, examples and a model answer. Try writing your answer first.