Skip to main content

Device Security Analysis

Food bank donation site: sprayed admin logins and a receipt download trick

  • Units 1, 3, 4 and 5
  • 14 points
  • About 50 minutes

You get several sources from one device, such as its firewall rules, system and web logs, a file listing with permissions, and its acceptable use policy. You explain how the policy protects the device, find the evidence of attacks in the logs, read and write file permissions with chmod, change a firewall rule and say what that changes, and suggest ways to stop the attack. On the exam: The only free-response question: Section II, 1 question in 50 minutes, 30% of the exam score, taken in Bluebook (fully digital) after the 60-question, 80-minute multiple-choice section. The CED sample gives 6 sources about one device and has parts A to E with 14 one-point subparts (A 2, B 2, C 3, D 3, E 4). It assesses Mitigate Risk and Detect Attacks, and you must cite specific evidence, like log line numbers, IP addresses, file names and rule numbers.

The question and its sources

The following sources all come from the same device, the donation website server for Harbor Lights Food Bank (IP address 192.0.2.180), and were gathered during a security review. Use them to answer parts A, B, C, D and E. Label each subpart (i, ii, iii, iv) in your answer, and cite specific evidence such as source numbers, line numbers, IP addresses, file names and rule numbers.

Source 1: Device firewall settings

RuleActionSourceDestinationDirectionPortService
1AllowALL192.0.2.180Inbound443HTTPS
2AllowALL192.0.2.180Inbound80HTTP
3Allow192.0.2.0/24192.0.2.180Inbound22SSH
4DenyALLALLInboundALLALL

Source: Hypothetical device records written for this practice question

Source 2: Admin login log (sudo tail -n 11 /var/log/site-admin.log)

LineEntry
1May 19 16:10:03 donate site-admin[611]: login ok user=webmaster ip=192.0.2.33
2May 20 01:15:03 donate site-admin[611]: login failed user=admin ip=198.51.100.77
3May 20 01:15:06 donate site-admin[611]: login failed user=coordinator ip=198.51.100.77
4May 20 01:15:09 donate site-admin[611]: login failed user=volunteer1 ip=198.51.100.77
5May 20 01:15:12 donate site-admin[611]: login failed user=volunteer2 ip=198.51.100.77
6May 20 01:15:15 donate site-admin[611]: login failed user=treasurer ip=198.51.100.77
7May 20 01:15:18 donate site-admin[611]: login failed user=webmaster ip=198.51.100.77
8May 20 01:15:21 donate site-admin[611]: login failed user=events ip=198.51.100.77
9May 20 01:15:24 donate site-admin[611]: login failed user=outreach ip=198.51.100.77
10May 20 09:31:12 donate kernel: [UFW BLOCK] IN=eth0 OUT= SRC=198.51.100.44 DST=192.0.2.180 PROTO=TCP DPT=22
11May 20 11:02:40 donate kernel: [UFW BLOCK] IN=eth0 OUT= SRC=203.0.113.9 DST=192.0.2.180 PROTO=TCP DPT=3306

Source: Hypothetical device records written for this practice question. 198.51.100.44 is the home internet address of the food bank's volunteer webmaster

Source 3: Web server access log (sudo tail -n 7 /var/log/nginx/access.log)

LineEntry
1198.51.100.150 - - [20/May/2026:10:12:30 -0400] "POST /donate HTTP/1.1" 302 96 "-" "Mozilla/5.0 (iPhone)"
2198.51.100.150 - - [20/May/2026:10:12:41 -0400] "GET /receipt?file=receipt_10233.pdf HTTP/1.1" 200 48211 "-" "Mozilla/5.0 (iPhone)"
3203.0.113.212 - - [20/May/2026:10:40:02 -0400] "GET /receipt?file=receipt_10234.pdf HTTP/1.1" 200 48300 "-" "curl/8.4.0"
4203.0.113.212 - - [20/May/2026:10:40:05 -0400] "GET /receipt?file=[path using repeated parent-directory steps (../) to reach /etc/passwd] HTTP/1.1" 200 1822 "-" "curl/8.4.0"
5203.0.113.212 - - [20/May/2026:10:40:07 -0400] "GET /receipt?file=[path using repeated parent-directory steps (../) to reach /etc/shadow] HTTP/1.1" 403 162 "-" "curl/8.4.0"
6203.0.113.212 - - [20/May/2026:10:40:11 -0400] "GET /receipt?file=[path using parent-directory steps (../) to reach /var/www/donate/site.conf] HTTP/1.1" 200 412 "-" "curl/8.4.0"
7192.0.2.33 - webmaster [20/May/2026:10:55:20 -0400] "GET /admin/campaigns HTTP/1.1" 200 6120 "-" "Mozilla/5.0 (Windows NT 10.0)"

Source: Hypothetical device records written for this practice question. Bracketed text describes request content that has been removed

Source 4: File listing

$ ls -l /var/www/donate

-rw-rw-r-- 1 webmaster www-data 220416 May 20 06:00 donors.csv

-rw-r--r-- 1 webmaster www-data 412 Apr 02 13:40 site.conf

-rw-r--r-- 1 webmaster www-data 9120 Mar 14 10:05 receipt_template.html

-rwxrwxrwx 1 webmaster webmaster 760 Feb 11 09:22 cleanup.sh

-rw-rw-r-- 1 webmaster www-data 288 May 01 12:00 admin_users.txt

Source: Hypothetical device records written for this practice question

Source 5: Harbor Lights website software policy

Required:

• Website software and plugins must be updated within 7 days of a security update.

• Only plugins approved by the volunteer IT lead may be installed on the website.

Permitted:

• Volunteers may edit donation campaign pages through the admin site.

Prohibited:

• Card numbers may not be stored on the web server; all payments go through the payment processor.

• Volunteers may not share admin logins.

Source: Hypothetical device records written for this practice question

Suggested time: 50 minutes

Your answers are saved in this browser as you type.

Something wrong with this question?

What's wrong?

Please don't include personal details.

Part (A)

2 points

(i) Explain how one rule in the website software policy in Source 5 protects the device from a specific threat. (ii) Explain how one rule that is already in the website software policy could be changed to make the device more secure. Give a specific example of the changed rule.

0 / 2,500 characters

Part (B)

2 points

Source 2 contains evidence of an online password attack on the admin site. (i) Describe the evidence in the log that indicates a password attack. Cite specific line numbers and entries. (ii) Identify the IP address of the adversary.

0 / 2,500 characters

Part (C)

3 points

(i) Choose one file in /var/www/donate (Source 4). Explain what its owner, its group and all other users can each do with the file, and how its permission string shows this. Name the file. (ii) Without removing every permission from every user, describe one change to the permissions of one file in Source 4 that would limit access for some users. Name the file. (iii) Write one or more chmod commands that make the change you described in part C (ii).

0 / 2,500 characters

Part (D)

3 points

(i) Explain why one connection attempt recorded in the logs was blocked by the device's firewall. Cite the log entry and the firewall rule involved. (ii) Other than allowing all traffic on all ports, describe a change to one existing rule in Source 1 that would let the connection you identified in part D (i) through. (iii) Besides letting that connection through, describe one other effect your change in part D (ii) would have on network traffic to or from the device.

0 / 2,500 characters

Part (E)

4 points

Besides the password attack in part B, Source 3 shows evidence of a second attack. (i) Determine the type of attack. (ii) Describe the specific information in the sources that indicates this attack. Cite the source and line numbers. (iii) Describe one way an automated system could stop this attack while it is happening. (iv) Other than a firewall, an IDS, an IPS or an AI tool, identify one countermeasure that could prevent, mitigate or deter this attack.

0 / 2,500 characters

Checking scoring…

Scoring it yourself shows you the rubric, examples and a model answer. Try writing your answer first.