Device Security Analysis
Payroll server: a convincing phone call and a login with no second factor
- Units 1, 2, 3, 4 and 5
- 14 points
- About 50 minutes
You get several sources from one device, such as its firewall rules, system and web logs, a file listing with permissions, and its acceptable use policy. You explain how the policy protects the device, find the evidence of attacks in the logs, read and write file permissions with chmod, change a firewall rule and say what that changes, and suggest ways to stop the attack. On the exam: The only free-response question: Section II, 1 question in 50 minutes, 30% of the exam score, taken in Bluebook (fully digital) after the 60-question, 80-minute multiple-choice section. The CED sample gives 6 sources about one device and has parts A to E with 14 one-point subparts (A 2, B 2, C 3, D 3, E 4). It assesses Mitigate Risk and Detect Attacks, and you must cite specific evidence, like log line numbers, IP addresses, file names and rule numbers.
The question and its sources
The following sources all come from the same device, the payroll server at Tidewater Logistics (IP address 192.0.2.120), and were gathered during a security review. D. Wilson is the company's chief financial officer (CFO). Use them to answer parts A, B, C, D and E. Label each subpart (i, ii, iii, iv) in your answer, and cite specific evidence such as source numbers, line numbers, IP addresses, file names and rule numbers.
Source 1: Device firewall settings
| Rule | Action | Source | Destination | Direction | Port | Service |
|---|---|---|---|---|---|---|
| 1 | Allow | ALL | 192.0.2.120 | Inbound | 443 | HTTPS |
| 2 | Allow | 192.0.2.0/24 | 192.0.2.120 | Inbound | 3389 | RDP |
| 3 | Allow | 192.0.2.5 | 192.0.2.120 | Inbound | 22 | SSH |
| 4 | Deny | ALL | ALL | Inbound | ALL | ALL |
Source: Hypothetical device records written for this practice question
Source 2: Help desk ticket log (helpdesk export --ticket 5512)
| Line | Entry |
|---|---|
| 1 | Jun 12 17:55:02 ticket 5512 opened by helpdesk1: call from 555-0142. Caller says he is D. Wilson (CFO). The number on file for D. Wilson is 555-0190 |
| 2 | Jun 12 17:55:40 ticket 5512: caller says he is locked out and his board meeting starts in 10 minutes, so he needs a password reset right now. Voice sounded exactly like D. Wilson |
| 3 | Jun 12 17:56:15 ticket 5512: caller gave D. Wilson's employee ID and birth date; both match HR records |
| 4 | Jun 12 17:56:20 ticket 5512: caller asked for MFA to be removed because he lost his phone; caller declined a video call |
| 5 | Jun 12 17:57:01 ticket 5512: helpdesk1 reset the password for dwilson and removed MFA |
| 6 | Jun 13 08:40:12 ticket 5512 note by helpdesk2: D. Wilson says he made no call. He was on a flight with no Wi-Fi from 17:30 on June 12 to 02:00 on June 13 |
Source: Hypothetical device records written for this practice question
Source 3: Payroll login and activity log (sudo tail -n 8 /var/log/payroll/activity.log)
| Line | Entry |
|---|---|
| 1 | Jun 11 09:02:14 payroll01 payroll-app: login ok user=dwilson ip=192.0.2.44 mfa=yes |
| 2 | Jun 12 08:58:30 payroll01 payroll-app: login ok user=dwilson ip=192.0.2.44 mfa=yes |
| 3 | Jun 12 17:57:01 payroll01 accounts: password reset for dwilson by helpdesk1; MFA removed |
| 4 | Jun 12 18:03:40 payroll01 payroll-app: login ok user=dwilson ip=203.0.113.35 mfa=no |
| 5 | Jun 12 18:05:12 payroll01 payroll-app: user=dwilson changed payment account for vendor Coastal Freight to an account ending 7731 |
| 6 | Jun 12 18:06:45 payroll01 payroll-app: user=dwilson approved payment batch 0612-B ($84,300) |
| 7 | Jun 12 18:20:09 payroll01 kernel: [UFW BLOCK] IN=eth0 OUT= SRC=198.51.100.81 DST=192.0.2.120 PROTO=TCP DPT=3389 |
| 8 | Jun 12 18:22:51 payroll01 kernel: [UFW BLOCK] IN=eth0 OUT= SRC=203.0.113.35 DST=192.0.2.120 PROTO=TCP DPT=22 |
Source: Hypothetical device records written for this practice question. 198.51.100.81 is the home internet address of the company's accountant, who works remotely
Source 4: File listing
$ ls -l /srv/payroll
-rw-rw-r-- 1 payroll finance 18220 Jun 12 18:05 vendor_accounts.csv
-rw-rw-rw- 1 payroll finance 912384 Jan 30 11:00 w2_forms_2025.pdf
-rwxr-xr-x 1 payroll payroll 3310 Mar 02 09:15 payroll_run.sh
-rw-rw-r-- 1 payroll finance 214 May 28 16:40 approvers.txt
-rw-r----- 1 payroll audit 50112 Jun 12 23:00 audit_export.csv
Source: Hypothetical device records written for this practice question
Source 5: Tidewater Logistics help desk and payroll policy
Required:
• Before resetting a password over the phone, the help desk must confirm the caller's employee ID and birth date.
• Payments of more than $100,000 must be approved by a second person.
Permitted:
• Finance staff may sign in to the payroll app from home over HTTPS.
Prohibited:
• Employees may not share passwords or MFA codes with anyone, including the help desk.
Source: Hypothetical device records written for this practice question
Suggested time: 50 minutes
Your answers are saved in this browser as you type.
Part (A)
2 points(i) Explain how one rule in the help desk and payroll policy in Source 5 protects the device from a specific threat. (ii) Explain how one rule that is already in the help desk and payroll policy could be changed to make the device more secure. Give a specific example of the changed rule.
0 / 2,500 characters
Part (B)
2 pointsSource 3 contains evidence that the dwilson account was used by someone other than D. Wilson. (i) Describe the evidence in the log. Cite specific line numbers and entries. (ii) Identify the IP address of the adversary.
0 / 2,500 characters
Part (C)
3 points(i) Choose one file in /srv/payroll (Source 4). Explain what its owner, its group and all other users can each do with the file, and how its permission string shows this. Name the file. (ii) Without removing every permission from every user, describe one change to the permissions of one file in Source 4 that would limit access for some users. Name the file. (iii) Write one or more chmod commands that make the change you described in part C (ii).
0 / 2,500 characters
Part (D)
3 points(i) Explain why one connection attempt recorded in the logs was blocked by the device's firewall. Cite the log entry and the firewall rule involved. (ii) Other than allowing all traffic on all ports, describe a change to one existing rule in Source 1 that would let the connection you identified in part D (i) through. (iii) Besides letting that connection through, describe one other effect your change in part D (ii) would have on network traffic to or from the device.
0 / 2,500 characters
Part (E)
4 pointsSource 2 shows how the adversary got control of the dwilson account. (i) Determine the type of attack used against the help desk. (ii) Describe the specific information in Source 2 that indicates this attack. Cite line numbers. (iii) Describe one way an automated system could have stopped the adversary's login or payment changes while they were happening. (iv) Other than a firewall, an IDS, an IPS or an AI tool, identify one countermeasure that could prevent, mitigate or deter this attack.
0 / 2,500 characters
Checking scoring…
Scoring it yourself shows you the rubric, examples and a model answer. Try writing your answer first.