Skip to main content

Device Security Analysis

Office print server: admin guessing and a gateway with a new address

  • Units 3, 4 and 5
  • 14 points
  • About 50 minutes

You get several sources from one device, such as its firewall rules, system and web logs, a file listing with permissions, and its acceptable use policy. You explain how the policy protects the device, find the evidence of attacks in the logs, read and write file permissions with chmod, change a firewall rule and say what that changes, and suggest ways to stop the attack. On the exam: The only free-response question: Section II, 1 question in 50 minutes, 30% of the exam score, taken in Bluebook (fully digital) after the 60-question, 80-minute multiple-choice section. The CED sample gives 6 sources about one device and has parts A to E with 14 one-point subparts (A 2, B 2, C 3, D 3, E 4). It assesses Mitigate Risk and Detect Attacks, and you must cite specific evidence, like log line numbers, IP addresses, file names and rule numbers.

The question and its sources

The following sources all come from the same device, the print server at Sunfield Architects (IP address 192.0.2.12), and were gathered during a security review. The office network's gateway is 192.0.2.1, and guests use a separate Wi-Fi network, 198.51.100.0/24. Use them to answer parts A, B, C, D and E. Label each subpart (i, ii, iii, iv) in your answer, and cite specific evidence such as source numbers, line numbers, IP addresses, file names and rule numbers.

Source 1: Device firewall settings

RuleActionSourceDestinationDirectionPortService
1Allow192.0.2.0/24192.0.2.12Inbound631IPP
2Allow192.0.2.0/24192.0.2.12Inbound9100Raw printing
3Allow192.0.2.5192.0.2.12Inbound22SSH
4DenyALLALLInboundALLALL

Source: Hypothetical device records written for this practice question

Source 2: Print server log (sudo tail -n 13 /var/log/cups/error_log)

LineEntry
1Feb 02 08:41:10 print01 cupsd: job 1040 'site_plan.pdf' from 192.0.2.31 printed
2Feb 02 09:20:04 print01 cupsd: admin authorization failed for user admin from 192.0.2.77
3Feb 02 09:20:06 print01 cupsd: admin authorization failed for user admin from 192.0.2.77
4Feb 02 09:20:08 print01 cupsd: admin authorization failed for user admin from 192.0.2.77
5Feb 02 09:20:10 print01 cupsd: admin authorization failed for user admin from 192.0.2.77
6Feb 02 09:20:12 print01 cupsd: admin authorization failed for user admin from 192.0.2.77
7Feb 02 09:20:14 print01 cupsd: admin authorization failed for user admin from 192.0.2.77
8Feb 02 09:20:16 print01 cupsd: admin authorization failed for user admin from 192.0.2.77
9Feb 02 09:20:18 print01 cupsd: admin authorization failed for user admin from 192.0.2.77
10Feb 02 09:20:20 print01 cupsd: admin authorization failed for user admin from 192.0.2.77
11Feb 02 11:15:37 print01 kernel: [UFW BLOCK] IN=eth0 OUT= SRC=198.51.100.40 DST=192.0.2.12 PROTO=TCP DPT=9100
12Feb 02 11:15:52 print01 kernel: [UFW BLOCK] IN=eth0 OUT= SRC=198.51.100.40 DST=192.0.2.12 PROTO=TCP DPT=631
13Feb 02 11:30:05 print01 cupsd: job 1043 'contract_Lee.pdf' from 192.0.2.31 printed

Source: Hypothetical device records written for this practice question. 198.51.100.40 is a visitor's laptop on the guest Wi-Fi

Source 3: Address monitor and print entries (sudo tail -n 7 /var/log/syslog)

LineEntry
1Feb 02 08:00:11 print01 arpwatch: new station 192.0.2.1 00:00:5e:00:53:01
2Feb 02 08:00:14 print01 arpwatch: new station 192.0.2.31 00:00:5e:00:53:31
3Feb 02 09:14:40 print01 arpwatch: new station 192.0.2.77 00:00:5e:00:53:4d
4Feb 02 10:02:15 print01 arpwatch: changed ethernet address 192.0.2.1 00:00:5e:00:53:4d (was 00:00:5e:00:53:01)
5Feb 02 10:02:17 print01 arpwatch: flip flop 192.0.2.1 00:00:5e:00:53:01 (was 00:00:5e:00:53:4d)
6Feb 02 10:02:19 print01 arpwatch: flip flop 192.0.2.1 00:00:5e:00:53:4d (was 00:00:5e:00:53:01)
7Feb 02 10:05:44 print01 cupsd: scan-to-email job 1042 sent to mail server through gateway 192.0.2.1 (00:00:5e:00:53:4d)

Source: Hypothetical device records written for this practice question. arpwatch records which hardware (MAC) address answers for each IP address on the local network

Source 4: File listing

$ ls -l /var/spool/print

-rw-r--r-- 1 lp lp 2210441 Feb 02 08:41 job_1040_site_plan.pdf

-rw-rw-rw- 1 lp lp 401233 Feb 02 10:05 job_1042_scan.pdf

-rwxrwxrwx 1 lp lp 640 Jan 08 12:00 cleanup_jobs.sh

-rw-r--r-- 1 root lp 3120 Jan 08 12:02 printers.conf

-rw-r--r-- 1 root lp 88 Jan 08 12:03 admin.htpasswd

Source: Hypothetical device records written for this practice question

Source 5: Sunfield Architects network and printer policy

Required:

• Network switch ports in meeting rooms and the lobby must use port security that allows only one approved device per port.

• Administrator logins on network devices must go through the company's sign-in server, not local accounts.

Permitted:

• Employees may print from any office computer.

• Guests may use the guest Wi-Fi, which is kept on a separate network from office devices.

Prohibited:

• Print and scan jobs may not be kept on the print server for more than 24 hours.

• Employees may not connect personal network devices, such as their own Wi-Fi routers, to office ports.

Source: Hypothetical device records written for this practice question

Suggested time: 50 minutes

Your answers are saved in this browser as you type.

Something wrong with this question?

What's wrong?

Please don't include personal details.

Part (A)

2 points

(i) Explain how one rule in the network and printer policy in Source 5 protects the device from a specific threat. (ii) Explain how one rule that is already in the network and printer policy could be changed to make the device more secure. Give a specific example of the changed rule.

0 / 2,500 characters

Part (B)

2 points

Source 2 contains evidence of an online password attack. (i) Describe the evidence in the log that indicates a password attack. Cite specific line numbers and entries. (ii) Identify the IP address of the adversary.

0 / 2,500 characters

Part (C)

3 points

(i) Choose one file in /var/spool/print (Source 4). Explain what its owner, its group and all other users can each do with the file, and how its permission string shows this. Name the file. (ii) Without removing every permission from every user, describe one change to the permissions of one file in Source 4 that would limit access for some users. Name the file. (iii) Write one or more chmod commands that make the change you described in part C (ii).

0 / 2,500 characters

Part (D)

3 points

(i) Explain why one connection attempt recorded in the logs was blocked by the device's firewall. Cite the log entry and the firewall rule involved. (ii) Other than allowing all traffic on all ports, describe a change to one existing rule in Source 1 that would let the connection you identified in part D (i) through. (iii) Besides letting that connection through, describe one other effect your change in part D (ii) would have on network traffic to or from the device.

0 / 2,500 characters

Part (E)

4 points

Besides the password attack in part B, Source 3 shows evidence of a network attack. (i) Determine the type of attack. (ii) Describe the specific information in the sources that indicates this attack. Cite the source and line numbers. (iii) Describe one way an automated system could stop this attack while it is happening. (iv) Other than a firewall, an IDS, an IPS or an AI tool, identify one countermeasure that could prevent, mitigate or deter this attack.

0 / 2,500 characters

Checking scoring…

Scoring it yourself shows you the rubric, examples and a model answer. Try writing your answer first.