Skip to main content

Device Security Analysis

Work laptop at a café: a look-alike network and a stolen mail login

  • Units 1, 3, 4 and 5
  • 14 points
  • About 50 minutes

You get several sources from one device, such as its firewall rules, system and web logs, a file listing with permissions, and its acceptable use policy. You explain how the policy protects the device, find the evidence of attacks in the logs, read and write file permissions with chmod, change a firewall rule and say what that changes, and suggest ways to stop the attack. On the exam: The only free-response question: Section II, 1 question in 50 minutes, 30% of the exam score, taken in Bluebook (fully digital) after the 60-question, 80-minute multiple-choice section. The CED sample gives 6 sources about one device and has parts A to E with 14 one-point subparts (A 2, B 2, C 3, D 3, E 4). It assesses Mitigate Risk and Detect Attacks, and you must cite specific evidence, like log line numbers, IP addresses, file names and rule numbers.

The question and its sources

The following sources all come from the same device, a work laptop that jalvarez, an employee of Brightline Marketing, used while working at a café, and were gathered during a security review. The company's mail site is mail.brightline.example.com, and the office network is 192.0.2.0/24. Use them to answer parts A, B, C, D and E. Label each subpart (i, ii, iii, iv) in your answer, and cite specific evidence such as source numbers, line numbers, IP addresses, file names and rule numbers.

Source 1: Laptop firewall settings

RuleActionSourceDestinationDirectionPortService
1AllowALLALLInbound445SMB
2Allow192.0.2.0/24ALLInbound22SSH
3DenyALLALLInboundALLALL

Source: Hypothetical device records written for this practice question. Destination ALL means any address the laptop has on its current network

Source 2: Laptop network and browser log (sudo tail -n 9 /var/log/laptop-events.log)

LineEntry
1Mar 03 08:30:12 laptop-ja wifi: connected to "Harborview Cafe Guest" (WPA3), address 198.51.100.23, gateway 198.51.100.1
2Mar 03 08:30:20 laptop-ja vpn-client: connected to Brightline VPN
3Mar 04 08:31:02 laptop-ja wifi: scan found two networks named "Harborview Cafe Guest": one WPA3, signal -71 dBm; one OPEN (no encryption), signal -38 dBm
4Mar 04 08:31:05 laptop-ja wifi: connected to "Harborview Cafe Guest" (OPEN), address 203.0.113.140, gateway 203.0.113.1
5Mar 04 08:31:40 laptop-ja vpn-client: connection prompt dismissed by user jalvarez
6Mar 04 08:33:15 laptop-ja browser: certificate warning for mail.brightline.example.com (issuer not trusted); user chose Continue anyway
7Mar 04 08:33:52 laptop-ja browser: login form submitted on mail.brightline.example.com
8Mar 04 08:52:30 laptop-ja smbd: connection to share Projects from 203.0.113.9 port 445
9Mar 04 08:52:41 laptop-ja smbd: 203.0.113.9 copied Projects/client_pitch.pptx

Source: Hypothetical device records written for this practice question

Source 3: Company mail sign-in log (mail-admin signins --user jalvarez)

LineEntry
1Mar 03 08:31:01 mail: sign-in ok user=jalvarez ip=198.51.100.23 device=laptop-ja
2Mar 04 08:33:52 mail: sign-in ok user=jalvarez ip=203.0.113.140 device=laptop-ja
3Mar 04 13:02:17 mail: sign-in ok user=jalvarez ip=203.0.113.77 device=unknown (first time seen)
4Mar 04 13:05:40 mail: user=jalvarez created a rule to forward all incoming mail to an outside address
5Mar 04 13:06:02 mail: user=jalvarez exported contacts (2,140 entries)

Source: Hypothetical device records written for this practice question. jalvarez was at the café until 12:00 and in a client meeting from 12:30 to 15:00 with the laptop closed

Source 4: File listing

$ ls -l /home/jalvarez/Projects

-rw-rw-rw- 1 jalvarez staff 8812032 Mar 02 17:40 client_pitch.pptx

-rw-r--r-- 1 jalvarez staff 40112 Feb 26 11:05 budget_2026.xlsx

-rw-r--r-- 1 jalvarez jalvarez 5120 Jan 15 09:30 vpn_profile.ovpn

-rw-rw-r-- 1 jalvarez staff 3302 Mar 03 10:12 notes.md

-rwxr-xr-x 1 jalvarez jalvarez 640 Jan 15 09:45 sync.sh

Source: Hypothetical device records written for this practice question

Source 5: Brightline Marketing remote work policy

Required:

• Employees must connect to the company VPN before doing any work on public Wi-Fi.

• The laptop's host firewall must stay turned on at all times.

Permitted:

• Employees may work from cafés, airports and hotels.

Prohibited:

• Employees may not use split tunneling (sending some traffic outside the VPN).

• Employees may not click past browser security warnings.

Source: Hypothetical device records written for this practice question

Suggested time: 50 minutes

Your answers are saved in this browser as you type.

Something wrong with this question?

What's wrong?

Please don't include personal details.

Part (A)

2 points

(i) Explain how one rule in the remote work policy in Source 5 protects the device from a specific threat. (ii) Explain how one rule that is already in the remote work policy could be changed to make the device more secure. Give a specific example of the changed rule.

0 / 2,500 characters

Part (B)

2 points

Source 3 contains evidence that jalvarez's mail account was used by someone else. (i) Describe the evidence in the log. Cite specific line numbers and entries. (ii) Identify the IP address the adversary used to sign in to jalvarez's mail account.

0 / 2,500 characters

Part (C)

3 points

(i) Choose one file in /home/jalvarez/Projects (Source 4). Explain what its owner, its group and all other users can each do with the file, and how its permission string shows this. Name the file. (ii) Without removing every permission from every user, describe one change to the permissions of one file in Source 4 that would limit access for some users. Name the file. (iii) Write one or more chmod commands that make the change you described in part C (ii).

0 / 2,500 characters

Part (D)

3 points

(i) Explain how the connection on line 8 of Source 2 got through the laptop's firewall. Cite the firewall rule involved. (ii) jalvarez only shares files with coworkers on the office network, 192.0.2.0/24. Describe a change to one existing rule in Source 1 that would block the connection on line 8 while still allowing file sharing with coworkers in the office. (iii) Besides blocking that connection, describe one other effect your change in part D (ii) would have on network traffic to the laptop.

0 / 2,500 characters

Part (E)

4 points

Source 2 shows how jalvarez's password was captured. (i) Determine the type of attack. (ii) Describe the specific information in the sources that indicates this attack. Cite the source and line numbers. (iii) Describe one way an automated system could stop this attack while it is happening. (iv) Other than a firewall, an IDS, an IPS or an AI tool, identify one countermeasure that could prevent, mitigate or deter this attack.

0 / 2,500 characters

Checking scoring…

Scoring it yourself shows you the rubric, examples and a model answer. Try writing your answer first.