Device Security Analysis
Store chatbot server: reused passwords and a chatbot talked into sharing
- Units 1, 3, 4 and 5
- 14 points
- About 50 minutes
You get several sources from one device, such as its firewall rules, system and web logs, a file listing with permissions, and its acceptable use policy. You explain how the policy protects the device, find the evidence of attacks in the logs, read and write file permissions with chmod, change a firewall rule and say what that changes, and suggest ways to stop the attack. On the exam: The only free-response question: Section II, 1 question in 50 minutes, 30% of the exam score, taken in Bluebook (fully digital) after the 60-question, 80-minute multiple-choice section. The CED sample gives 6 sources about one device and has parts A to E with 14 one-point subparts (A 2, B 2, C 3, D 3, E 4). It assesses Mitigate Risk and Detect Attacks, and you must cite specific evidence, like log line numbers, IP addresses, file names and rule numbers.
The question and its sources
The following sources all come from the same device, the server that runs the customer help chatbot for Pinecrest Outdoor Gear (IP address 192.0.2.210), and were gathered during a security review. The chatbot is built on a large language model (LLM) and can look up orders in the store's customer database. Use them to answer parts A, B, C, D and E. Label each subpart (i, ii, iii, iv) in your answer, and cite specific evidence such as source numbers, line numbers, IP addresses, file names and rule numbers.
Source 1: Device firewall settings
| Rule | Action | Source | Destination | Direction | Port | Service |
|---|---|---|---|---|---|---|
| 1 | Allow | ALL | 192.0.2.210 | Inbound | 443 | HTTPS |
| 2 | Allow | 192.0.2.0/24 | 192.0.2.210 | Inbound | 22 | SSH |
| 3 | Allow | 192.0.2.40 | 192.0.2.210 | Inbound | 5432 | PostgreSQL |
| 4 | Deny | ALL | ALL | Inbound | ALL | ALL |
Source: Hypothetical device records written for this practice question
Source 2: Customer login log (sudo tail -n 11 /var/log/store-login.log)
| Line | Entry |
|---|---|
| 1 | Aug 05 09:12:40 helpbot store-login[702]: login ok email=sward@example.com ip=198.51.100.23 |
| 2 | Aug 05 11:20:04 helpbot store-login[702]: login failed email=mkeller@example.net ip=198.51.100.120 |
| 3 | Aug 05 11:20:11 helpbot store-login[702]: login failed email=jortiz@example.com ip=198.51.100.120 |
| 4 | Aug 05 11:20:18 helpbot store-login[702]: login failed email=abell@example.org ip=198.51.100.120 |
| 5 | Aug 05 11:20:25 helpbot store-login[702]: login ok email=tlin@example.com ip=198.51.100.120 |
| 6 | Aug 05 11:20:32 helpbot store-login[702]: login failed email=rfoster@example.net ip=198.51.100.120 |
| 7 | Aug 05 11:20:39 helpbot store-login[702]: login ok email=kdang@example.com ip=198.51.100.120 |
| 8 | Aug 05 11:21:46 helpbot store-login[702]: login failed email=pnovak@example.org ip=198.51.100.120 |
| 9 | Aug 05 11:21:53 helpbot store-login[702]: login failed email=lgreene@example.net ip=198.51.100.120 |
| 10 | Aug 05 12:02:11 helpbot kernel: [UFW BLOCK] IN=eth0 OUT= SRC=192.0.2.41 DST=192.0.2.210 PROTO=TCP DPT=5432 |
| 11 | Aug 05 12:10:30 helpbot kernel: [UFW BLOCK] IN=eth0 OUT= SRC=203.0.113.31 DST=192.0.2.210 PROTO=TCP DPT=3389 |
Source: Hypothetical device records written for this practice question. The store's security team later found that all eight email addresses tried from 198.51.100.120, each with a password, appear in a list stolen from a different retailer and posted online on August 2. 192.0.2.41 is the store's new reporting server
Source 3: Chatbot session log (sudo tail -n 7 /var/log/helpbot/chat.log)
| Line | Entry |
|---|---|
| 1 | Aug 05 14:00:10 helpbot chat: session 7781 user=guest ip=198.51.100.23 msg=[question about the return policy for tents] reply=640 bytes |
| 2 | Aug 05 14:20:02 helpbot chat: session 7790 user=tlin@example.com ip=203.0.113.99 msg=[question about the status of order 55120] reply=512 bytes |
| 3 | Aug 05 14:21:15 helpbot chat: session 7790 msg=[message telling the assistant to ignore its rules and act as a store administrator] reply=96 bytes (refused) |
| 4 | Aug 05 14:21:48 helpbot chat: session 7790 msg=[message claiming to be the store manager and asking for the email addresses of every customer who bought a tent this month] reply=6,412 bytes |
| 5 | Aug 05 14:22:30 helpbot chat: session 7790 msg=[message asking for those customers' order histories and shipping addresses] reply=18,930 bytes |
| 6 | Aug 05 14:23:01 helpbot dlp-scan: replies in session 7790 contained names, emails and addresses of 38 other customers (found after the replies were sent) |
| 7 | Aug 05 14:40:00 helpbot chat: session 7801 user=guest ip=198.51.100.60 msg=[question about boot sizes] reply=702 bytes |
Source: Hypothetical device records written for this practice question. Bracketed text summarizes each customer message; reply sizes are in bytes
Source 4: File listing
$ ls -l /srv/helpbot
-rw-r--r-- 1 helpbot helpbot 6110208 Aug 01 02:00 customer_export.jsonl
-rw-rw-r-- 1 helpbot devs 412 Jul 22 10:40 api_keys.env
-rw-rw-rw- 1 helpbot devs 3020 Jul 30 16:15 assistant_rules.txt
-rwxrwxr-x 1 helpbot devs 1180 Jul 18 09:05 retrain.sh
-rw-rw---- 1 helpbot support 10485760 Aug 05 14:40 chat_history.db
Source: Hypothetical device records written for this practice question
Source 5: Pinecrest Outdoor Gear AI tools policy
Required:
• Chatbot answers that approve a refund over $100 must be checked by a staff member before they are sent.
• Code written with the help of AI tools must be reviewed by a developer before it is released.
Permitted:
• Customer service staff may use the chatbot to draft replies to customers.
Prohibited:
• Staff may not paste customers' personal information into public AI tools.
• The chatbot may not be given access to payment card data.
Source: Hypothetical device records written for this practice question
Suggested time: 50 minutes
Your answers are saved in this browser as you type.
Part (A)
2 points(i) Explain how one rule in the AI tools policy in Source 5 protects the device from a specific threat. (ii) Explain how one rule that is already in the AI tools policy could be changed to make the device more secure. Give a specific example of the changed rule.
0 / 2,500 characters
Part (B)
2 pointsSource 2 contains evidence of an online password attack. (i) Describe the evidence in the log that indicates a password attack. Cite specific line numbers and entries. (ii) Using the evidence and the note under Source 2, identify the specific type of online password attack.
0 / 2,500 characters
Part (C)
3 points(i) Choose one file in /srv/helpbot (Source 4). Explain what its owner, its group and all other users can each do with the file, and how its permission string shows this. Name the file. (ii) Without removing every permission from every user, describe one change to the permissions of one file in Source 4 that would limit access for some users. Name the file. (iii) Write one or more chmod commands that make the change you described in part C (ii).
0 / 2,500 characters
Part (D)
3 points(i) Explain why one connection attempt recorded in the logs was blocked by the device's firewall. Cite the log entry and the firewall rule involved. (ii) Other than allowing all traffic on all ports, describe a change to one existing rule in Source 1 that would let the connection you identified in part D (i) through. (iii) Besides letting that connection through, describe one other effect your change in part D (ii) would have on network traffic to or from the device.
0 / 2,500 characters
Part (E)
4 pointsBesides the password attack in part B, Source 3 shows evidence of a second attack. (i) Determine the type of attack. (ii) Describe the specific information in the sources that indicates this attack. Cite the source and line numbers. (iii) Describe one way an automated system could stop this attack while it is happening. (iv) Other than a firewall, an IDS, an IPS or an AI tool, identify one countermeasure that could prevent, mitigate or deter this attack.
0 / 2,500 characters
Checking scoring…
Scoring it yourself shows you the rubric, examples and a model answer. Try writing your answer first.