Device Security Analysis
School district DNS server: a contractor login and a changed record
- Units 3, 4 and 5
- 14 points
- About 50 minutes
You get several sources from one device, such as its firewall rules, system and web logs, a file listing with permissions, and its acceptable use policy. You explain how the policy protects the device, find the evidence of attacks in the logs, read and write file permissions with chmod, change a firewall rule and say what that changes, and suggest ways to stop the attack. On the exam: The only free-response question: Section II, 1 question in 50 minutes, 30% of the exam score, taken in Bluebook (fully digital) after the 60-question, 80-minute multiple-choice section. The CED sample gives 6 sources about one device and has parts A to E with 14 one-point subparts (A 2, B 2, C 3, D 3, E 4). It assesses Mitigate Risk and Detect Attacks, and you must cite specific evidence, like log line numbers, IP addresses, file names and rule numbers.
The question and its sources
The following sources all come from the same device, the internal DNS server for Fairview Unified School District (IP address 192.0.2.8), and were gathered during a security review. Students and staff sign in at login.fairview.example.org, which runs on 192.0.2.80. Use them to answer parts A, B, C, D and E. Label each subpart (i, ii, iii, iv) in your answer, and cite specific evidence such as source numbers, line numbers, IP addresses, file names and rule numbers.
Source 1: Device firewall settings
| Rule | Action | Source | Destination | Direction | Port | Service |
|---|---|---|---|---|---|---|
| 1 | Allow | 192.0.2.0/24 | 192.0.2.8 | Inbound | 53 | DNS |
| 2 | Allow | 192.0.2.5 | 192.0.2.8 | Inbound | 22 | SSH |
| 3 | Allow | 203.0.113.0/24 | 192.0.2.8 | Inbound | 22 | SSH |
| 4 | Deny | ALL | ALL | Inbound | ALL | ALL |
Source: Hypothetical device records written for this practice question. Rule 3 was added for the district's DNS contractor, whose office network is 203.0.113.0/24. The district's new Lincoln Elementary campus uses 198.51.100.0/24
Source 2: Authentication log (sudo tail -n 15 /var/log/auth.log)
| Line | Entry |
|---|---|
| 1 | Oct 20 14:10:02 ns1 sshd[3301]: Accepted publickey for jreyes from 192.0.2.5 port 50110 ssh2 |
| 2 | Oct 21 02:10:04 ns1 sshd[3410]: Failed password for dnsadmin from 203.0.113.66 port 41000 ssh2 |
| 3 | Oct 21 02:10:08 ns1 sshd[3411]: Failed password for dnsadmin from 203.0.113.66 port 41003 ssh2 |
| 4 | Oct 21 02:10:12 ns1 sshd[3412]: Failed password for dnsadmin from 203.0.113.66 port 41006 ssh2 |
| 5 | Oct 21 02:10:16 ns1 sshd[3413]: Failed password for dnsadmin from 203.0.113.66 port 41009 ssh2 |
| 6 | Oct 21 02:10:20 ns1 sshd[3414]: Failed password for dnsadmin from 203.0.113.66 port 41012 ssh2 |
| 7 | Oct 21 02:10:24 ns1 sshd[3415]: Failed password for dnsadmin from 203.0.113.66 port 41015 ssh2 |
| 8 | Oct 21 02:10:28 ns1 sshd[3416]: Failed password for dnsadmin from 203.0.113.66 port 41018 ssh2 |
| 9 | Oct 21 02:10:32 ns1 sshd[3417]: Failed password for dnsadmin from 203.0.113.66 port 41021 ssh2 |
| 10 | Oct 21 02:10:36 ns1 sshd[3418]: Failed password for dnsadmin from 203.0.113.66 port 41024 ssh2 |
| 11 | Oct 21 02:10:40 ns1 sshd[3419]: Failed password for dnsadmin from 203.0.113.66 port 41027 ssh2 |
| 12 | Oct 21 02:10:46 ns1 sshd[3420]: Accepted password for dnsadmin from 203.0.113.66 port 41030 ssh2 |
| 13 | Oct 21 02:11:30 ns1 sudo: dnsadmin : TTY=pts/0 ; PWD=/home/dnsadmin ; USER=root ; COMMAND=/usr/bin/nano /etc/bind/db.fairview |
| 14 | Oct 21 07:31:09 ns1 kernel: [UFW BLOCK] IN=eth0 OUT= SRC=198.51.100.12 DST=192.0.2.8 PROTO=UDP DPT=53 |
| 15 | Oct 21 07:40:22 ns1 kernel: [UFW BLOCK] IN=eth0 OUT= SRC=198.51.100.12 DST=192.0.2.8 PROTO=UDP DPT=53 |
Source: Hypothetical device records written for this practice question
Source 3: DNS server log (sudo tail -n 4 /var/log/named/named.log)
| Line | Entry |
|---|---|
| 1 | Oct 20 16:00:00 ns1 named: zone fairview.example.org serial 2026102001 loaded |
| 2 | Oct 21 02:12:30 ns1 named: zone fairview.example.org: record login.fairview.example.org changed from 192.0.2.80 to 203.0.113.66 (edited by dnsadmin; no ticket number) |
| 3 | Oct 21 02:12:31 ns1 named: zone fairview.example.org reloaded |
| 4 | Oct 21 07:45:00 ns1 named: 1,812 queries for login.fairview.example.org answered with 203.0.113.66 since 02:12 |
Source: Hypothetical device records written for this practice question
Source 4: Sign-ins on login.fairview.example.org (192.0.2.80)
| Day | Successful sign-ins, 7:00–8:00 a.m. |
|---|---|
| Monday, Oct 19 | 1,904 |
| Tuesday, Oct 20 | 1,876 |
| Wednesday, Oct 21 | 41 |
Source: Hypothetical device records written for this practice question
Source 5: File listing
$ ls -l /etc/bind
-rw-rw-rw- 1 root bind 4402 Oct 21 02:12 db.fairview
-rw-r--r-- 1 root bind 1210 Sep 02 10:00 named.conf
-rw-r--r-- 1 bind bind 100 Sep 02 10:01 rndc.key
-rwxrwxr-x 1 root bind 512 Sep 02 10:05 zone_backup.sh
Source: Hypothetical device records written for this practice question
Source 6: Fairview USD DNS server policy
Required:
• Every change to a DNS record must include a ticket number.
• Administrator passwords must be at least 14 characters long.
Permitted:
• The district's DNS contractor may connect over SSH from its office network.
Prohibited:
• Administrators may not use shared accounts.
• The DNS server may not answer queries from outside the district.
Source: Hypothetical device records written for this practice question
Suggested time: 50 minutes
Your answers are saved in this browser as you type.
Part (A)
2 points(i) Explain how one rule in the DNS server policy in Source 6 protects the device from a specific threat. (ii) Explain how one rule that is already in the DNS server policy could be changed to make the device more secure. Give a specific example of the changed rule.
0 / 2,500 characters
Part (B)
2 pointsSource 2 contains evidence of an online password attack. (i) Describe the evidence in the log that indicates a password attack. Cite specific line numbers and entries. (ii) Identify the IP address of the adversary.
0 / 2,500 characters
Part (C)
3 points(i) Choose one file in /etc/bind (Source 5). Explain what its owner, its group and all other users can each do with the file, and how its permission string shows this. Name the file. (ii) Without removing every permission from every user, describe one change to the permissions of one file in Source 5 that would limit access for some users. Name the file. (iii) Write one or more chmod commands that make the change you described in part C (ii). Use the numeric (octal) form of chmod.
0 / 2,500 characters
Part (D)
3 points(i) Explain why one connection attempt recorded in the logs was blocked by the device's firewall. Cite the log entry and the firewall rule involved. (ii) Other than allowing all traffic on all ports, describe a change to one existing rule in Source 1 that would let the connection you identified in part D (i) through. (iii) Besides letting that connection through, describe one other effect your change in part D (ii) would have on network traffic to or from the device.
0 / 2,500 characters
Part (E)
4 pointsBesides the password attack in part B, the sources show evidence of a second attack. (i) Determine the type of attack. (ii) Describe the specific information in the sources that indicates this attack. Cite the source and line numbers. (iii) Describe one way an automated system could stop this attack while it is happening. (iv) Other than a firewall, an IDS, an IPS or an AI tool, identify one countermeasure that could prevent, mitigate or deter this attack.
0 / 2,500 characters
Checking scoring…
Scoring it yourself shows you the rubric, examples and a model answer. Try writing your answer first.