Skip to main content

Device Security Analysis

Warehouse handheld scanner: a guessed PIN and a flashlight app that phones home

  • Units 3, 4 and 5
  • 14 points
  • About 50 minutes

You get several sources from one device, such as its firewall rules, system and web logs, a file listing with permissions, and its acceptable use policy. You explain how the policy protects the device, find the evidence of attacks in the logs, read and write file permissions with chmod, change a firewall rule and say what that changes, and suggest ways to stop the attack. On the exam: The only free-response question: Section II, 1 question in 50 minutes, 30% of the exam score, taken in Bluebook (fully digital) after the 60-question, 80-minute multiple-choice section. The CED sample gives 6 sources about one device and has parts A to E with 14 one-point subparts (A 2, B 2, C 3, D 3, E 4). It assesses Mitigate Risk and Detect Attacks, and you must cite specific evidence, like log line numbers, IP addresses, file names and rule numbers.

The question and its sources

The following sources all come from the same device, a handheld barcode scanner, scanner-12, at the Summit Freight warehouse (IP address 192.0.2.150), and were gathered during a security review. The scanner is a small handheld computer that runs Linux. Use them to answer parts A, B, C, D and E. Label each subpart (i, ii, iii, iv) in your answer, and cite specific evidence such as source numbers, line numbers, IP addresses, file names and rule numbers.

Source 1: Device firewall settings

RuleActionSourceDestinationDirectionPortService
1Allow192.0.2.5192.0.2.150Inbound22SSH
2DenyALLALLInboundALLALL
3Allow192.0.2.150192.0.2.10Outbound443HTTPS
4Allow192.0.2.150ALLOutbound8080HTTP-alt
5DenyALLALLOutboundALLALL

Source: Hypothetical device records written for this practice question. Rule 4 was left over from the vendor's testing. On July 14 at 13:00 the warehouse moved its inventory system from 192.0.2.10 to 192.0.2.11

Source 2: Scanner system log (sudo tail -n 17 /var/log/syslog)

LineEntry
1Jul 14 06:01:12 scanner-12 lockscreen: user worker7 unlocked the screen (PIN ok)
2Jul 14 12:31:05 scanner-12 lockscreen: wrong PIN for user supervisor (attempt 1)
3Jul 14 12:31:09 scanner-12 lockscreen: wrong PIN for user supervisor (attempt 2)
4Jul 14 12:31:13 scanner-12 lockscreen: wrong PIN for user supervisor (attempt 3)
5Jul 14 12:31:17 scanner-12 lockscreen: wrong PIN for user supervisor (attempt 4)
6Jul 14 12:31:21 scanner-12 lockscreen: wrong PIN for user supervisor (attempt 5)
7Jul 14 12:31:25 scanner-12 lockscreen: wrong PIN for user supervisor (attempt 6)
8Jul 14 12:31:31 scanner-12 lockscreen: user supervisor unlocked the screen (PIN ok)
9Jul 14 12:32:10 scanner-12 pkg: supervisor installed flashlight-plus 1.0 from /media/usb0/flashlight-plus.pkg (unsigned; not on the approved app list)
10Jul 14 12:32:40 scanner-12 flashlight-plus: requested access to camera, location and contacts; access granted
11Jul 14 12:33:00 scanner-12 audit: process flplus-agent opened /var/lib/scanner/location.db
12Jul 14 12:40:00 scanner-12 kernel: [UFW BLOCK] IN= OUT=eth0 SRC=192.0.2.150 DST=203.0.113.150 PROTO=TCP DPT=443
13Jul 14 12:40:02 scanner-12 conntrack: NEW tcp src=192.0.2.150 dst=203.0.113.150 dport=8080 (2.1 MB sent)
14Jul 14 12:50:02 scanner-12 conntrack: NEW tcp src=192.0.2.150 dst=203.0.113.150 dport=8080 (2.1 MB sent)
15Jul 14 13:00:02 scanner-12 conntrack: NEW tcp src=192.0.2.150 dst=203.0.113.150 dport=8080 (2.2 MB sent)
16Jul 14 13:05:40 scanner-12 kernel: [UFW BLOCK] IN= OUT=eth0 SRC=192.0.2.150 DST=192.0.2.11 PROTO=TCP DPT=443
17Jul 14 13:05:41 scanner-12 inventory-app: cannot reach inventory server 192.0.2.11

Source: Hypothetical device records written for this practice question. Scanners use a 4-digit PIN. Workers start their shifts at 6:00 a.m.

Source 3: File listing

$ ls -l /var/lib/scanner

-rw-rw-rw- 1 scanner scanner 1048576 Jul 14 13:00 location.db

-rw-rw-r-- 1 scanner warehouse 524288 Jul 14 12:58 inventory_cache.db

-rw-r--r-- 1 scanner scanner 214 Jun 02 08:00 wifi.conf

-rwxrwxrwx 1 scanner scanner 940 Jun 02 08:05 sync.sh

-rw-rw-r-- 1 scanner warehouse 380 Jun 30 15:20 approved_apps.list

Source: Hypothetical device records written for this practice question

Source 4: Summit Freight handheld device policy

Required:

• Scanners must lock after 2 minutes without use and unlock with a 4-digit PIN.

• Only apps on the company's approved app list may be installed.

Permitted:

• Workers may use the scanner's camera to photograph damaged pallets.

Prohibited:

• Scanners may not leave the warehouse.

• Workers may not plug USB drives or personal devices into scanners.

Source: Hypothetical device records written for this practice question

Suggested time: 50 minutes

Your answers are saved in this browser as you type.

Something wrong with this question?

What's wrong?

Please don't include personal details.

Part (A)

2 points

(i) Explain how one rule in the handheld device policy in Source 4 protects the device from a specific threat. (ii) Explain how one rule that is already in the handheld device policy could be changed to make the device more secure. Give a specific example of the changed rule.

0 / 2,500 characters

Part (B)

2 points

Source 2 contains evidence that someone guessed their way into the scanner. (i) Describe the evidence in the log. Cite specific line numbers and entries. (ii) Identify one login setting that would have stopped or slowed this attack, and explain how.

0 / 2,500 characters

Part (C)

3 points

(i) Choose one file in /var/lib/scanner (Source 3). Explain what its owner, its group and all other users can each do with the file, and how its permission string shows this. Name the file. (ii) Without removing every permission from every user, describe one change to the permissions of one file in Source 3 that would limit access for some users. Name the file. (iii) Write one or more chmod commands that make the change you described in part C (ii).

0 / 2,500 characters

Part (D)

3 points

(i) Explain why one connection attempt in Source 2 was blocked by the device's firewall. Cite the log entry and the firewall rule involved. (ii) The warehouse has moved its inventory system to 192.0.2.11. Other than allowing all traffic, describe a change to one existing rule in Source 1 that would let the connection on line 16 through. (iii) Besides letting that connection through, describe one other effect your change in part D (ii) would have on network traffic from the device.

0 / 2,500 characters

Part (E)

4 points

Besides the password attack in part B, Source 2 shows evidence of a second attack. (i) Determine the type of attack. (ii) Describe the specific information in the sources that indicates this attack. Cite the source and line numbers. (iii) Describe one way an automated system could stop this attack while it is happening. (iv) Other than a firewall, an IDS, an IPS or an AI tool, identify one countermeasure that could prevent, mitigate or deter this attack.

0 / 2,500 characters

Checking scoring…

Scoring it yourself shows you the rubric, examples and a model answer. Try writing your answer first.