Device Security Analysis
Library catalog server: sprayed staff logins and a poisoned book review
- Units 1, 3, 4 and 5
- 14 points
- About 50 minutes
You get several sources from one device, such as its firewall rules, system and web logs, a file listing with permissions, and its acceptable use policy. You explain how the policy protects the device, find the evidence of attacks in the logs, read and write file permissions with chmod, change a firewall rule and say what that changes, and suggest ways to stop the attack. On the exam: The only free-response question: Section II, 1 question in 50 minutes, 30% of the exam score, taken in Bluebook (fully digital) after the 60-question, 80-minute multiple-choice section. The CED sample gives 6 sources about one device and has parts A to E with 14 one-point subparts (A 2, B 2, C 3, D 3, E 4). It assesses Mitigate Risk and Detect Attacks, and you must cite specific evidence, like log line numbers, IP addresses, file names and rule numbers.
The question and its sources
The following sources all come from the same device, the online catalog server at Northgate Public Library (IP address 192.0.2.30), and were gathered during a security review. Use them to answer parts A, B, C, D and E. Label each subpart (i, ii, iii, iv) in your answer, and cite specific evidence such as source numbers, line numbers, IP addresses, file names and rule numbers.
Source 1: Device firewall settings
| Rule | Action | Source | Destination | Direction | Port | Service |
|---|---|---|---|---|---|---|
| 1 | Allow | ALL | 192.0.2.30 | Inbound | 443 | HTTPS |
| 2 | Allow | ALL | 192.0.2.30 | Inbound | 80 | HTTP |
| 3 | Allow | 192.0.2.10 | 192.0.2.30 | Inbound | 22 | SSH |
| 4 | Allow | 192.0.2.0/24 | 192.0.2.30 | Inbound | 5432 | PostgreSQL |
| 5 | Deny | ALL | ALL | Inbound | ALL | ALL |
Source: Hypothetical device records written for this practice question
Source 2: Catalog login log (sudo tail -n 15 /var/log/catalog/login.log)
| Line | Entry |
|---|---|
| 1 | Oct 06 08:59:12 catalog catalog-web[812]: login ok user=rdiaz ip=192.0.2.21 path=/staff/login |
| 2 | Oct 06 23:40:05 catalog catalog-web[812]: login failed user=achen ip=203.0.113.14 path=/staff/login |
| 3 | Oct 06 23:40:07 catalog catalog-web[812]: login failed user=bmorales ip=203.0.113.14 path=/staff/login |
| 4 | Oct 06 23:40:09 catalog catalog-web[812]: login failed user=cwright ip=203.0.113.14 path=/staff/login |
| 5 | Oct 06 23:40:11 catalog catalog-web[812]: login failed user=dpatel ip=203.0.113.14 path=/staff/login |
| 6 | Oct 06 23:40:13 catalog catalog-web[812]: login failed user=eokafor ip=203.0.113.14 path=/staff/login |
| 7 | Oct 06 23:40:15 catalog catalog-web[812]: login failed user=fnguyen ip=203.0.113.14 path=/staff/login |
| 8 | Oct 06 23:40:17 catalog catalog-web[812]: login failed user=gsilva ip=203.0.113.14 path=/staff/login |
| 9 | Oct 06 23:40:19 catalog catalog-web[812]: login failed user=hkim ip=203.0.113.14 path=/staff/login |
| 10 | Oct 06 23:40:21 catalog catalog-web[812]: login failed user=ilopez ip=203.0.113.14 path=/staff/login |
| 11 | Oct 06 23:40:23 catalog catalog-web[812]: login failed user=jsmith ip=203.0.113.14 path=/staff/login |
| 12 | Oct 07 07:52:40 catalog kernel: [UFW BLOCK] IN=eth0 OUT= SRC=192.0.2.88 DST=192.0.2.30 PROTO=TCP DPT=22 |
| 13 | Oct 07 07:55:03 catalog kernel: [UFW BLOCK] IN=eth0 OUT= SRC=198.51.100.9 DST=192.0.2.30 PROTO=TCP DPT=23 |
| 14 | Oct 07 08:02:19 catalog catalog-web[812]: login ok user=rdiaz ip=192.0.2.21 path=/staff/login |
| 15 | Oct 07 08:03:55 catalog catalog-web[812]: login ok user=hkim ip=192.0.2.24 path=/staff/login |
Source: Hypothetical device records written for this practice question
Source 3: Web server access log (sudo tail -n 9 /var/log/nginx/access.log)
| Line | Entry |
|---|---|
| 1 | 198.51.100.57 - - [07/Oct/2026:10:02:11 -0400] "GET /books/4471 HTTP/1.1" 200 8122 "-" "Mozilla/5.0 (iPad)" |
| 2 | 198.51.100.57 - - [07/Oct/2026:10:02:40 -0400] "POST /reviews/new?book=4471 HTTP/1.1" 201 64 "-" "Mozilla/5.0 (iPad)" |
| 3 | 198.51.100.201 - - [07/Oct/2026:10:14:09 -0400] "POST /reviews/new?book=4471&text=[review text containing a script tag that loads code from cdn.example.net] HTTP/1.1" 201 64 "-" "Mozilla/5.0 (X11; Linux)" |
| 4 | 198.51.100.201 - - [07/Oct/2026:10:15:31 -0400] "POST /reviews/new?book=5120&text=[review text containing a script tag that sends the reader's session cookie to cdn.example.net] HTTP/1.1" 201 64 "-" "Mozilla/5.0 (X11; Linux)" |
| 5 | 198.51.100.73 - - [07/Oct/2026:10:20:48 -0400] "GET /books/4471 HTTP/1.1" 200 8391 "-" "Mozilla/5.0 (Windows NT 10.0)" |
| 6 | 192.0.2.21 - rdiaz [07/Oct/2026:10:22:10 -0400] "GET /staff/holds HTTP/1.1" 200 3310 "-" "Mozilla/5.0 (Windows NT 10.0)" |
| 7 | 198.51.100.88 - - [07/Oct/2026:10:31:02 -0400] "GET /books/5120 HTTP/1.1" 200 7954 "-" "Mozilla/5.0 (iPhone)" |
| 8 | 198.51.100.90 - - [07/Oct/2026:10:33:47 -0400] "GET /books/4471 HTTP/1.1" 200 8391 "-" "Mozilla/5.0 (Macintosh)" |
| 9 | 192.0.2.24 - hkim [07/Oct/2026:10:40:15 -0400] "GET /staff/reports HTTP/1.1" 200 2875 "-" "Mozilla/5.0 (Windows NT 10.0)" |
Source: Hypothetical device records written for this practice question. Bracketed text describes request content that has been removed
Source 4: File listing
$ ls -l /srv/catalog
-rw-rw-r-- 1 catalog www-data 90112 Oct 07 06:00 patrons.db
-rw-r--r-- 1 catalog catalog 318 Sep 21 14:12 app.env
-rwxrwxr-x 1 catalog staff 1460 Aug 30 10:05 restart.sh
-rw------- 1 catalog catalog 2210 Oct 01 16:44 staff_notes.txt
-rw-r----- 1 catalog www-data 40960 Oct 07 10:15 reviews.db
Source: Hypothetical device records written for this practice question
Source 5: Northgate Public Library staff computer policy
Required:
• Staff passwords must be at least 10 characters long.
• Staff must lock their screen whenever they step away from a desk.
Permitted:
• Patrons may post book reviews, which appear on the catalog as soon as they are submitted.
• Staff may open the catalog's staff pages from library computers.
Prohibited:
• Staff may not reuse their library password on any other website.
• Staff may not install browser extensions on library computers.
Source: Hypothetical device records written for this practice question
Suggested time: 50 minutes
Your answers are saved in this browser as you type.
Part (A)
2 points(i) Explain how one rule in the staff computer policy in Source 5 protects the device from a specific threat. (ii) Explain how one rule that is already in the staff computer policy could be changed to make the device more secure. Give a specific example of the changed rule.
0 / 2,500 characters
Part (B)
2 pointsSource 2 contains evidence of an online password attack. (i) Describe the evidence in the log that indicates a password attack. Cite specific line numbers and entries. (ii) Identify the specific type of online password attack that the evidence best matches.
0 / 2,500 characters
Part (C)
3 points(i) Choose one file in /srv/catalog (Source 4). Explain what its owner, its group and all other users can each do with the file, and how its permission string shows this. Name the file. (ii) Without removing every permission from every user, describe one change to the permissions of one file in Source 4 that would limit access for some users. Name the file. (iii) Write one or more chmod commands that make the change you described in part C (ii). Use the numeric (octal) form of chmod.
0 / 2,500 characters
Part (D)
3 points(i) Explain why one connection attempt recorded in the logs was blocked by the device's firewall. Cite the log entry and the firewall rule involved. (ii) Other than allowing all traffic on all ports, describe a change to one existing rule in Source 1 that would let the connection you identified in part D (i) through. (iii) Besides letting that connection through, describe one other effect your change in part D (ii) would have on network traffic to or from the device.
0 / 2,500 characters
Part (E)
4 pointsBesides the password attack in part B, another attack is shown in the sources. (i) Determine the type of attack. (ii) Describe the specific information in the sources that indicates this attack. Cite the source and line numbers. (iii) Describe one way an automated system could stop this attack while it is happening. (iv) Other than a firewall, an IDS, an IPS or an AI tool, identify one countermeasure that could prevent, mitigate or deter this attack.
0 / 2,500 characters
Checking scoring…
Scoring it yourself shows you the rubric, examples and a model answer. Try writing your answer first.