Device Security Analysis
Store back-office server: a 3 a.m. login and an oversized gift card number
- Units 1, 3, 4 and 5
- 14 points
- About 50 minutes
You get several sources from one device, such as its firewall rules, system and web logs, a file listing with permissions, and its acceptable use policy. You explain how the policy protects the device, find the evidence of attacks in the logs, read and write file permissions with chmod, change a firewall rule and say what that changes, and suggest ways to stop the attack. On the exam: The only free-response question: Section II, 1 question in 50 minutes, 30% of the exam score, taken in Bluebook (fully digital) after the 60-question, 80-minute multiple-choice section. The CED sample gives 6 sources about one device and has parts A to E with 14 one-point subparts (A 2, B 2, C 3, D 3, E 4). It assesses Mitigate Risk and Detect Attacks, and you must cite specific evidence, like log line numbers, IP addresses, file names and rule numbers.
The question and its sources
The following sources all come from the same device, the back-office server at a Copperline Outfitters store (IP address 192.0.2.90), which handles gift cards and card payment batches, and were gathered during a security review. Use them to answer parts A, B, C, D and E. Label each subpart (i, ii, iii, iv) in your answer, and cite specific evidence such as source numbers, line numbers, IP addresses, file names and rule numbers.
Source 1: Device firewall settings
| Rule | Action | Source | Destination | Direction | Port | Service |
|---|---|---|---|---|---|---|
| 1 | Allow | ALL | 192.0.2.90 | Inbound | 22 | SSH |
| 2 | Deny | 198.51.100.0/24 | ALL | Inbound | ALL | ALL |
| 3 | Allow | ALL | 192.0.2.90 | Inbound | 443 | HTTPS |
| 4 | Allow | 192.0.2.0/24 | 192.0.2.90 | Inbound | 8443 | Gift card API |
| 5 | Deny | ALL | ALL | Inbound | ALL | ALL |
Source: Hypothetical device records written for this practice question. Rule 2 was added last month to block an address range that had attacked other stores
Source 2: System log (sudo tail -n 13 /var/log/syslog)
| Line | Entry |
|---|---|
| 1 | Mar 03 08:56:40 pos-office sshd[3101]: Accepted password for lgarcia from 192.0.2.31 port 51522 ssh2 |
| 2 | Mar 03 17:31:05 pos-office sshd[3101]: pam_unix(sshd:session): session closed for user lgarcia |
| 3 | Mar 04 08:58:12 pos-office sshd[3377]: Accepted password for lgarcia from 192.0.2.31 port 51607 ssh2 |
| 4 | Mar 04 17:29:51 pos-office sshd[3377]: pam_unix(sshd:session): session closed for user lgarcia |
| 5 | Mar 05 03:12:02 pos-office sshd[3590]: Failed password for lgarcia from 198.51.100.90 port 40112 ssh2 |
| 6 | Mar 05 03:12:09 pos-office sshd[3591]: Failed password for lgarcia from 198.51.100.90 port 40118 ssh2 |
| 7 | Mar 05 03:12:15 pos-office sshd[3592]: Failed password for lgarcia from 198.51.100.90 port 40121 ssh2 |
| 8 | Mar 05 03:12:22 pos-office sshd[3593]: Accepted password for lgarcia from 198.51.100.90 port 40127 ssh2 |
| 9 | Mar 05 03:14:48 pos-office sudo: lgarcia : TTY=pts/1 ; PWD=/srv/pos ; USER=root ; COMMAND=/usr/bin/cp /srv/pos/aes_key.bin /tmp/k.bin |
| 10 | Mar 05 10:41:27 pos-office giftcard-web[2231]: segfault in parse_card_number; service stopped |
| 11 | Mar 05 10:41:29 pos-office systemd[1]: giftcard-web.service: restarted after crash |
| 12 | Mar 05 10:41:52 pos-office giftcard-web[2290]: segfault in parse_card_number; service stopped |
| 13 | Mar 05 10:41:54 pos-office systemd[1]: giftcard-web.service: restarted after crash |
Source: Hypothetical device records written for this practice question
Source 3: Web server access log (sudo tail -n 6 /var/log/nginx/access.log)
| Line | Entry |
|---|---|
| 1 | 203.0.113.15 - - [05/Mar/2026:10:30:02 -0500] "GET /giftcard HTTP/1.1" 200 3120 "-" "Mozilla/5.0 (Windows NT 10.0)" |
| 2 | 203.0.113.120 - - [05/Mar/2026:10:33:15 -0500] "POST /giftcard/balance?card=9900123412341234 HTTP/1.1" 200 214 "-" "Mozilla/5.0 (Android)" |
| 3 | 203.0.113.48 - - [05/Mar/2026:10:40:58 -0500] "POST /giftcard/balance?card=9900555566667777 HTTP/1.1" 200 214 "-" "curl/8.4.0" |
| 4 | 203.0.113.48 - - [05/Mar/2026:10:41:27 -0500] "POST /giftcard/balance?card=[a run of about 12,000 digits and letters in the card number field] HTTP/1.1" 500 0 "-" "curl/8.4.0" |
| 5 | 203.0.113.48 - - [05/Mar/2026:10:41:52 -0500] "POST /giftcard/balance?card=[a run of about 24,000 repeated characters in the card number field] HTTP/1.1" 500 0 "-" "curl/8.4.0" |
| 6 | 192.0.2.31 - lgarcia [05/Mar/2026:10:45:10 -0500] "GET /giftcard/report HTTP/1.1" 200 5530 "-" "Mozilla/5.0 (Windows NT 10.0)" |
Source: Hypothetical device records written for this practice question. Bracketed text describes request content that has been removed. Gift card numbers are 16 digits
Source 4: File listing
$ ls -l /srv/pos
-rw-r--r-- 1 posadmin pos 524288 Mar 05 02:00 card_batch_0305.enc
-rw-r--r-- 1 posadmin pos 32 Jan 10 09:30 aes_key.bin
-rwxrwxrwx 1 posadmin pos 1290 Feb 14 11:12 till_sync.sh
-rw-rw-r-- 1 posadmin pos 14200 Mar 05 06:00 settlement_report.csv
-rw-r----- 1 posadmin pos 880 Feb 02 08:15 pos.conf
Source: Hypothetical device records written for this practice question
Source 5: Copperline Outfitters payment data policy
Required:
• Card numbers must be stored only in encrypted form (AES with a 256-bit key).
• Store servers must be patched within 14 days of a security update's release.
Permitted:
• Store managers may sign in to the back-office server from store computers.
Prohibited:
• Staff may not write down, photograph or email card numbers.
• Staff may not use the back-office server for personal web browsing.
Source: Hypothetical device records written for this practice question
Suggested time: 50 minutes
Your answers are saved in this browser as you type.
Part (A)
2 points(i) Explain how one rule in the payment data policy in Source 5 protects the device from a specific threat. (ii) Explain how one rule that is already in the payment data policy could be changed to make the device more secure. Give a specific example of the changed rule.
0 / 2,500 characters
Part (B)
2 pointsSource 2 contains evidence that an account on the server was compromised. (i) Describe the evidence in the log that one account was used by someone other than its owner. Cite specific line numbers and entries. (ii) Identify the IP address of the adversary.
0 / 2,500 characters
Part (C)
3 points(i) Choose one file in /srv/pos (Source 4). Explain what its owner, its group and all other users can each do with the file, and how its permission string shows this. Name the file. (ii) Without removing every permission from every user, describe one change to the permissions of one file in Source 4 that would limit access for some users. Name the file. (iii) Write one or more chmod commands that make the change you described in part C (ii).
0 / 2,500 characters
Part (D)
3 pointsRule 2 in Source 1 was meant to block every connection from the range 198.51.100.0/24. (i) Explain why the login from 198.51.100.90 on line 8 of Source 2 still got through the firewall. Cite the rules involved. (ii) Other than blocking all traffic, describe a change to one existing rule in Source 1 (without adding or deleting rules) that would block SSH from 198.51.100.0/24 while still letting store computers on 192.0.2.0/24 use SSH. (iii) Besides blocking SSH from 198.51.100.0/24, describe one other effect your change in part D (ii) would have on network traffic to the device.
0 / 2,500 characters
Part (E)
4 pointsBesides the account compromise in part B, the sources show evidence of a second attack. (i) Determine the type of attack. (ii) Describe the specific information in the sources that indicates this attack. Cite the source and line numbers. (iii) Describe one way an automated system could stop this attack while it is happening. (iv) Other than a firewall, an IDS, an IPS or an AI tool, identify one countermeasure that could prevent, mitigate or deter this attack.
0 / 2,500 characters
Checking scoring…
Scoring it yourself shows you the rubric, examples and a model answer. Try writing your answer first.