Device Security Analysis
Law firm file server: sprayed logins and files that suddenly locked
- Units 3, 4 and 5
- 14 points
- About 50 minutes
You get several sources from one device, such as its firewall rules, system and web logs, a file listing with permissions, and its acceptable use policy. You explain how the policy protects the device, find the evidence of attacks in the logs, read and write file permissions with chmod, change a firewall rule and say what that changes, and suggest ways to stop the attack. On the exam: The only free-response question: Section II, 1 question in 50 minutes, 30% of the exam score, taken in Bluebook (fully digital) after the 60-question, 80-minute multiple-choice section. The CED sample gives 6 sources about one device and has parts A to E with 14 one-point subparts (A 2, B 2, C 3, D 3, E 4). It assesses Mitigate Risk and Detect Attacks, and you must cite specific evidence, like log line numbers, IP addresses, file names and rule numbers.
The question and its sources
The following sources all come from the same device, the shared file server at the law firm Hollis & Grant (IP address 192.0.2.15), and were gathered during a security review. Use them to answer parts A, B, C, D and E. Label each subpart (i, ii, iii, iv) in your answer, and cite specific evidence such as source numbers, line numbers, IP addresses, file names and rule numbers.
Source 1: Device firewall settings
| Rule | Action | Source | Destination | Direction | Port | Service |
|---|---|---|---|---|---|---|
| 1 | Allow | ALL | 192.0.2.15 | Inbound | 445 | SMB |
| 2 | Allow | 192.0.2.5 | 192.0.2.15 | Inbound | 22 | SSH |
| 3 | Allow | 192.0.2.0/24 | 192.0.2.15 | Inbound | 9102 | Backup agent |
| 4 | Deny | ALL | ALL | Inbound | ALL | ALL |
Source: Hypothetical device records written for this practice question. Rule 1 lets lawyers open shared files from home
Source 2: File sharing login log (sudo tail -n 12 /var/log/samba/auth.log)
| Line | Entry |
|---|---|
| 1 | Feb 18 17:42:10 fileserver smbd[2201]: auth ok user=abrooks remote=192.0.2.47 |
| 2 | Feb 19 00:47:11 fileserver smbd[2290]: auth failed user=jmiller remote=198.51.100.37 |
| 3 | Feb 19 00:47:14 fileserver smbd[2290]: auth failed user=abrooks remote=198.51.100.37 |
| 4 | Feb 19 00:47:17 fileserver smbd[2290]: auth failed user=tcarver remote=198.51.100.37 |
| 5 | Feb 19 00:47:20 fileserver smbd[2290]: auth failed user=lfong remote=198.51.100.37 |
| 6 | Feb 19 00:47:23 fileserver smbd[2290]: auth failed user=mhale remote=198.51.100.37 |
| 7 | Feb 19 00:47:26 fileserver smbd[2290]: auth failed user=rortega remote=198.51.100.37 |
| 8 | Feb 19 00:47:29 fileserver smbd[2290]: auth failed user=sgupta remote=198.51.100.37 |
| 9 | Feb 19 00:47:32 fileserver smbd[2290]: auth failed user=paralegal1 remote=198.51.100.37 |
| 10 | Feb 19 00:47:35 fileserver smbd[2290]: auth ok user=paralegal2 remote=198.51.100.37 |
| 11 | Feb 19 07:58:02 fileserver kernel: [UFW BLOCK] IN=eth0 OUT= SRC=192.0.2.60 DST=192.0.2.15 PROTO=TCP DPT=22 |
| 12 | Feb 19 08:10:44 fileserver kernel: [UFW BLOCK] IN=eth0 OUT= SRC=203.0.113.70 DST=192.0.2.15 PROTO=TCP DPT=3389 |
Source: Hypothetical device records written for this practice question
Source 3: File activity log (sudo tail -n 9 /var/log/samba/audit.log)
| Line | Entry |
|---|---|
| 1 | Feb 18 16:20:05 fileserver smbd_audit: user=abrooks ip=192.0.2.47 open Litigation/Case_2291_brief.docx |
| 2 | Feb 18 23:00:00 fileserver backup: nightly job copied 1,906 files to /mnt/backup (drive attached to this server) |
| 3 | Feb 19 00:52:03 fileserver smbd_audit: user=paralegal2 ip=198.51.100.37 rename Litigation/Case_2291_brief.docx to Case_2291_brief.docx.locked |
| 4 | Feb 19 00:52:03 fileserver smbd_audit: user=paralegal2 ip=198.51.100.37 rename Litigation/settlement_draft.docx to settlement_draft.docx.locked |
| 5 | Feb 19 00:52:04 fileserver smbd_audit: user=paralegal2 ip=198.51.100.37 rename Litigation/client_contacts.xlsx to client_contacts.xlsx.locked |
| 6 | Feb 19 00:52:04 fileserver smbd_audit: user=paralegal2 ip=198.51.100.37 create Litigation/HOW_TO_RESTORE_FILES.txt |
| 7 | Feb 19 00:55:41 fileserver smbd_audit: user=paralegal2 ip=198.51.100.37 1,874 more renames to .locked in 3 minutes (all folders) |
| 8 | Feb 19 00:56:10 fileserver smbd_audit: user=paralegal2 ip=198.51.100.37 rename /mnt/backup/Litigation.tar to Litigation.tar.locked |
| 9 | Feb 19 08:02:33 fileserver smbd_audit: user=abrooks ip=192.0.2.47 open Litigation/Case_2291_brief.docx.locked FAILED (unreadable) |
Source: Hypothetical device records written for this practice question
Source 4: File listing
$ ls -l /srv/share/Litigation
-rw-rw-rw- 1 abrooks lawyers 284113 Feb 17 15:02 Case_2291_brief.docx
-rw-rw---- 1 abrooks lawyers 51200 Feb 16 10:40 settlement_draft.docx
-rw-rw-r-- 1 abrooks staff 33820 Feb 10 09:15 client_contacts.xlsx
-rw-r--r-- 1 abrooks staff 18044 Jan 05 11:00 retainer_template.docx
-rwxrwxr-x 1 itadmin staff 902 Dec 12 14:30 sync_backup.sh
Source: Hypothetical device records written for this practice question. This listing was saved the day before the incident
Source 5: Hollis & Grant file server policy
Required:
• All shared files must be backed up every night to the backup drive attached to the file server.
• File server passwords must be at least 10 characters long.
Permitted:
• Lawyers may open shared files from home over the internet.
Prohibited:
• Staff may not store client files on personal devices.
• Staff may not share their file server password with anyone, including assistants.
Source: Hypothetical device records written for this practice question
Suggested time: 50 minutes
Your answers are saved in this browser as you type.
Part (A)
2 points(i) Explain how one rule in the file server policy in Source 5 protects the device from a specific threat. (ii) Explain how one rule that is already in the file server policy could be changed to make the device more secure. Give a specific example of the changed rule.
0 / 2,500 characters
Part (B)
2 pointsSource 2 contains evidence of an online password attack. (i) Describe the evidence in the log that indicates a password attack. Cite specific line numbers and entries. (ii) Identify the IP address of the adversary.
0 / 2,500 characters
Part (C)
3 points(i) Choose one file in /srv/share/Litigation (Source 4). Explain what its owner, its group and all other users can each do with the file, and how its permission string shows this. Name the file. (ii) Without removing every permission from every user, describe one change to the permissions of one file in Source 4 that would limit access for some users. Name the file. (iii) Write one or more chmod commands that make the change you described in part C (ii).
0 / 2,500 characters
Part (D)
3 points(i) Explain why one connection attempt recorded in the logs was blocked by the device's firewall. Cite the log entry and the firewall rule involved. (ii) Other than allowing all traffic on all ports, describe a change to one existing rule in Source 1 that would let the connection you identified in part D (i) through. (iii) Besides letting that connection through, describe one other effect your change in part D (ii) would have on network traffic to or from the device.
0 / 2,500 characters
Part (E)
4 pointsBesides the password attack in part B, Source 3 shows evidence of a second attack. (i) Determine the type of attack. (ii) Describe the specific information in the sources that indicates this attack. Cite the source and line numbers. (iii) Describe one way an automated system could stop this attack while it is happening. (iv) Other than a firewall, an IDS, an IPS or an AI tool, identify one countermeasure that could prevent, mitigate or deter this attack.
0 / 2,500 characters
Checking scoring…
Scoring it yourself shows you the rubric, examples and a model answer. Try writing your answer first.