Skip to main content

Device Security Analysis

Research lab workstation: a scary email and a 2.3 GB upload

  • Units 1, 3, 4 and 5
  • 14 points
  • About 50 minutes

You get several sources from one device, such as its firewall rules, system and web logs, a file listing with permissions, and its acceptable use policy. You explain how the policy protects the device, find the evidence of attacks in the logs, read and write file permissions with chmod, change a firewall rule and say what that changes, and suggest ways to stop the attack. On the exam: The only free-response question: Section II, 1 question in 50 minutes, 30% of the exam score, taken in Bluebook (fully digital) after the 60-question, 80-minute multiple-choice section. The CED sample gives 6 sources about one device and has parts A to E with 14 one-point subparts (A 2, B 2, C 3, D 3, E 4). It assesses Mitigate Risk and Detect Attacks, and you must cite specific evidence, like log line numbers, IP addresses, file names and rule numbers.

The question and its sources

The following sources all come from the same device, a workstation in the Ashford University genomics lab (IP address 192.0.2.140), and were gathered during a security review. The lab's real login page is login.ashford.example.org. Use them to answer parts A, B, C, D and E. Label each subpart (i, ii, iii, iv) in your answer, and cite specific evidence such as source numbers, line numbers, IP addresses, file names and rule numbers.

Source 1: Device firewall settings

RuleActionSourceDestinationDirectionPortService
1Allow192.0.2.0/24192.0.2.140Inbound22SSH
2DenyALLALLInboundALLALL
3Allow192.0.2.140ALLOutbound443HTTPS
4Allow192.0.2.140ALLOutbound21FTP
5Allow192.0.2.140192.0.2.0/24Outbound445SMB
6DenyALLALLOutboundALLALL

Source: Hypothetical device records written for this practice question. Rule 4 was added so the lab can send data to its partner lab at 198.51.100.60

Source 2: Mail and web proxy log (sudo tail -n 6 /var/log/mail-proxy.log)

LineEntry
1Sep 08 15:02:11 lab-ws7 mail: delivered from=<pi-office@ashford.example.org> to=<rpatel@ashford.example.org> subject="Lab meeting moved to Thursday"
2Sep 08 16:44:05 lab-ws7 mail: delivered from=<it-support@ashford-helpdesk.example.net> to=<rpatel@ashford.example.org> subject="URGENT: your research storage will be DELETED in 2 hours unless you verify your account"
3Sep 08 16:44:05 lab-ws7 mail: message contains link to https://login.ashford-helpdesk.example.net/verify
4Sep 08 16:47:30 lab-ws7 proxy: rpatel GET https://login.ashford-helpdesk.example.net/verify 200
5Sep 08 16:48:02 lab-ws7 proxy: rpatel POST https://login.ashford-helpdesk.example.net/verify 302 (form fields: username, password)
6Sep 08 16:50:14 lab-ws7 proxy: rpatel GET https://login.ashford.example.org/ 200

Source: Hypothetical device records written for this practice question

Source 3: System log (sudo tail -n 8 /var/log/syslog)

LineEntry
1Sep 08 09:01:40 lab-ws7 sshd[1402]: Accepted password for rpatel from 192.0.2.141 port 50211 ssh2
2Sep 09 02:39:55 lab-ws7 vpn: user rpatel connected from 203.0.113.88, assigned address 192.0.2.201
3Sep 09 02:41:12 lab-ws7 sshd[2877]: Accepted password for rpatel from 192.0.2.201 port 50980 ssh2
4Sep 09 02:43:30 lab-ws7 audit: user=rpatel created /tmp/out/genome_set_A.tar (2.3 GB) from /data/genomics
5Sep 09 02:47:02 lab-ws7 ftp-client: user=rpatel upload /tmp/out/genome_set_A.tar to 203.0.113.88 port 21 started
6Sep 09 03:19:48 lab-ws7 ftp-client: user=rpatel upload to 203.0.113.88 finished (2.3 GB in 32 minutes)
7Sep 09 03:20:15 lab-ws7 audit: user=rpatel deleted /tmp/out/genome_set_A.tar
8Sep 09 09:05:21 lab-ws7 ftp-client: user=kwong upload /data/genomics/shared/run_118.csv to 198.51.100.60 port 21 finished (48 MB)

Source: Hypothetical device records written for this practice question. 198.51.100.60 is the partner lab's FTP server

Source 4: File listing

$ ls -l /data/genomics

-rw-rw-r-- 1 labadmin genomics 2469606195 Sep 01 12:00 genome_set_A.tar

-rw-r--r-- 1 labadmin genomics 884736 Aug 20 10:31 consent_forms.pdf

-rwxrwxr-x 1 labadmin genomics 15022 Aug 28 17:45 analysis.py

-rw-r--r-- 1 labadmin genomics 96 Jul 14 09:00 partner_ftp.cred

-rw-rw---- 1 labadmin genomics 40210 Sep 07 16:12 lab_notebook.md

Source: Hypothetical device records written for this practice question

Source 5: Ashford genomics lab computer use policy

Required:

• Lab members must report suspicious emails to the IT help desk.

• Sending research data to anyone outside the university must be approved by the lab's principal investigator.

Permitted:

• Lab members may connect from off campus through the university VPN with their university password.

Prohibited:

• Lab members may not enter their university password on any site other than login.ashford.example.org.

• Lab members may not store research data in personal cloud accounts.

Source: Hypothetical device records written for this practice question

Suggested time: 50 minutes

Your answers are saved in this browser as you type.

Something wrong with this question?

What's wrong?

Please don't include personal details.

Part (A)

2 points

(i) Explain how one rule in the lab computer use policy in Source 5 protects the device from a specific threat. (ii) Explain how one rule that is already in the lab computer use policy could be changed to make the device more secure. Give a specific example of the changed rule.

0 / 2,500 characters

Part (B)

2 points

Source 2 shows how the adversary got rpatel's password. (i) Describe the evidence in Source 2 that the email on line 2 was a phishing attack and that it worked. Cite specific line numbers and entries. (ii) Identify one social engineering tactic used in the subject line of that email.

0 / 2,500 characters

Part (C)

3 points

(i) Choose one file in /data/genomics (Source 4). Explain what its owner, its group and all other users can each do with the file, and how its permission string shows this. Name the file. (ii) Without removing every permission from every user, describe one change to the permissions of one file in Source 4 that would limit access for some users. Name the file. (iii) Write one or more chmod commands that make the change you described in part C (ii).

0 / 2,500 characters

Part (D)

3 points

(i) Explain how the upload on line 5 of Source 3 got through the device's firewall. Cite the firewall rule involved. (ii) The lab only needs to send files by FTP to its partner lab at 198.51.100.60. Describe a change to one existing rule in Source 1 that would have blocked the upload on line 5 while still allowing transfers to the partner lab. (iii) Besides blocking that upload, describe one other effect your change in part D (ii) would have on network traffic from the device.

0 / 2,500 characters

Part (E)

4 points

After stealing rpatel's password, the adversary carried out a second attack, shown in Source 3. (i) Determine the type of attack. (ii) Describe the specific information in the sources that indicates this attack. Cite the source and line numbers. (iii) Describe one way an automated system could stop this attack while it is happening. (iv) Other than a firewall, an IDS, an IPS or an AI tool, identify one countermeasure that could prevent, mitigate or deter this attack.

0 / 2,500 characters

Checking scoring…

Scoring it yourself shows you the rubric, examples and a model answer. Try writing your answer first.