Skip to main content

Device Security Analysis

Hospital lobby kiosk: a held door and a drive plugged in after hours

  • Units 2, 3, 4 and 5
  • 14 points
  • About 50 minutes

You get several sources from one device, such as its firewall rules, system and web logs, a file listing with permissions, and its acceptable use policy. You explain how the policy protects the device, find the evidence of attacks in the logs, read and write file permissions with chmod, change a firewall rule and say what that changes, and suggest ways to stop the attack. On the exam: The only free-response question: Section II, 1 question in 50 minutes, 30% of the exam score, taken in Bluebook (fully digital) after the 60-question, 80-minute multiple-choice section. The CED sample gives 6 sources about one device and has parts A to E with 14 one-point subparts (A 2, B 2, C 3, D 3, E 4). It assesses Mitigate Risk and Detect Attacks, and you must cite specific evidence, like log line numbers, IP addresses, file names and rule numbers.

The question and its sources

The following sources all come from the same device, a patient check-in kiosk in the lobby of St. Brigid Community Hospital (IP address 192.0.2.160), and were gathered during a security review. Use them to answer parts A, B, C, D and E. Label each subpart (i, ii, iii, iv) in your answer, and cite specific evidence such as source numbers, line numbers, IP addresses, file names and rule numbers.

Source 1: Device firewall settings

RuleActionSourceDestinationDirectionPortService
1Allow192.0.2.15192.0.2.160Inbound22SSH
2DenyALLALLInboundALLALL
3Allow192.0.2.160192.0.2.10Outbound443HTTPS
4Allow192.0.2.160192.0.2.24Outbound514Syslog
5DenyALLALLOutboundALLALL

Source: Hypothetical device records written for this practice question. 192.0.2.10 is the hospital's check-in server. On November 1 the hospital moved its log server from 192.0.2.24 to 192.0.2.25

Source 2: Door badge log (badge-report --door lobby-east --date 2026-11-03)

LineEntry
1Nov 03 21:02:11 Lobby east door (after hours): badge 3307 (J. Kim, nurse), door open 4 seconds
2Nov 03 21:40:52 Lobby east door (after hours): badge 5120 (T. Ames, security), door open 5 seconds
3Nov 03 22:09:14 Lobby east door (after hours): badge 4471 (R. Ortiz, night cleaner), door open 47 seconds
4Nov 03 22:31:30 Lobby east door (after hours): badge 4471 (R. Ortiz, night cleaner), door open 5 seconds
5Nov 03 22:58:02 Lobby east door (after hours): badge 5120 (T. Ames, security), door open 4 seconds

Source: Hypothetical device records written for this practice question

Source 3: Security desk note

Nov 3, 22:40. R. Ortiz (night cleaner) reported that when she badged in at about 22:09, a man in a delivery uniform carrying a large box asked her to hold the door so he could drop off supplies. She held the door for him. He walked to the lobby and left a few minutes later. No delivery was scheduled for that night.

Source: Hypothetical device records written for this practice question

Source 4: Kiosk system log (sudo tail -n 14 /var/log/syslog)

LineEntry
1Nov 03 21:58:00 kiosk-lobby1 kiosk-app: idle screen shown
2Nov 03 22:11:40 kiosk-lobby1 kernel: usb 1-1: new high-speed USB device number 4 using xhci_hcd
3Nov 03 22:11:41 kiosk-lobby1 kernel: usb-storage 1-1:1.0: USB Mass Storage device detected
4Nov 03 22:11:43 kiosk-lobby1 udisks: Mounted /dev/sda1 at /media/kiosk/USB
5Nov 03 22:11:44 kiosk-lobby1 autorun: running /media/kiosk/USB/setup.sh (autorun is enabled)
6Nov 03 22:11:46 kiosk-lobby1 audit: new file /opt/kiosk/bin/kiosk_helper created by setup.sh
7Nov 03 22:11:47 kiosk-lobby1 systemd[1]: kiosk-helper.service enabled to start at boot
8Nov 03 22:12:05 kiosk-lobby1 kernel: usb 1-1: USB disconnect, device number 4
9Nov 03 22:15:00 kiosk-lobby1 kernel: [UFW BLOCK] IN= OUT=eth0 SRC=192.0.2.160 DST=203.0.113.140 PROTO=TCP DPT=8080
10Nov 03 22:20:00 kiosk-lobby1 kernel: [UFW BLOCK] IN= OUT=eth0 SRC=192.0.2.160 DST=203.0.113.140 PROTO=TCP DPT=8080
11Nov 03 22:25:00 kiosk-lobby1 kernel: [UFW BLOCK] IN= OUT=eth0 SRC=192.0.2.160 DST=203.0.113.140 PROTO=TCP DPT=8080
12Nov 04 06:00:03 kiosk-lobby1 kernel: [UFW BLOCK] IN= OUT=eth0 SRC=192.0.2.160 DST=192.0.2.25 PROTO=UDP DPT=514
13Nov 04 06:00:04 kiosk-lobby1 rsyslogd: could not send log messages to 192.0.2.25
14Nov 04 07:30:12 kiosk-lobby1 kiosk-app: check-in completed for appointment 88213

Source: Hypothetical device records written for this practice question

Source 5: File listing

$ ls -l /opt/kiosk/bin

-rwxr-xr-x 1 kiosk kiosk 482304 Sep 12 10:00 kiosk_app

-rwxrwxrwx 1 kiosk kiosk 61440 Nov 03 22:11 kiosk_helper

-rw-rw-rw- 1 kiosk kiosk 2210 Oct 30 14:22 config.json

-rw-r--r-- 1 kiosk kiosk 81920 Nov 04 07:30 patient_queue.db

-rwxrwxr-x 1 kiosk it 1288 Sep 12 10:02 update.sh

Source: Hypothetical device records written for this practice question

Source 6: St. Brigid lobby and kiosk policy

Required:

• After hours, staff must not hold the lobby door open for anyone who does not badge in.

• IT must inspect each kiosk for unknown devices every 90 days.

Permitted:

• Patients may use the kiosk's touch screen and card reader to check in.

Prohibited:

• No one except IT staff may plug a device into a kiosk's USB port.

• Kiosks may not be used to browse the web.

Source: Hypothetical device records written for this practice question

Suggested time: 50 minutes

Your answers are saved in this browser as you type.

Something wrong with this question?

What's wrong?

Please don't include personal details.

Part (A)

2 points

(i) Explain how one rule in the lobby and kiosk policy in Source 6 protects the device from a specific threat. (ii) Explain how one rule that is already in the lobby and kiosk policy could be changed to make the device more secure. Give a specific example of the changed rule.

0 / 2,500 characters

Part (B)

2 points

Sources 2 and 3 describe how someone got into the lobby after hours. (i) Describe the evidence in Source 2 that a person may have entered without using their own badge. Cite a specific line. (ii) Using Source 3, identify the type of physical attack.

0 / 2,500 characters

Part (C)

3 points

(i) Choose one file in /opt/kiosk/bin (Source 5). Explain what its owner, its group and all other users can each do with the file, and how its permission string shows this. Name the file. (ii) Without removing every permission from every user, describe one change to the permissions of one file in Source 5 that would limit access for some users. Name the file. (iii) Write one or more chmod commands that make the change you described in part C (ii).

0 / 2,500 characters

Part (D)

3 points

(i) Explain why one connection attempt in Source 4 was blocked by the device's firewall. Cite the log entry and the firewall rule involved. (ii) The hospital wants the kiosk to send its logs to the new log server at 192.0.2.25. Other than allowing all traffic, describe a change to one existing rule in Source 1 that would let the connection on line 12 through. (iii) Besides letting that connection through, describe one other effect your change in part D (ii) would have on network traffic from the device.

0 / 2,500 characters

Part (E)

4 points

Besides the physical attack in part B, Source 4 shows evidence of an attack on the kiosk itself. (i) Determine the type of attack. (ii) Describe the specific information in the sources that indicates this attack. Cite the source and line numbers. (iii) Describe one way an automated system could stop this attack while it is happening. (iv) Other than a firewall, an IDS, an IPS or an AI tool, identify one countermeasure that could prevent, mitigate or deter this attack.

0 / 2,500 characters

Checking scoring…

Scoring it yourself shows you the rubric, examples and a model answer. Try writing your answer first.