Device Security Analysis
Hospital lobby kiosk: a held door and a drive plugged in after hours
- Units 2, 3, 4 and 5
- 14 points
- About 50 minutes
You get several sources from one device, such as its firewall rules, system and web logs, a file listing with permissions, and its acceptable use policy. You explain how the policy protects the device, find the evidence of attacks in the logs, read and write file permissions with chmod, change a firewall rule and say what that changes, and suggest ways to stop the attack. On the exam: The only free-response question: Section II, 1 question in 50 minutes, 30% of the exam score, taken in Bluebook (fully digital) after the 60-question, 80-minute multiple-choice section. The CED sample gives 6 sources about one device and has parts A to E with 14 one-point subparts (A 2, B 2, C 3, D 3, E 4). It assesses Mitigate Risk and Detect Attacks, and you must cite specific evidence, like log line numbers, IP addresses, file names and rule numbers.
The question and its sources
The following sources all come from the same device, a patient check-in kiosk in the lobby of St. Brigid Community Hospital (IP address 192.0.2.160), and were gathered during a security review. Use them to answer parts A, B, C, D and E. Label each subpart (i, ii, iii, iv) in your answer, and cite specific evidence such as source numbers, line numbers, IP addresses, file names and rule numbers.
Source 1: Device firewall settings
| Rule | Action | Source | Destination | Direction | Port | Service |
|---|---|---|---|---|---|---|
| 1 | Allow | 192.0.2.15 | 192.0.2.160 | Inbound | 22 | SSH |
| 2 | Deny | ALL | ALL | Inbound | ALL | ALL |
| 3 | Allow | 192.0.2.160 | 192.0.2.10 | Outbound | 443 | HTTPS |
| 4 | Allow | 192.0.2.160 | 192.0.2.24 | Outbound | 514 | Syslog |
| 5 | Deny | ALL | ALL | Outbound | ALL | ALL |
Source: Hypothetical device records written for this practice question. 192.0.2.10 is the hospital's check-in server. On November 1 the hospital moved its log server from 192.0.2.24 to 192.0.2.25
Source 2: Door badge log (badge-report --door lobby-east --date 2026-11-03)
| Line | Entry |
|---|---|
| 1 | Nov 03 21:02:11 Lobby east door (after hours): badge 3307 (J. Kim, nurse), door open 4 seconds |
| 2 | Nov 03 21:40:52 Lobby east door (after hours): badge 5120 (T. Ames, security), door open 5 seconds |
| 3 | Nov 03 22:09:14 Lobby east door (after hours): badge 4471 (R. Ortiz, night cleaner), door open 47 seconds |
| 4 | Nov 03 22:31:30 Lobby east door (after hours): badge 4471 (R. Ortiz, night cleaner), door open 5 seconds |
| 5 | Nov 03 22:58:02 Lobby east door (after hours): badge 5120 (T. Ames, security), door open 4 seconds |
Source: Hypothetical device records written for this practice question
Source 3: Security desk note
Nov 3, 22:40. R. Ortiz (night cleaner) reported that when she badged in at about 22:09, a man in a delivery uniform carrying a large box asked her to hold the door so he could drop off supplies. She held the door for him. He walked to the lobby and left a few minutes later. No delivery was scheduled for that night.
Source: Hypothetical device records written for this practice question
Source 4: Kiosk system log (sudo tail -n 14 /var/log/syslog)
| Line | Entry |
|---|---|
| 1 | Nov 03 21:58:00 kiosk-lobby1 kiosk-app: idle screen shown |
| 2 | Nov 03 22:11:40 kiosk-lobby1 kernel: usb 1-1: new high-speed USB device number 4 using xhci_hcd |
| 3 | Nov 03 22:11:41 kiosk-lobby1 kernel: usb-storage 1-1:1.0: USB Mass Storage device detected |
| 4 | Nov 03 22:11:43 kiosk-lobby1 udisks: Mounted /dev/sda1 at /media/kiosk/USB |
| 5 | Nov 03 22:11:44 kiosk-lobby1 autorun: running /media/kiosk/USB/setup.sh (autorun is enabled) |
| 6 | Nov 03 22:11:46 kiosk-lobby1 audit: new file /opt/kiosk/bin/kiosk_helper created by setup.sh |
| 7 | Nov 03 22:11:47 kiosk-lobby1 systemd[1]: kiosk-helper.service enabled to start at boot |
| 8 | Nov 03 22:12:05 kiosk-lobby1 kernel: usb 1-1: USB disconnect, device number 4 |
| 9 | Nov 03 22:15:00 kiosk-lobby1 kernel: [UFW BLOCK] IN= OUT=eth0 SRC=192.0.2.160 DST=203.0.113.140 PROTO=TCP DPT=8080 |
| 10 | Nov 03 22:20:00 kiosk-lobby1 kernel: [UFW BLOCK] IN= OUT=eth0 SRC=192.0.2.160 DST=203.0.113.140 PROTO=TCP DPT=8080 |
| 11 | Nov 03 22:25:00 kiosk-lobby1 kernel: [UFW BLOCK] IN= OUT=eth0 SRC=192.0.2.160 DST=203.0.113.140 PROTO=TCP DPT=8080 |
| 12 | Nov 04 06:00:03 kiosk-lobby1 kernel: [UFW BLOCK] IN= OUT=eth0 SRC=192.0.2.160 DST=192.0.2.25 PROTO=UDP DPT=514 |
| 13 | Nov 04 06:00:04 kiosk-lobby1 rsyslogd: could not send log messages to 192.0.2.25 |
| 14 | Nov 04 07:30:12 kiosk-lobby1 kiosk-app: check-in completed for appointment 88213 |
Source: Hypothetical device records written for this practice question
Source 5: File listing
$ ls -l /opt/kiosk/bin
-rwxr-xr-x 1 kiosk kiosk 482304 Sep 12 10:00 kiosk_app
-rwxrwxrwx 1 kiosk kiosk 61440 Nov 03 22:11 kiosk_helper
-rw-rw-rw- 1 kiosk kiosk 2210 Oct 30 14:22 config.json
-rw-r--r-- 1 kiosk kiosk 81920 Nov 04 07:30 patient_queue.db
-rwxrwxr-x 1 kiosk it 1288 Sep 12 10:02 update.sh
Source: Hypothetical device records written for this practice question
Source 6: St. Brigid lobby and kiosk policy
Required:
• After hours, staff must not hold the lobby door open for anyone who does not badge in.
• IT must inspect each kiosk for unknown devices every 90 days.
Permitted:
• Patients may use the kiosk's touch screen and card reader to check in.
Prohibited:
• No one except IT staff may plug a device into a kiosk's USB port.
• Kiosks may not be used to browse the web.
Source: Hypothetical device records written for this practice question
Suggested time: 50 minutes
Your answers are saved in this browser as you type.
Part (A)
2 points(i) Explain how one rule in the lobby and kiosk policy in Source 6 protects the device from a specific threat. (ii) Explain how one rule that is already in the lobby and kiosk policy could be changed to make the device more secure. Give a specific example of the changed rule.
0 / 2,500 characters
Part (B)
2 pointsSources 2 and 3 describe how someone got into the lobby after hours. (i) Describe the evidence in Source 2 that a person may have entered without using their own badge. Cite a specific line. (ii) Using Source 3, identify the type of physical attack.
0 / 2,500 characters
Part (C)
3 points(i) Choose one file in /opt/kiosk/bin (Source 5). Explain what its owner, its group and all other users can each do with the file, and how its permission string shows this. Name the file. (ii) Without removing every permission from every user, describe one change to the permissions of one file in Source 5 that would limit access for some users. Name the file. (iii) Write one or more chmod commands that make the change you described in part C (ii).
0 / 2,500 characters
Part (D)
3 points(i) Explain why one connection attempt in Source 4 was blocked by the device's firewall. Cite the log entry and the firewall rule involved. (ii) The hospital wants the kiosk to send its logs to the new log server at 192.0.2.25. Other than allowing all traffic, describe a change to one existing rule in Source 1 that would let the connection on line 12 through. (iii) Besides letting that connection through, describe one other effect your change in part D (ii) would have on network traffic from the device.
0 / 2,500 characters
Part (E)
4 pointsBesides the physical attack in part B, Source 4 shows evidence of an attack on the kiosk itself. (i) Determine the type of attack. (ii) Describe the specific information in the sources that indicates this attack. Cite the source and line numbers. (iii) Describe one way an automated system could stop this attack while it is happening. (iv) Other than a firewall, an IDS, an IPS or an AI tool, identify one countermeasure that could prevent, mitigate or deter this attack.
0 / 2,500 characters
Checking scoring…
Scoring it yourself shows you the rubric, examples and a model answer. Try writing your answer first.