You're a junior network security analyst at a regional bank. The security team received reports of 'weird network behavior' from the operations team, and your manager wants you to investigate. You'll analyze firewall configurations, review traffic logs, and examine packet captures to determine what's normal, what's misconfigured, and what might be malicious.
Reading the Wire
Work through the scenario and submit your answers.
Firewall Rule Review
Your manager asks you to review a section of the perimeter firewall rules. The previous network admin left abruptly, and documentation is sparse.
Rule # | Source | Destination | Port/Protocol | Action | Description
--------|-----------------|-----------------|---------------|--------|------------------
101 | Any | 10.1.1.50 | 443/TCP | Allow | Public web server
102 | Any | 10.1.1.50 | 80/TCP | Allow | HTTP redirect
103 | 192.168.1.0/24 | Any | Any | Allow | Corp LAN outbound
104 | Any | 10.1.1.100 | 22/TCP | Allow | SSH management
105 | 10.5.0.0/16 | 10.1.2.0/24 | 1433/TCP | Allow | Database access
106 | Any | 10.1.1.51 | 21/TCP | Allow | FTP server
107 | Any | 10.1.1.51 | 20/TCP | Allow | FTP data
108 | 172.16.50.25 | 10.1.2.50 | 3389/TCP | Allow | Vendor RDP
109 | Any | Any | Any | Allow | [No description]
110 | Any | Any | Any | Deny | Default deny
Rate each firewall rule's security posture:
Focus on the three rules you rated as most problematic. For each one:
- Explain what's wrong with it
- Describe what an attacker could exploit
- Write the corrected rule (or recommend removal)
Suspicious Outbound Traffic
The SOC flagged unusual outbound traffic from a workstation (10.1.5.47) belonging to someone in Accounting. Here's the connection log:
Timestamp | Src IP | Dst IP | Dst Port | Bytes Out | Bytes In | Duration
---------------------|-------------|-----------------|----------|-----------|-----------|----------
2026-01-28 09:15:22 | 10.1.5.47 | 13.107.42.14 | 443 | 2,340 | 45,230 | 3.2s
2026-01-28 09:15:45 | 10.1.5.47 | 52.96.166.130 | 443 | 5,120 | 128,450 | 8.1s
2026-01-28 09:22:18 | 10.1.5.47 | 185.243.115.42 | 443 | 1,024 | 512 | 0.4s
2026-01-28 09:22:19 | 10.1.5.47 | 185.243.115.42 | 443 | 45,670 | 1,024 | 12.3s
2026-01-28 09:35:02 | 10.1.5.47 | 185.243.115.42 | 443 | 89,340 | 1,024 | 24.1s
2026-01-28 09:48:33 | 10.1.5.47 | 185.243.115.42 | 443 | 156,200 | 1,024 | 41.2s
2026-01-28 10:01:15 | 10.1.5.47 | 40.126.28.11 | 443 | 3,400 | 67,800 | 5.5s
2026-01-28 10:15:44 | 10.1.5.47 | 185.243.115.42 | 443 | 203,450 | 1,024 | 53.8s
For context: 13.107.x.x and 52.96.x.x are Microsoft IP ranges. 40.126.x.x is Azure AD. The 185.243.115.42 address is hosted by a VPS provider in Eastern Europe.
Looking at the traffic pattern to 185.243.115.42, what specifically about the bytes in/out ratio concerns you? What type of activity does this pattern typically indicate?
What additional information would you want to gather to continue your investigation? Select all that apply.
Based on what you see, what's your initial classification of this traffic?
Your manager asks: "Should we isolate this workstation now or wait until we have more information?"
What's your recommendation and why? Consider the trade-offs between containing a potential threat and disrupting business operations based on incomplete information.
Packet Capture Analysis
You captured some traffic from a host that's been flagged by EDR. Here's a decoded excerpt showing DNS queries:
Frame 1: DNS Query
Source: 10.1.5.102
Destination: 10.1.1.10 (Internal DNS)
Query: aGVsbG8gd29ybGQ.data.update-srv.net (Type A)
Frame 2: DNS Response
Source: 10.1.1.10
Destination: 10.1.5.102
Answer: 192.0.2.1 (TTL: 60)
Frame 3: DNS Query
Source: 10.1.5.102
Destination: 10.1.1.10
Query: dGhpcyBpcyBhIHRlc3Q.data.update-srv.net (Type A)
Frame 4: DNS Response
Source: 10.1.1.10
Destination: 10.1.5.102
Answer: 192.0.2.1 (TTL: 60)
Frame 5: DNS Query
Source: 10.1.5.102
Destination: 10.1.1.10
Query: c2VjcmV0IGRhdGE.data.update-srv.net (Type A)
[Pattern continues with similar queries every 30 seconds]
The subdomain portions (aGVsbG8gd29ybGQ, dGhpcyBpcyBhIHRlc3Q, c2VjcmV0IGRhdGE) look like encoded data. What encoding is this, and what do these three strings decode to?
What technique is being demonstrated in this packet capture?
Explain how this technique works in your own words. Include:
- Why an attacker would use DNS for this purpose
- What the 30-second interval might indicate
- What network controls could detect or prevent this
The Noisy Neighbor
Operations complains that the network has been slow. You run a capture on the core switch and notice one host generating unusual traffic:
Top Talkers (Last 5 Minutes):
Source IP | Packets | Bytes | Unique Destinations
--------------|---------|------------|--------------------
10.1.3.25 | 847,203 | 42,360,150 | 23,847
10.1.5.47 | 12,450 | 8,234,500 | 45
10.1.2.100 | 8,320 | 5,120,000 | 12
10.1.4.15 | 5,670 | 2,340,000 | 8
Traffic Sample from 10.1.3.25:
Dst IP | Dst Port | Count | Status
--------------|----------|-------|--------
10.1.3.1 | 445 | 3 | RST
10.1.3.2 | 445 | 3 | RST
10.1.3.3 | 445 | 3 | RST
10.1.3.4 | 445 | 3 | SYN-ACK
10.1.3.5 | 445 | 3 | RST
10.1.3.6 | 445 | 3 | RST
10.1.3.7 | 445 | 3 | RST
10.1.3.8 | 445 | 3 | RST
...
[Pattern continues sequentially through 10.1.3.0/24, 10.1.4.0/24, etc.]
10.1.3.25 is registered as a workstation in Engineering.
What is host 10.1.3.25 doing?
The traffic shows mostly RST (reset) responses with occasional SYN-ACK. What does this pattern tell you about what the scanning host is finding?
This could be an authorized vulnerability scan, a compromised host, or something else entirely. Describe the steps you would take to determine which it is before taking containment action. Be specific about what you'd check and in what order.
Documentation
Your manager wants you to document one of the issues you found for the incident tracking system.
Which finding from your investigation warrants the highest priority response?
Write a brief incident summary for the finding you selected above. Include:
- What you observed
- Why it's significant
- Recommended immediate actions
- Suggested follow-up investigation steps
This challenge has closed, so no points are awarded. You can still work through it and keep your response.