PRACTICAL SECURITY GUIDANCE
CHALLENGE

Reading the Wire

Work through the scenario and submit your answers.

You're a junior network security analyst at a regional bank. The security team received reports of 'weird network behavior' from the operations team, and your manager wants you to investigate. You'll analyze firewall configurations, review traffic logs, and examine packet captures to determine what's normal, what's misconfigured, and what might be malicious.

Firewall Rule Review

Your manager asks you to review a section of the perimeter firewall rules. The previous network admin left abruptly, and documentation is sparse.

Rule #  | Source          | Destination     | Port/Protocol | Action | Description
--------|-----------------|-----------------|---------------|--------|------------------
101     | Any             | 10.1.1.50       | 443/TCP       | Allow  | Public web server
102     | Any             | 10.1.1.50       | 80/TCP        | Allow  | HTTP redirect
103     | 192.168.1.0/24  | Any             | Any           | Allow  | Corp LAN outbound
104     | Any             | 10.1.1.100      | 22/TCP        | Allow  | SSH management
105     | 10.5.0.0/16     | 10.1.2.0/24     | 1433/TCP      | Allow  | Database access
106     | Any             | 10.1.1.51       | 21/TCP        | Allow  | FTP server
107     | Any             | 10.1.1.51       | 20/TCP        | Allow  | FTP data
108     | 172.16.50.25    | 10.1.2.50       | 3389/TCP      | Allow  | Vendor RDP
109     | Any             | Any             | Any           | Allow  | [No description]
110     | Any             | Any             | Any           | Deny   | Default deny

Rate each firewall rule's security posture:

Rule 101 (HTTPS to web server)
Rule 103 (Corp LAN outbound)
Rule 104 (SSH management)
Rule 106 (FTP server)
Rule 108 (Vendor RDP)
Rule 109 (No description)

Focus on the three rules you rated as most problematic. For each one:

  • Explain what's wrong with it
  • Describe what an attacker could exploit
  • Write the corrected rule (or recommend removal)

Suspicious Outbound Traffic

The SOC flagged unusual outbound traffic from a workstation (10.1.5.47) belonging to someone in Accounting. Here's the connection log:

Timestamp            | Src IP      | Dst IP          | Dst Port | Bytes Out | Bytes In  | Duration
---------------------|-------------|-----------------|----------|-----------|-----------|----------
2026-01-28 09:15:22  | 10.1.5.47   | 13.107.42.14    | 443      | 2,340     | 45,230    | 3.2s
2026-01-28 09:15:45  | 10.1.5.47   | 52.96.166.130   | 443      | 5,120     | 128,450   | 8.1s
2026-01-28 09:22:18  | 10.1.5.47   | 185.243.115.42  | 443      | 1,024     | 512       | 0.4s
2026-01-28 09:22:19  | 10.1.5.47   | 185.243.115.42  | 443      | 45,670    | 1,024     | 12.3s
2026-01-28 09:35:02  | 10.1.5.47   | 185.243.115.42  | 443      | 89,340    | 1,024     | 24.1s
2026-01-28 09:48:33  | 10.1.5.47   | 185.243.115.42  | 443      | 156,200   | 1,024     | 41.2s
2026-01-28 10:01:15  | 10.1.5.47   | 40.126.28.11    | 443      | 3,400     | 67,800    | 5.5s
2026-01-28 10:15:44  | 10.1.5.47   | 185.243.115.42  | 443      | 203,450   | 1,024     | 53.8s

For context: 13.107.x.x and 52.96.x.x are Microsoft IP ranges. 40.126.x.x is Azure AD. The 185.243.115.42 address is hosted by a VPS provider in Eastern Europe.

Looking at the traffic pattern to 185.243.115.42, what specifically about the bytes in/out ratio concerns you? What type of activity does this pattern typically indicate?

What additional information would you want to gather to continue your investigation? Select all that apply.

Based on what you see, what's your initial classification of this traffic?

Your manager asks: "Should we isolate this workstation now or wait until we have more information?"

What's your recommendation and why? Consider the trade-offs between containing a potential threat and disrupting business operations based on incomplete information.

Packet Capture Analysis

You captured some traffic from a host that's been flagged by EDR. Here's a decoded excerpt showing DNS queries:

Frame 1: DNS Query
  Source: 10.1.5.102
  Destination: 10.1.1.10 (Internal DNS)
  Query: aGVsbG8gd29ybGQ.data.update-srv.net (Type A)
  
Frame 2: DNS Response  
  Source: 10.1.1.10
  Destination: 10.1.5.102
  Answer: 192.0.2.1 (TTL: 60)

Frame 3: DNS Query
  Source: 10.1.5.102
  Destination: 10.1.1.10
  Query: dGhpcyBpcyBhIHRlc3Q.data.update-srv.net (Type A)

Frame 4: DNS Response
  Source: 10.1.1.10  
  Destination: 10.1.5.102
  Answer: 192.0.2.1 (TTL: 60)

Frame 5: DNS Query
  Source: 10.1.5.102
  Destination: 10.1.1.10
  Query: c2VjcmV0IGRhdGE.data.update-srv.net (Type A)

[Pattern continues with similar queries every 30 seconds]

The subdomain portions (aGVsbG8gd29ybGQ, dGhpcyBpcyBhIHRlc3Q, c2VjcmV0IGRhdGE) look like encoded data. What encoding is this, and what do these three strings decode to?

What technique is being demonstrated in this packet capture?

Explain how this technique works in your own words. Include:

  • Why an attacker would use DNS for this purpose
  • What the 30-second interval might indicate
  • What network controls could detect or prevent this

The Noisy Neighbor

Operations complains that the network has been slow. You run a capture on the core switch and notice one host generating unusual traffic:

Top Talkers (Last 5 Minutes):
Source IP     | Packets | Bytes      | Unique Destinations
--------------|---------|------------|--------------------
10.1.3.25     | 847,203 | 42,360,150 | 23,847
10.1.5.47     | 12,450  | 8,234,500  | 45
10.1.2.100    | 8,320   | 5,120,000  | 12
10.1.4.15     | 5,670   | 2,340,000  | 8

Traffic Sample from 10.1.3.25:
Dst IP        | Dst Port | Count | Status
--------------|----------|-------|--------
10.1.3.1      | 445      | 3     | RST
10.1.3.2      | 445      | 3     | RST  
10.1.3.3      | 445      | 3     | RST
10.1.3.4      | 445      | 3     | SYN-ACK
10.1.3.5      | 445      | 3     | RST
10.1.3.6      | 445      | 3     | RST
10.1.3.7      | 445      | 3     | RST
10.1.3.8      | 445      | 3     | RST
...
[Pattern continues sequentially through 10.1.3.0/24, 10.1.4.0/24, etc.]

10.1.3.25 is registered as a workstation in Engineering.

What is host 10.1.3.25 doing?

The traffic shows mostly RST (reset) responses with occasional SYN-ACK. What does this pattern tell you about what the scanning host is finding?

This could be an authorized vulnerability scan, a compromised host, or something else entirely. Describe the steps you would take to determine which it is before taking containment action. Be specific about what you'd check and in what order.

Documentation

Your manager wants you to document one of the issues you found for the incident tracking system.

Which finding from your investigation warrants the highest priority response?

Write a brief incident summary for the finding you selected above. Include:

  • What you observed
  • Why it's significant
  • Recommended immediate actions
  • Suggested follow-up investigation steps

This challenge has closed, so no points are awarded. You can still work through it and keep your response.

Subscribe to the Newsletter

Get updates for new articles and resource updates delivered right to your inbox.