Take one lab VM from default install to defended, and measure every step
Task
Pull Domain 2 together on a single machine: establish what it exposes, what an attacker would find, what evidence each weakness leaves, and then close them in the order that matters -- measuring the change after each one so the work is evidence rather than assertion.
Steps
- Revert the Linux guest to the
cleansnapshot, so the starting measurement is a real default install rather than the result of earlier labs. - Baseline from the Windows guest: test a fixed list of ports against 10.99.0.10 with
Test-NetConnection -Port-- 21, 22, 23, 25, 53, 80, 111, 139, 443, 445, 631, 3306, 5432 and 8080 -- and count the ones that answer. Every address here is a VM you built on the lab network you own. - Baseline on the Linux guest itself: listening sockets, enabled services, accounts with a login shell, sudo rights, password policy, and whether the host firewall is active. Record them in
/tmp/host-before.txt, and start/tmp/progress.csvwith the headerstep,open_ports,enabled_services,shell_accounts,sudoers,detectionsand a first row for the baseline, whereopen_portsis the count the Windows guest could reach anddetectionsis 0 because nothing is watching yet. - Generate evidence of three of this domain's indicators, using only accounts you created: a spray of one wrong password across several usernames and a burst of wrong passwords against one, both from the Windows guest's SSH client; and a beacon -- a loop on the Linux guest requesting a listener you started on 127.0.0.1 every thirty seconds, as in the malware lab. Collect the resulting log lines.
- Now mitigate, ONE control at a time, in this order: default credentials and unused accounts; unnecessary services and ports; host firewall default-deny with SSH allowed only from the lab subnet; least privilege on sudo; and finally
/tmp/monitor.sh, which reads the auth log and the listener's access log, prints one line per indicator it recognises, and ends withdetections: N. - After each control, re-measure from both sides and append a row to
/tmp/progress.csv. - Re-generate the three indicators and confirm your monitoring now reports all three, where at the start it reported none.
- Write
/tmp/capstone.md: the before and after figures, which single control produced the largest reduction, which had no effect, and which mitigation you would do in the first hour if an hour was all you had.
Verify
bash /tmp/monitor.sh | tail -1
python3 - <<'PY'
import csv
rows=list(csv.DictReader(open('/tmp/progress.csv')))
assert len(rows)>=6, 'fewer than a baseline and five measured steps'
first,last=rows[0],rows[-1]
for k in ('open_ports','enabled_services','sudoers'):
b,a=int(first[k]),int(last[k])
print('%-18s %s -> %s' % (k,b,a))
assert a<=b, k+' increased'
assert int(last['open_ports'])<int(first['open_ports']), 'no ports were closed'
assert int(last['detections'])>=3, 'monitoring does not catch all three indicators'
assert int(first['detections'])==0, 'the baseline already detected something - re-measure from clean'
print('hardening measured across', len(rows), 'rows')
PY
grep -icE "largest reduction|no effect|first hour" /tmp/capstone.md
The assertions are the whole capstone. Ports reachable from the other guest must genuinely have closed; detections must go from zero at the baseline to at least three at the end; and nothing may have increased along the way. A run where detections starts non-zero means the baseline was not taken from the clean snapshot, which makes every later comparison meaningless. The grep must report three lines, one for each question in the write-up.
Notes
The question in the last step -- which single mitigation you would do first with an hour -- is the one worth having an answer to. It is the question a real organisation asks, the exam asks it as 'what is the BEST first step', and after this exercise you will have a number behind your answer rather than an opinion.
This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.