WGU C844 GRP 1 TASK 1 | ANALYSIS /RECOMMENDATION OF
SECURITY INVESTIGATION | LATEST UPDATE WITH COMPLETE
SOLUTIONS
Analysis/Recommendation of Security Investigation
Conducted by Michael Votaw
Date: April 17, 2024
A – NMAP/Zenmap scans
We received reports of network anomalies and began investigating. The reported host
was coming from the 10.168.27.0/24 network.
Our initial scan discovered 6 hosts. The summary of hosts discovered
1. 10.168.27.1 – No clear information – suspect it’s the default gateway for the
subnet.
2. 10.168.27.10 – With a 98% certainty, it’s a Windows Server 2012R2 – Hosted on
our VMware environment. The host is likely serving as a domain controller.
3. 10.168.27.14 – The host appears to be running a Linux OS with SSH open, as well
as an application on TCP/9090. This port is common to about a dozen
applications.
4. 10.168.27.15—It is highly likely to be a Windows 8.1 Pro workstation running an
open copy of Windows IIS on port TCP/80.
5. 10.168.27.20 – Another Linux OS that is listening on SSH (22/TCP) with no other
ports.
,6. 10.168.27.132 – Most likely Linux OS. Looks very similar to 10.168.27.14 also
listening on 9090/TCP and no other
, Summary for 10.168.27.1 – Likely a switch/router serving as the DG for subnet
Summary for 10.168.27.10 – Most likely a Windows 2012R2 server running Active
Directory
SECURITY INVESTIGATION | LATEST UPDATE WITH COMPLETE
SOLUTIONS
Analysis/Recommendation of Security Investigation
Conducted by Michael Votaw
Date: April 17, 2024
A – NMAP/Zenmap scans
We received reports of network anomalies and began investigating. The reported host
was coming from the 10.168.27.0/24 network.
Our initial scan discovered 6 hosts. The summary of hosts discovered
1. 10.168.27.1 – No clear information – suspect it’s the default gateway for the
subnet.
2. 10.168.27.10 – With a 98% certainty, it’s a Windows Server 2012R2 – Hosted on
our VMware environment. The host is likely serving as a domain controller.
3. 10.168.27.14 – The host appears to be running a Linux OS with SSH open, as well
as an application on TCP/9090. This port is common to about a dozen
applications.
4. 10.168.27.15—It is highly likely to be a Windows 8.1 Pro workstation running an
open copy of Windows IIS on port TCP/80.
5. 10.168.27.20 – Another Linux OS that is listening on SSH (22/TCP) with no other
ports.
,6. 10.168.27.132 – Most likely Linux OS. Looks very similar to 10.168.27.14 also
listening on 9090/TCP and no other
, Summary for 10.168.27.1 – Likely a switch/router serving as the DG for subnet
Summary for 10.168.27.10 – Most likely a Windows 2012R2 server running Active
Directory