Cyber Patriot 18 CP-18 Round 2 Server 2022 Answer Key

Nov 29, 2025    #cyberpatriot   #scoring   #cyberpatriot18   #high-school  

Summary

Forensics Questions

Question 1

File Path: C:\Users\benjamin\Desktop\Forensics Question 1.txt

Content:

A user reported a file will be accessable via the authorized SMB share that
may leak credentials. Management has asked you to find and remove this file
before creating the authorized SMB share.
What is the leaked password of the user "mross" according to this file?
( EXAMPLE: Password123! )
ANSWER: <Type Answer Here>

Question 2

File Path: C:\Users\benjamin\Desktop\Forensics Question 2.txt

Content:

During a recent audit, it was discovered that there is an open SMB share on
this machine. However, none should have been created just yet.
What user is responsible for creating the unauthorized SMB share?
( EXAMPLE: Guest )
ANSWER: <Type Answer Here>

Question 3

File Path: C:\Users\benjamin\Desktop\Forensics Question 3.txt

Content:

Management captured wireshark traffic of an attempted FTP brute force attack.
The pcap file is located on your desktop.
What is the username and password of the user that successfully logged in
during the attack?
( EXAMPLE: anonymous )
( EXAMPLE: Password123! )
ANSWER: <Type Answer Here>
ANSWER: <Type Answer Here>

Category: Account policy (F) (ACT)

✅ A secure minimum password length is required +2

Specific Conditions:

ID: MINL

✅ A secure lockout threshold exists +2

Specific Conditions:

ID: THR

Category: Application security (F) (APP)

✅ Exec SMB share permissions have been correctly configured +5

Specific Conditions:

ID: SMB_EXEC_PERM

✅ SMB 1.x removed or disabled +5

Specific Conditions:

ID: SMB_NOV1

Category: Application update (F) (AUP)

✅ Notepad++ has been updated +3

Specific Conditions:

ID: NTPP

✅ Wireshark has been updated +3

Specific Conditions:

ID: WRSHRK

Category: Prohibited file (F) (FIL)

✅ Removed plain text file with passwords in it +4

Specific Conditions:

ID: PWRD

Category: Forensic Question (F) (FOR)

✅ Forensics Question 1 correct +7

Specific Conditions:

ID: Q1

✅ Forensics Question 2 correct +7

Specific Conditions:

ID: Q2

✅ Forensics Question 3 correct +7

Specific Conditions:

ID: Q3

Category: Malware (F) (MAL)

✅ Removed netcat backdoor +5

Specific Conditions:

ID: NCAT

Category: Operating system update (F) (OUP)

✅ Windows automatically checks for updates +3

Specific Conditions:

ID: AUTO_10

Category: Penalty (F) (PEN)

➖ WARNING: VirtualBox is unsupported 0

Specific Conditions:

ID: VBX

❌ Account lockout threshold less than 5 is deprecated -3

Specific Conditions:

ID: LOCK

❌ Remote Desktop is disabled -5

Specific Conditions:

ID: RDSK

❌ SMB client service (v2/v3) disabled -5

Specific Conditions:

ID: SRV_SMBC

❌ Google Chrome is not installed at the default location -5

Specific Conditions:

ID: SFT_GCHR

❌ Notepad++ is not installed at the default location -5

Specific Conditions:

ID: SFT_NPP

❌ 7-Zip is not installed at the default location -5

Specific Conditions:

ID: SFT_7ZIP

❌ Wireshark is not installed at the default location -5

Specific Conditions:

ID: SFT_WRSH

❌ Critical business file(s) deleted from SMB share -5

Specific Conditions:

ID: FIL_SMB

❌ Removed one or more authorized administrators -5

Specific Conditions:

ID: USRA

❌ Removed one or more authorized users -5

Specific Conditions:

ID: USRS

❌ Removed one or more authorized user directories -5

Specific Conditions:

ID: USRD

Category: Local policy (F) (POL)

✅ Everyone may not access this computer from the network +3

Specific Conditions:

ID: SE_NLR

✅ Limit local use of blank passwords to console only [enabled] +3

Specific Conditions:

ID: AC_LBPU

✅ Microsoft network server: Digitally sign communications (always) [enabled] +3

Specific Conditions:

ID: MNS_RSIG

✅ Audit File Share [Success] +2

Specific Conditions:

ID: AU_FSS

❌ Performed an unspecified action on the registry -2

Specific Conditions:

ID: CXCCF

❌ Performed an unspecified action on the registry -2

Specific Conditions:

ID: JQKYF

❌ Performed an unspecified action on the registry -2

Specific Conditions:

ID: FZKAL

❌ Performed an unspecified action on the registry -2

Specific Conditions:

ID: LVPVB

❌ Performed an unspecified action on the registry -2

Specific Conditions:

ID: QERBA

❌ Performed an unspecified action on the registry -2

Specific Conditions:

ID: UICDG

❌ Performed an unspecified action on the registry -2

Specific Conditions:

ID: FHYKR

❌ Performed an unspecified action on the registry -2

Specific Conditions:

ID: DSWPX

❌ Performed an unspecified action on the registry -2

Specific Conditions:

ID: RZTRS

❌ Performed an unspecified action on the registry -2

Specific Conditions:

ID: CJXUI

❌ Performed an unspecified action on the registry -2

Specific Conditions:

ID: FOVCE

❌ Performed an unspecified action on the registry -2

Specific Conditions:

ID: OTZQI

❌ Performed an unspecified action on the registry -2

Specific Conditions:

ID: JLKLV

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: TFULU

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: RHSQU

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: EBNWL

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: ZVRDD

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: EVYGZ

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: FOFDN

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: EBEHA

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: QHQSQ

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: NJBXY

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: OIWMI

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: XNZOA

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: NSRPX

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: JHRGB

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: GRGGH

❌ Performed an unspecified action on the registry -4

Specific Conditions:

ID: SQXML

❌ Performed an unspecified action on the registry -4

Specific Conditions:

ID: OFDLN

❌ Performed an unspecified action on the registry -4

Specific Conditions:

ID: MCZDD

❌ Performed an unspecified action on the registry -4

Specific Conditions:

ID: SOIOO

❌ Performed an unspecified action on the registry -4

Specific Conditions:

ID: MMMGP

❌ Performed an unspecified action on the registry -4

Specific Conditions:

ID: TMGHZ

❌ Performed an unspecified action on the registry -4

Specific Conditions:

ID: HNXKB

❌ Performed an unspecified action on the registry -4

Specific Conditions:

ID: QCEIY

❌ Performed an unspecified action on the registry -4

Specific Conditions:

ID: HOEKV

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: KDJJA

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: BMPTF

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: QBMUY

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: GSMRN

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: EYNYC

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: LUCER

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: HBTKK

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: PQWFA

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: QHYWI

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: MWGYI

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: GEVNA

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: XTNRC

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: SLRPW

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: ZSGDC

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: HHYLY

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: KUHVS

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: LQECI

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: NGXHU

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: ZLCFN

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: DIDXS

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: TLPJQ

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: MVQSG

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: OUOVI

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: LMUMA

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: IQQZJ

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: ODPXZ

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: PDEOH

Category: Penalty (F) (SCR)

❌ Removed multiple authorized user directories -2

Specific Conditions:

ID: SCRD

❌ Removed multiple authorized users -3

Specific Conditions:

ID: SCRU

Category: Unwanted software (F) (SFT)

✅ Removed TightVNC Server +5

Specific Conditions:

ID: TIVNC

❌ Performed an unspecified action on the filesystem -2

Specific Conditions:

ID: JLDW

❌ Performed an unspecified action on the filesystem -2

Specific Conditions:

ID: SSED

❌ Performed an unspecified action on the filesystem -2

Specific Conditions:

ID: DENF

❌ Performed an unspecified action on the filesystem -2

Specific Conditions:

ID: OKCO

❌ Performed an unspecified action on the filesystem -2

Specific Conditions:

ID: MKWA

❌ Performed an unspecified action on the filesystem -2

Specific Conditions:

ID: QZUN

❌ Performed an unspecified action on the filesystem -2

Specific Conditions:

ID: BLQF

❌ Performed an unspecified action on the filesystem -2

Specific Conditions:

ID: MPGI

❌ Performed an unspecified action on the filesystem -2

Specific Conditions:

ID: XEFN

❌ Performed an unspecified action on the filesystem -2

Specific Conditions:

ID: YVRS

❌ Performed an unspecified action on the filesystem -2

Specific Conditions:

ID: SCEA

❌ Performed an unspecified action on the filesystem -3

Specific Conditions:

ID: OFXQ

❌ Performed an unspecified action on the filesystem -3

Specific Conditions:

ID: TVFH

❌ Performed an unspecified action on the filesystem -3

Specific Conditions:

ID: QYDZ

❌ Performed an unspecified action on the filesystem -3

Specific Conditions:

ID: ZRKV

❌ Performed an unspecified action on the filesystem -3

Specific Conditions:

ID: DXRN

❌ Performed an unspecified action on the filesystem -3

Specific Conditions:

ID: RZSF

❌ Performed an unspecified action on the filesystem -3

Specific Conditions:

ID: JQVK

❌ Performed an unspecified action on the filesystem -3

Specific Conditions:

ID: QZCO

❌ Performed an unspecified action on the filesystem -3

Specific Conditions:

ID: ZLMN

❌ Performed an unspecified action on the filesystem -3

Specific Conditions:

ID: KGBB

❌ Performed an unspecified action on the filesystem -3

Specific Conditions:

ID: XZRW

❌ Performed an unspecified action on the filesystem -3

Specific Conditions:

ID: WYBG

❌ Performed an unspecified action on the filesystem -3

Specific Conditions:

ID: GKFH

❌ Performed an unspecified action on the filesystem -3

Specific Conditions:

ID: UJII

❌ Performed an unspecified action on the filesystem -3

Specific Conditions:

ID: NXWB

❌ Performed an unspecified action on the filesystem -3

Specific Conditions:

ID: VFOK

❌ Performed an unspecified action on the filesystem -3

Specific Conditions:

ID: JJWB

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: PYJH

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: EMWB

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: BLUA

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: IWAW

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: WNUO

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: KMKE

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: JXQM

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: MIFC

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: WOPC

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: PNZL

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: DTKZ

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: BQMX

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: ZZNJ

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: DOGP

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: CTQU

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: USKD

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: JPRN

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: XFQZ

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: VMJV

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: IAAQ

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: EZUS

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: BBHV

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: DADW

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: VNKA

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: GYAT

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: GFBF

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: FCQY

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: BWDP

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: TXXT

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: UAUE

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: KGDP

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: NPQG

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: XYXO

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: ANAC

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: FRAI

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: DQEA

Category: Uncategorized operating system setting (F) (SYS)

✅ File sharing disabled for hidden share Private$ +4

Specific Conditions:

ID: SHHDN

✅ Created Executive SMB Share +4

Specific Conditions:

ID: SMB_EXEC

Category: User auditing (F) (USR)

✅ Created group Exec SMB Users +4

Specific Conditions:

ID: SMB_GRP1

✅ Added users to group Exec SMB Users +4

Specific Conditions:

ID: SMB_GRP2

✅ Removed unauthorized user ttanner +3

Specific Conditions:

ID: TTAN

✅ Removed unauthorized user tgianopolous +3

Specific Conditions:

ID: TGIA

✅ User kbennett is not an administrator +3

Specific Conditions:

ID: KBEN

✅ User rzane is not an administrator +3

Specific Conditions:

ID: RZAN

✅ Changed insecure password for user dscott +3

Specific Conditions:

ID: DSCO