Cyber Patriot 18 CP-18 Introductory Round / Round 2 Windows 11 Answer Key

Nov 29, 2025    #cyberpatriot   #scoring   #cyberpatriot18   #high-school   #middle-school  

Summary

Forensics Questions

Question 1

File Path: C:\Users\benjamin\Desktop\Forensics Question 1.txt

Content:

An external network scan identified an unauthorized web server running on this
machine and management has asked you to investigate it. The typical file path
for the web server files is C:\inetpub\wwwroot\, however, that directory is
empty.
What is the absolute file path of the configured root directory for the web
server?
( HINT: You can use inetmgr to view the web server configuration. )
( EXAMPLE: C:\Windows\System32\ )
ANSWER: <Type Answer Here>

Question 2

File Path: C:\Users\benjamin\Desktop\Forensics Question 2.txt

Content:

Remote Desktop access is determined by the local or domain security policy
called "Allow log on through Remote Desktop Services." This setting defines
which groups or users are permitted to connect using Remote Desktop Protocol.
By default, this policy usually includes two groups: Administrators and Remote
Desktop Users. However, additional groups or individual accounts can be added
manually through Group Policy or local security settings.
To find out who actually has RDP access, it is not enough to just look at the
Remote Desktop Users group. You must enumerate all users and nested groups
within the above permission to see who effectively can log in via RDP.
Based on the above information, please list all user accounts that can log in
via Remote Desktop Protocol (RDP) on this machine.
( HINT: The Administrators group does NOT currently have the permission. )
( HINT: You will NOT gain any points for removing anyone's RDP permission
as RDP is not a critical service and should be disabled. )
( EXAMPLE: Guest )
ANSWER: <Type Answer Here>
ANSWER: <Type Answer Here>
ANSWER: <Type Answer Here>
ANSWER: <Type Answer Here>
ANSWER: <Type Answer Here>

Category: Account policy (F) (ACT)

✅ Passwords are not stored using reversible encryption +4

Specific Conditions:

ID: REV

✅ A secure account lockout duration exists +4

Specific Conditions:

ID: DUR

Category: Application update (F) (AUP)

✅ 7-Zip has been updated +5

Specific Conditions:

ID: 7ZIP

✅ LibreOffice has been updated +5

Specific Conditions:

ID: LOFF

Category: Defensive countermeasure (F) (DEF)

✅ Firewall protection has been enabled +5

Specific Conditions:

ID: FWALL

Category: Prohibited file (F) (FIL)

✅ Removed prohibited MP3 files +4

Specific Conditions:

ID: MP3

Category: Forensic Question (F) (FOR)

✅ Forensics Question 1 correct +10

Specific Conditions:

ID: Q1

✅ Forensics Question 2 correct +10

Specific Conditions:

ID: Q2

Category: Malware (F) (MAL)

✅ Removed Tini backdoor +6

Specific Conditions:

ID: TINI

Category: Penalty (F) (PEN)

➖ WARNING: VirtualBox is unsupported 0

Specific Conditions:

ID: VBX

❌ Account lockout threshold less than 5 is deprecated -3

Specific Conditions:

ID: LOCK

❌ Google Chrome is not installed at the default location -5

Specific Conditions:

ID: SFT_GCHR

❌ Notepad++ is not installed at the default location -5

Specific Conditions:

ID: SFT_NPP

❌ 7-Zip is not installed at the default location -5

Specific Conditions:

ID: SFT_7ZIP

❌ Removed one or more authorized administrators -5

Specific Conditions:

ID: USRA

❌ Removed one or more authorized users -5

Specific Conditions:

ID: USRS

❌ Removed one or more authorized user directories -5

Specific Conditions:

ID: USRD

Category: Local policy (F) (POL)

✅ Do not require CTRL+ALT+DEL [disabled] +5

Specific Conditions:

ID: IL_CAD

❌ Performed an unspecified action on the registry -2

Specific Conditions:

ID: GAZZR

❌ Performed an unspecified action on the registry -2

Specific Conditions:

ID: KQGUS

❌ Performed an unspecified action on the registry -2

Specific Conditions:

ID: PVVDF

❌ Performed an unspecified action on the registry -2

Specific Conditions:

ID: GCQBY

❌ Performed an unspecified action on the registry -2

Specific Conditions:

ID: WLBEM

❌ Performed an unspecified action on the registry -2

Specific Conditions:

ID: UMZEQ

❌ Performed an unspecified action on the registry -2

Specific Conditions:

ID: WFJET

❌ Performed an unspecified action on the registry -2

Specific Conditions:

ID: ZOXED

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: TXUYV

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: ARNZQ

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: NICRY

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: BCIAA

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: EMHCA

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: HYIJE

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: UICUM

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: LHVEJ

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: JPEXO

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: AAFMG

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: STMNG

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: BKTQL

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: YVRMJ

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: SPSCZ

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: XPUVT

❌ Performed an unspecified action on the registry -3

Specific Conditions:

ID: ICFQF

❌ Performed an unspecified action on the registry -4

Specific Conditions:

ID: UMWTI

❌ Performed an unspecified action on the registry -4

Specific Conditions:

ID: QIRDZ

❌ Performed an unspecified action on the registry -4

Specific Conditions:

ID: CLJUI

❌ Performed an unspecified action on the registry -4

Specific Conditions:

ID: HMYMN

❌ Performed an unspecified action on the registry -4

Specific Conditions:

ID: VUXMC

❌ Performed an unspecified action on the registry -4

Specific Conditions:

ID: UHOEM

❌ Performed an unspecified action on the registry -4

Specific Conditions:

ID: GSGZW

❌ Performed an unspecified action on the registry -4

Specific Conditions:

ID: VLUYI

❌ Performed an unspecified action on the registry -4

Specific Conditions:

ID: WUEBI

❌ Performed an unspecified action on the registry -4

Specific Conditions:

ID: VRMKX

❌ Performed an unspecified action on the registry -4

Specific Conditions:

ID: LSIEF

❌ Performed an unspecified action on the registry -4

Specific Conditions:

ID: SVWZG

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: YCHHB

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: HMFBT

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: MVRUA

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: QDNMA

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: OQMND

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: BFPQN

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: INCBM

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: HOCKL

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: HDOZQ

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: PPNFC

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: RODGC

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: UNORP

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: LHMJT

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: WUKEQ

❌ Performed an unspecified action on the registry -5

Specific Conditions:

ID: AJZVR

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: QRQVD

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: CJRXK

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: ENCKZ

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: OVWKO

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: UJLNM

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: ONUXU

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: YFFRI

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: NJJAA

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: QCDPS

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: JSCBW

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: FWTHE

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: EQJOS

❌ Performed an unspecified action on the registry -6

Specific Conditions:

ID: MFTGD

Category: Penalty (F) (SCR)

❌ Removed multiple authorized users -6

Specific Conditions:

ID: SCRU

❌ Removed multiple authorized user directories -6

Specific Conditions:

ID: SCRD

Category: Unwanted software (F) (SFT)

✅ Removed TicTacToe +4

Specific Conditions:

ID: TICTAC

✅ Removed Cursor +4

Specific Conditions:

ID: CURSOR

❌ Performed an unspecified action on the filesystem -2

Specific Conditions:

ID: FNOI

❌ Performed an unspecified action on the filesystem -2

Specific Conditions:

ID: FQLN

❌ Performed an unspecified action on the filesystem -2

Specific Conditions:

ID: NXGP

❌ Performed an unspecified action on the filesystem -2

Specific Conditions:

ID: USGY

❌ Performed an unspecified action on the filesystem -2

Specific Conditions:

ID: AXCU

❌ Performed an unspecified action on the filesystem -2

Specific Conditions:

ID: GWOZ

❌ Performed an unspecified action on the filesystem -2

Specific Conditions:

ID: SAIP

❌ Performed an unspecified action on the filesystem -2

Specific Conditions:

ID: WRSZ

❌ Performed an unspecified action on the filesystem -2

Specific Conditions:

ID: KEPB

❌ Performed an unspecified action on the filesystem -2

Specific Conditions:

ID: YICB

❌ Performed an unspecified action on the filesystem -3

Specific Conditions:

ID: UOOV

❌ Performed an unspecified action on the filesystem -3

Specific Conditions:

ID: TBKV

❌ Performed an unspecified action on the filesystem -3

Specific Conditions:

ID: SRAU

❌ Performed an unspecified action on the filesystem -3

Specific Conditions:

ID: WARS

❌ Performed an unspecified action on the filesystem -3

Specific Conditions:

ID: HMJA

❌ Performed an unspecified action on the filesystem -3

Specific Conditions:

ID: CQYY

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: CFDV

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: JCGH

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: QGRC

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: KMMG

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: GSGP

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: QQHH

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: WWLW

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: JEFS

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: MOTK

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: FOPU

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: NWGT

❌ Performed an unspecified action on the filesystem -4

Specific Conditions:

ID: VVWL

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: UYTR

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: XHIN

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: GKEU

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: YQNB

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: ZNWP

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: QQAK

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: BVDU

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: WJMM

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: LAFU

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: IEAK

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: MFPF

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: RAMX

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: XYZM

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: SXYV

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: RTJV

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: GFSG

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: XEPJ

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: GEOT

❌ Performed an unspecified action on the filesystem -5

Specific Conditions:

ID: ZTLH

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: TLXN

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: FNPG

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: YXHX

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: WGRJ

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: TKFR

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: HKND

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: AZNL

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: SMKF

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: XWEE

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: HFZK

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: VFES

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: VLPW

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: OHUK

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: PBUJ

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: XYWB

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: RPTB

❌ Performed an unspecified action on the filesystem -6

Specific Conditions:

ID: GTAQ

Category: Service auditing (F) (SRV)

✅ World Wide Web Publishing service has been stopped and disabled +5

Specific Conditions:

ID: W3PUB

Category: Uncategorized operating system setting (F) (SYS)

✅ Remote desktop sharing is turned off +5

Specific Conditions:

ID: RDSK

Category: User auditing (F) (USR)

✅ Removed unauthorized user aholt +4

Specific Conditions:

ID: AHOL

✅ Removed unauthorized user jquelling +4

Specific Conditions:

ID: JQUE

✅ User dscott is not an administrator +4

Specific Conditions:

ID: DSCO

✅ User shuntley is not an administrator +4

Specific Conditions:

ID: SHUN

✅ Changed insecure password for user llitt +4

Specific Conditions:

ID: LLIT

✅ User sbandaru has a password +4

Specific Conditions:

ID: SBAN