Unit 3 — Securing Networks. You are working three independent case files this unit, each dropping you into a different network security role. Read each scenario carefully, work through the embedded evidence tables, and answer every question in your own words.
Your answers autosave to this browser as you type — nothing is transmitted anywhere. When you're finished, use Export My Case File to download a text file for submission.
Protecting Patient Medical Data
You are a network security engineer at Adams County Hospital. The hospital runs two critical systems: a public-facing web application that lets patients book appointments and pay bills, and an internal file server that stores patient medical records.
Administration has approved the purchase of two new firewalls. Your job is to determine where each firewall should sit in the network and how each protected server should be configured. Below is the current network segment inventory your team compiled during the site survey.
Evidence: Network Segment Inventory
Click a segment's firewall assignment to cycle through options: Unassigned → Firewall A (Perimeter) → Firewall B (Internal Segmentation) → Both Firewalls.
| Segment / Asset | Data Sensitivity | Current Exposure | Firewall Assignment |
|---|---|---|---|
| Patient Portal Web Server (booking & scheduling) | Low–Moderate (contact info, appointment data) | Internet-facing (DMZ) | — Unassigned —click to set |
| Bill Pay / Payment Processing Interface | High (cardholder data) | Internet-facing (DMZ) | — Unassigned —click to set |
| Internal Patient Records File Server (PHI) | Critical (protected health information) | Internal LAN only | — Unassigned —click to set |
| Staff Workstation Network | Moderate (staff credentials, EHR access) | Internal LAN only | — Unassigned —click to set |
| Guest / Patient Wi-Fi | Low (no hospital data access) | Internet-facing, physically inside building | — Unassigned —click to set |
Questions
Configuring a Secure Wireless Network
In the aftermath of a natural disaster, you've been called up as a network technician to set up a wireless network at the local high school gymnasium, now converted into an emergency shelter. A satellite uplink provides internet access. Displaced residents need connectivity to reach family and friends.
Your job is to configure the network so it's safe to use in a crowded, unvetted public setting — and to be able to detect malicious activity on a network you can't fully control who joins. Below is a snapshot of the device connection log from the first evening of operation.
Evidence: Device Connection Log
Click a row to flag it as suspicious. Flag every entry you believe warrants investigation.
| Timestamp | Device Name | MAC Address | Session Length | Data Transferred |
|---|---|---|---|---|
| 18:02:11 | Samsung-Galaxy-A14 | 3C:A6:F2:__:__:8B | 42 min | 18 MB |
| 18:07:44 | iPhone-Maria | A4:5E:60:__:__:2D | 1 hr 10 min | 64 MB |
| 18:15:02 | DESKTOP-UNKNOWN | 00:1A:2B:__:__:9F | 3 min | 2 MB |
| 19:30:55 | Android-Device-7F3A | 3C:A6:F2:__:__:8B | 4 hrs 20 min | 3 MB |
| 21:48:19 | unknown-device | DE:AD:BE:__:__:00 | 6 min | 4.2 GB |
| 22:10:03 | Kids-Tablet | 88:B1:11:__:__:C4 | 55 min | 210 MB |
| 02:14:37 | unknown-device | DE:AD:BE:__:__:01 | 11 min | 3.9 GB |
| 07:02:50 | Laptop-Guest12 | F0:99:B6:__:__:77 | 28 min | 15 MB |
Questions
Protecting a Network on a Naval Submarine
You manage three separate LANs aboard a naval submarine:
- A dedicated LAN for weapons systems
- A secure LAN for official naval operations
- A LAN for crew recreation
Each LAN carries a different level of risk if compromised, and each is used by a different mix of personnel. Your job is to recommend a security posture for each LAN and define exactly who should be able to reach what.
Evidence: LAN Access Control Matrix
Click a cell to cycle its access level: No Access → Monitored / Restricted → Full Access → No Access.
| LAN | Weapons Officer | Command Staff | General Crew | External / Internet Gateway |
|---|---|---|---|---|
| Weapons Systems LAN Fire control, targeting |
No Access | No Access | No Access | No Access |
| Official Operations LAN Navigation, comms, orders |
No Access | No Access | No Access | No Access |
| Crew Recreation LAN Entertainment, personal use |
No Access | No Access | No Access | No Access |