Peak traffic exceeds your inline IPS pair's inspection capacity — which budget do you surrender first, and what does an intruder gain?
answer
- four outcomes, one of them a decision
- rank traffic by payload value
- depth before breadth, never blanket bypass
- peaks are on the business calendar
- degraded minutes are a capacity signal
basics
~20 sDecide the degradation order in advance rather than letting the box choose. Surrender depth on low-value bulk paths before breadth, never fall into blanket bypass unannounced, and alert on entering degraded mode — because an intruder can time a transfer to your predictable peaks.
solid answer
~50 sThe dangerous answer is the default one: at saturation an inline pair either drops traffic, which is an outage the business will not tolerate, or falls into bypass and forwards everything uninspected, which is a security hole nobody declared. Both are the box choosing for you. A defensible design chooses first: rank traffic by payload value, and shed inspection depth on the classes where volume is large and content value is low — bulk replication, backup, machine-to-machine — before touching egress paths carrying customer data. Make the shed measurable: a mode-change alert, the truncated-stream and offloaded-byte counters as first-class telemetry, and a record of which classes were degraded and for how long. Then treat degraded minutes as a capacity signal, not a steady state. The intruder gain is timing: peaks are predictable from the business calendar and often visible as added latency from outside, so a patient operator moves staged data during your busiest window.
go deeper
Know that an inline inspection device under overload either delays traffic or passes it uninspected, and that neither happens silently by good luck.
Explain the four possible outcomes at saturation and why adaptive shedding hides what it gave up unless the counters are being read.
Demonstrate a declared degradation order ranked by payload value, the telemetry that makes it visible, and the adversary timing risk it creates.
Own the argument that sustained degradation is a sizing verdict, with counters as the evidence for the capacity line and a named owner for the residual risk.
## Something always gives An inline inspection pair sized for a rated throughput will meet a peak it cannot inspect at full depth. When it does, exactly one of four things happens, and only one of them is a decision. 1. **Fail-closed.** Queue and then drop. Latency climbs, sessions fail, the business notices within minutes. Security is intact and the phone rings. 2. **Fail-open bypass.** The pair relays traffic around the inspection path — sometimes in hardware, sometimes as a software decision — and every packet passes uninspected with no verdict at all. Nobody notices unless somebody built the alert. 3. **Adaptive shedding.** The engine reduces its own work: shorter reassembly depth, more aggressive offload, protocol analysers disabled, some rule classes dropped. Inspection continues in a diminished form, usually without a clear record of what was diminished. 4. **Declared degradation.** You decided beforehand what to give up, in what order, with what telemetry. This is the only one of the four that is engineering. The first three are what happens by default depending on the platform's configuration; the interview question is really whether the candidate knows a fourth option exists. ## The order to shed in Rank by payload value against volume, not by convenience: | Traffic class | Shed early? | Reasoning | |---|---|---| | Bulk replication, backup, image distribution | Yes | Enormous volume, low content value, and the class filling the box | | Internal interactive, machine-to-machine within a zone | Partially | Reduce depth before removing analysers | | Egress to the internet, tenant data paths | Last | This is where a staged transfer leaves; losing depth here loses the point of the control | Degrading **depth** on a class is usually better than degrading **breadth** across everything, because a shorter prefix on bulk paths still keeps protocol analysis and header-level enforcement everywhere. Blanket bypass is the worst outcome available and should require an explicit decision, not a threshold. ## What the intruder gets Degradation windows are predictable and, worse, observable. - **The business calendar leaks them.** Backup windows, batch runs, month-end, a marketing event. An operator who has been resident for weeks knows the estate's rhythm as well as its owner does. - **Latency is a side channel.** Response time through an inspection path changes measurably when the path degrades or bypasses. A patient adversary can probe for that from outside with ordinary traffic. - **The shed classes are the exfiltration path.** If bulk replication is what you shed, and bulk replication is also where a staged transfer hides, the shedding policy has told the adversary where to put the data. That last one is the trap in the obvious design, and naming it is what separates a senior answer from a plausible one. The mitigation is not to stop shedding — you must shed something — but to make sure the class you shed is not the class that carries value outward, and to keep volumetric analysis alive on shed traffic even when content inspection is gone. ## Instrumentation that makes it honest - **Mode transitions are events.** Entering and leaving degraded or bypass mode should generate an alert with a duration, not a graph nobody watches. - **Counters as coverage, not statistics.** Truncated streams, offloaded bytes, bypassed bytes and dropped packets are the numerator of your coverage claim. Trend them and report them. - **Correlate gaps with detections.** A quiet hour during a degraded window is not evidence of a quiet estate; the absence of a detection proves nothing about the traffic that passed uninspected. - **Bound the state.** Degraded mode with a declared duration and a written trigger for capacity purchase is defensible. Degraded mode as the permanent operating point is an unfunded risk pretending to be a configuration. ## The boundary worth stating This is a configured behaviour of an engine that received the traffic and decided what to do with it under load. It is a different failure from traffic that never arrived at the sensor at all — and in a post-incident review the two get conflated, which lets everyone conclude the wrong fix. Say which one you are describing. Finally, the honest close: sustained degradation is a sizing verdict. Every quarter spent in it is evidence for a capacity line, and the counters are the evidence. Engineering can choose the order; it cannot choose to have enough capacity it was not given.
- How would an intruder outside your network learn that the inspection path is degraded?Two ways, neither requiring access. Business rhythm is public or inferable — backup windows, batch cycles, month-end, a launch — and an operator already resident has watched it. And the path itself leaks: response latency through an inspection pair changes when depth is reduced or when the pair bypasses, so ordinary probe traffic can time it. Assume the window is discoverable and design as if it is announced.
- Your platform enters hardware bypass at overload and nobody noticed for a month. What is the first fix?Make the mode change an alert with a duration, before touching capacity. Bypassed bytes then become a measurable number rather than an unknown, and you can state what share of traffic passed with no verdict. Then re-scope: bypass should be the last resort behind a declared shedding order, not the first thing that happens at a threshold. Capacity is the third step and needs the counters to justify it.
- Is shedding inspection on bulk replication traffic safe, given that is also where large transfers hide?It is the least-bad shed, not a safe one, and the risk has to be closed elsewhere. Keep volumetric analysis alive on the shed class so an abnormal direction, destination or volume is still a question, and refuse to shed on the egress paths that leave the estate. If the shed class is also an egress path, it is the wrong class to shed and the choice must move.
saying these in an interview costs you the question
- Treating fail-open bypass as an acceptable default posture
- Assuming a quiet degraded window means nothing happened
- Shedding inspection on the same path data leaves by
- Calling sustained degraded mode a tuning problem, not a sizing one
- Confusing engine overload with traffic that never reached the sensor