skip to content

A visitor left alone in a meeting room plugs into the live wall socket — what does that port hand them, and what does shutting unused ports cost?

level: juniorimportance: must knowfreq 62%

answer

  1. physical estate meets logical estate
  2. the switch cannot see who walked in
  3. learn and forward is the default
  4. link down is not the same as unused
  5. default-deny at the socket costs tickets

basics

~20 s

A socket that never got admission control hands a stranger a DHCP lease and layer-2 adjacency to everything in that room's VLAN. Shutting unused ports removes that, at the cost of a ticket every time a room is re-cabled.

solid answer

~50 s

On link-up the switch simply starts forwarding. If no admission control was ever applied to that port — which is the normal state of a socket the estate map forgot — the laptop lands in whatever VLAN the port is statically configured for, usually the one the room's phone or video kit uses. It gets a DHCP lease, ARP and broadcast reach to every host in that VLAN, and whatever the gateway ACL lets that VLAN route to. Nothing about being a visitor is visible to the switch; the port has no idea a person walked in the front door. The cheap counter is default-deny at the socket: administratively shut every port with no named owner. The price is administrative — someone must hold the record of which port serves what, and every desk move or room change becomes a request before the socket works.

go deeper

for a junior

Be ready to say concretely what a laptop gets when it plugs into an enabled port: a DHCP lease, same-VLAN adjacency, and whatever that VLAN is allowed to route to. Know that a switch's default is to learn and forward.

for a middle

Explain why the socket is live — floors cabled once and rooms repurposed later — and why link state is weak evidence that a port is idle. Be able to compare shutting ports, a non-corporate zone and device authentication by cost, not just by strength.

for a senior

Show you would not propose default-deny without naming who holds the port record and who turns ports back on. Interviewers want to hear the operational friction that erodes the control described before the control is recommended.

for a principal

Own the framing that the wall socket is where physical access converts into network access, and that no single team currently owns that conversion. Be ready to argue what the default posture for a building should be and what recurring spend keeps it true.

## Two estates, one cable A building has a physical estate — rooms, wall plates, floor boxes, patch panels, wiring closets — and a network has a logical estate — VLANs, subnets, zones, access rules. The wall socket is the single point where those two estates touch, and it is the one place where a person's physical access converts directly into network access. Everything on this topic follows from that: whoever may stand in the room may plug into the socket, and the switch cannot tell who is standing there. ## Why the socket is live in the first place Floors are usually cabled once, generously, when the building is fitted out: every plate is patched, every patch is landed on a switchport, and every switchport is enabled and assigned a VLAN. Then the building is used. Rooms are repurposed, a training room becomes a visitor lounge, a corner of open plan becomes a waiting area with a sofa in front of a plate nobody remembers. The cabling does not move. The result is a socket in a public room that is still patched, still enabled, and still assigned to whatever VLAN the floor was built with — typically a staff or voice VLAN, because that is what the floor was for. ## What link-up actually gives When a laptop comes up on such a port: - The switch learns the laptop's source MAC address and begins forwarding for it. A switch's default behaviour is to learn and forward, not to deny. - The laptop broadcasts a DHCP request and, if a relay or server serves that VLAN, receives an address, a gateway and DNS servers. - It now has layer-2 adjacency to every other host in that VLAN: ARP, discovery and multicast traffic, printers, phones, and anything else that trusts being on the same segment. - Beyond the VLAN, it reaches whatever the gateway's access rules allow that VLAN to reach — which, for a staff VLAN, is usually a great deal. None of this requires a tool or an exploit. The adversary here is not a tooled intruder; it is a visitor with a laptop, a legitimate reason to be in the room, and ten unattended minutes. ## "Enabled" is not "in use" The critical direction-of-claim: a port being administratively up tells you nothing about whether anyone uses it, and link being down tells you nothing about whether the socket matters. A port with no link may serve an AV cart wheeled in twice a month, an auditor's desk used one week a quarter, or a floor box under a carpet tile. That asymmetry is precisely why ports stay enabled: nobody can prove a port is safe to shut, so nobody shuts it. ## The postures and what each costs - **Administratively shut by default.** The cheapest control and the strictest. It costs a record — someone must know which port serves what — and it costs friction: a re-cabled room on Friday is a ticket on Monday. That friction is exactly what erodes it, because the fastest way to close the ticket is to enable a block of ports and never revisit them. - **Give public sockets a zone a stranger's laptop cannot use.** Defensible, but it is a permanent thing to run: a routed path, addressing, and an ongoing decision about which rooms count as public. The room's own phone and video kit still need the corporate side, so you still need per-port decisions. - **Require the port to authenticate the device before forwarding.** The strongest, and a programme rather than a setting — it needs a credential on every device that will ever be plugged in, which most estates do not have on day one. ## What an interviewer is listening for That you treat the socket as an access-control boundary rather than as plumbing; that you say plainly what a live port grants; and that you name the running cost of the fix rather than proposing default-deny as though it were free. Candidates who answer "we'd just shut them all" and stop have not thought about who turns them back on, or about the fact that the list of which ports to shut does not currently exist anywhere trustworthy.

  • That room's socket is genuinely used by an AV cart twice a month. Does that change your answer?
    It changes the evidence, not the posture. "Unused" is a time window, and a two-monthly device will look dead in any snapshot of link state. Either the port gets an owner and stays enabled with a documented purpose, or it stays shut and the cart's user raises a request. What is not acceptable is leaving it enabled because nobody could prove it was idle — that is how the lobby socket survived.
  • Why isn't putting every public socket in a guest zone the obvious fix?
    It is a reasonable posture, but it is not free and it is not complete. You take on a routed path, addressing and support for it permanently, and you still need a per-port decision because the same room usually contains a phone or a video system that must reach the corporate side. It also depends on a live definition of which rooms are public, which is the record that is hardest to keep true.
  • A candidate says the badge system protects the internal ports. What do you say back?
    Building access and network admission are separate estates with no shared record. A badge grants presence in a room; it never reaches the switch, and nothing in the port's configuration knows whether the person in the chair is an employee, a contractor or a visitor. Treating physical access as the compensating control means the network's admission decision is being made by a system that does not talk to it.

A wall socket is an unlocked door with no receptionist behind it: the room's own door decided who may stand there, and the switch just assumes that decision was made well.

saying these in an interview costs you the question

  • Assumes an unused port is harmless because nothing is plugged in
  • Thinks a switch denies unknown MAC addresses by default
  • Treats building badge control as the network's admission control
  • Confuses a port being administratively up with the port being in use
  • Proposes shutting all unused ports without saying who re-enables them

context