skip to content

802.1X enforcement day: how do you get an owner to sign fail-open, admitting whoever is in the cabinet, or fail-closed, a site dark for a day?

level: principalimportance: nice to knowfreq 28%

answer

  1. the security team absorbs neither outcome
  2. one posture per site class, not per estate
  3. shrink the exposure until it is signable
  4. an off switch with someone else's hand on it
  5. five lines of back-out before enforcement day

basics

~20 s

Take it to whoever owns the sites, not the security team. Price a realistic outage per site class against what an open port reaches, recommend a different posture per class, and get the choice, the back-out and the invoker named on the change record before enforcement.

solid answer

~50 s

The failure posture is a business risk decision and the security team cannot sign it, because the security team does not absorb a dark substation or a till that cannot take payments. Go to the person who owns the site's operations. Bring three things. First, the realistic outage: how long a site is offline under a circuit failure, a server failure and a fleet-wide credential failure, using measured numbers, not the happy path. Second, the reach of the open posture: exactly which systems a fallback-admitted port can touch, which is your lever — if that VLAN reaches only local operational systems, fail-open becomes signable. Third, the detection and the bound: every port that takes the fallback is alarmed, the list is audited afterwards, and the relaxation is time-boxed. Then differentiate by class — a safety-critical site and a head-office floor should not share a posture. Get a name, a back-out and an invoker on the change record. What you refuse is enforcement day with the posture undecided.

go deeper

for a junior

Understand that whether a control denies or admits when it breaks is a choice someone makes in advance, and that the choice has an owner outside the security team.

for a middle

Be able to describe both postures with their concrete costs — a site with no network against a port that opens on demand — and say what a fallback VLAN should be allowed to reach.

for a senior

Show that you would bound and instrument the open posture until it is acceptable, and that you would rehearse the back-out and verify enforcement is restored after every relaxation.

for a principal

Own the negotiation: segment the estate, price each failure for the people who absorb it, state plainly that fail-open is attacker-triggerable, and refuse enforcement day until the posture, back-out and invoker are on a change record with a name.

## Why this is not an engineering decision Fail-open and fail-closed are usually argued in the network team as if the answer were technical. It is not. One choice buys availability and pays in exposure; the other buys assurance and pays in outage — and in an estate of unstaffed sites the outage is not an inconvenience, it is a depot that cannot dispatch, a store that cannot trade, a substation whose operators lose remote visibility. **Nobody in the security team is accountable for any of those, so nobody in the security team can accept that risk on the business's behalf.** The failure this question is really testing for is the engineer who makes the call alone and discovers on the first outage that they own a consequence they never had the authority to accept. ## Segment the estate before you argue A single global posture is almost always the wrong answer, and proposing one is what makes the conversation unwinnable — you are asking an owner to accept the worst case of both options at once. Classify sites by what being dark costs and what being open exposes: | Site class | Cost of dark | Exposure if open | Typical posture | |---|---|---|---| | Safety- or continuity-critical, unstaffed | Severe and immediate | Physical access is hard, reach can be kept local | Fail open, tightly scoped and alarmed | | Trading site with a till or a depot | Real revenue per hour | Public-adjacent floor space | Fail open to a narrow operational VLAN, short time box | | Staffed office floor | Inconvenience, people can move | Wall ports in reach of visitors | Fail closed | | Data centre and management network | Handled by other paths | Highest value in the estate | Fail closed, no exception | The table is the deliverable. It converts an argument about principle into a set of small decisions an owner can actually make, and it lets them accept exposure where the cost of denial is genuinely intolerable while conceding closure everywhere else. ## What you must state honestly to the signer Three things, in plain language, because a signature obtained without them is worthless: 1. **Fail-open is a control an adversary can trigger.** They do not have to defeat authentication; they have to make the authentication servers unreachable from that site, and a rural circuit is not hard to disturb. You are signing for an off switch whose operation is partly in someone else's hands. 2. **Fail-closed means no remote recovery.** The engineer who would fix it, the jump host and the patch source are behind the same control. If the answer is fail-closed, the organisation is funding an out-of-band path or accepting drive-time as the mean time to repair. 3. **The evidence obligation.** If you cannot show which ports took the fallback and what they did while there, you cannot tell the difference between a rough night and a breach. That is a monitoring cost with a real price attached, and it should be funded in the same decision, not discovered afterwards. ## Bound the open posture, and make it cheap to say yes Most owners will sign fail-open if the exposure is bounded and observable. Your job is to shrink it until it is signable: a fallback VLAN with a short list of reachable destinations and no route to management; an alarm per port placement, not a daily digest; an automatic re-evaluation and a review of the port list after every event; and a stated maximum duration after which the site is treated as an incident rather than a degraded state. Each of those turns an open-ended concession into a bounded one. ## Write the back-out before enforcement day, not during The operator on the bridge at 02:00 should be reading a decision somebody already made. That means: the trigger conditions for backing enforcement out, the scope it applies to, who may invoke it without waking an executive, the time box, and how enforcement is verified as restored afterwards, site by site. If those five lines do not exist, enforcement day is not ready, and saying so is the most senior thing you can do in this conversation. A rollout that begins with an undecided posture will make the decision anyway — at three in the morning, under pressure, by whoever happens to be on the call. ## The failure modes an interviewer is listening for Saying 'we fail closed, security first' with no acknowledgement of who absorbs the outage. Saying 'we fail open, availability first' with no scoping or detection. Presenting a single global posture. Owning the decision personally when the consequence lands elsewhere. Treating the signature as paperwork rather than as the moment the organisation actually chooses which failure it prefers.

  • The site owner refuses to sign either option; what do you do?
    Do not proceed to enforcement. A refusal usually means the numbers are not credible or the exposure is unbounded, so tighten one of them: measure the real outage duration, or shrink what the fallback reaches until the open posture is small enough to accept. If refusal persists, escalate the decision rather than resolving it yourself — an unsigned posture still becomes a decision on the first outage, just without an owner.
  • How do you keep the agreed posture from silently drifting after go-live?
    Make the current posture per site class a reviewed artefact, alarm on any port taking the fallback, and audit after every event that enforcement was restored where it was relaxed. Drift here is invisible because the estate looks healthy either way — an open site works perfectly until someone plugs in.
  • What would make you argue for fail-closed at a site whose owner wants fail-open?
    Public physical access to ports, no way to bound what the fallback reaches, or no detection on placements. If a stranger can reach a wall socket and the fallback cannot be scoped or alarmed, the open posture is not a degraded mode, it is an advertised entry point — and I would rather fund an out-of-band recovery path than sign for that.

saying these in an interview costs you the question

  • Chooses the failure posture inside the security team
  • Proposes one global posture for the whole estate
  • Argues security first without naming who absorbs the outage
  • Accepts fail-open with no scoping, alarm or time box
  • Reaches enforcement day with the back-out unwritten

context