skip to content

How does a remediated contractor laptop leave NAC quarantine without a link bounce, and what does the deadline override hand an intruder?

level: seniorimportance: nice to knowfreq 28%

answer

  1. the exit must be an event, not a hope
  2. change-of-authorization swaps a live session
  3. filter swap invisible, VLAN swap is not
  4. no agent means no completion signal
  5. the override becomes the exit

basics

~20 s

Something must re-evaluate the device so the policy server can push a change-of-authorization swapping the restricted authorization for the production one. Where no such signal exists, the exit becomes a human override, and that exception outlives the deadline that justified it.

solid answer

~50 s

The exit has to be an event, not a hope. Either a re-authentication fires or the health agent reports remediation complete; the policy server then sends a change-of-authorization to the switch that replaces the session's authorization in place. If quarantine was a per-session filter, the swap is invisible — same address, new filter. If it was a VLAN, the device must re-address, so leaving costs a bounce too. On a contractor floor you often control neither the endpoint agent nor the update source, so no completion signal is ever produced and the only exit left is a person moving the port into a production profile before a deadline. That override is the real risk: an unmeasured device in production with no expiry, no owner and no re-check — and a path an adversary can walk deliberately by failing the check and escalating the deadline.

go deeper

for a junior

Know that a device does not leave quarantine by being fixed — something has to re-evaluate it and the policy server has to change what the port is allowed to do.

for a middle

Explain the change-of-authorization exchange and why the exit is seamless when quarantine was a per-session filter but costs a re-address when it was a VLAN.

for a senior

Show you design the exit and the exception together: what triggers re-evaluation, what happens to a device that can never report, and how an override is bounded in scope and time.

for a principal

Own the numbers that make the boundary defensible — automatic versus manual exit rate, time spent in quarantine, live overrides — and be prepared to refuse a business deadline that would make the control decorative.

## Designing the exit before enforcement day Every estate designs the entrance to quarantine carefully and the exit not at all. The entrance is a decision the policy server makes; the exit needs a *second* decision, triggered by something, and if nothing triggers it the device stays until somebody intervenes. Interviewers ask this because 'how does a device ever leave?' is the question that stalls real rollouts. ## The mechanism A session's authorization is not fixed for its lifetime. The policy server can send a change-of-authorization to the network device holding the session, and that message either replaces the authorization attributes or forces the session to re-authenticate. That is the clean exit: the device is re-evaluated, now passes, and its restricted authorization is swapped for its normal one while the session continues. What has to happen for that message to be sent is the part candidates skip. Something must know the device is fixed: - the health agent re-evaluates after remediation and reports the new state, which is the smooth path and requires an agent you control; - a re-authentication timer expires and the whole decision is retaken, which is the crude path and can leave a fixed device waiting out the interval; - an operator triggers it by hand, which is not a design, but is what most estates do on day one. ## What the exit costs, per enforcement form If quarantine was a per-session filter, the swap is genuinely invisible: the address does not change, the link does not drop, the user notices nothing. If quarantine was a VLAN, leaving is another subnet change, so the endpoint has to re-address and the exit costs the same bounce the entrance did. That asymmetry is a legitimate reason to prefer per-session filtering on an estate where devices cycle in and out of quarantine often. ## The partner floor, where none of it applies On a joint-venture project floor, the devices belong to the partner firm. You cannot dictate their build, you often cannot require your health agent on them, and their updates come from the partner's own service, which is not on your network. So: the device fails a check you cannot enforce upstream, lands in a segment that must now also reach an external update source, remediates against something you cannot observe, and produces no completion signal your policy server understands. There is no automatic exit because there is no reporter. What is left is a human. ## The override, and why it is the interesting half The override is real and it is not rare: a contractor has a deadline, the engineer on shift moves the port into a production authorization profile, and the ticket is closed. Look at what that actually created. A device whose health was never confirmed is now in production. The exception has no expiry, because the pressure that produced it was a date, not a policy. It has no owner after the shift ends. Nothing will re-check it, since the re-check that would have caught it is exactly the mechanism that has just been bypassed. And it is repeatable — the same laptop takes the same route next quarter, because the process worked last time. An adversary does not need to defeat the control to use this. Being placed in quarantine is a choice available to whoever holds the device; escalating a deadline is a choice available to whoever holds the relationship. The control is then not defeated but *routed around by the organisation that owns it*, which is why the exception path deserves as much design as the enforcement path. ## What a good answer proposes Make the override a first-class object rather than an act: it grants a defined, limited profile — not full production — for a fixed period; it records who granted it and against which ticket; it expires automatically so the device returns to evaluation without anybody remembering; and it generates a visible record so that a repeat pattern for one device or one team is noticeable rather than invisible. Then commit to something falsifiable before enforcement day: what proportion of exits are expected to be automatic, how long the median device sits in quarantine, and how many active overrides are tolerable at once. Those three numbers are what turn 'we have NAC' into a claim you can defend when somebody asks whether the boundary actually holds.

  • What makes a manual override into production safe enough to keep in the design?
    Four properties: it grants a limited profile rather than full production; it carries an automatic expiry so nobody has to remember to revoke it; it records a named grantor and a ticket; and it is visible enough that repeated use by one device or one team shows up. Without expiry it is a permanent hole created by a deadline that passed months ago.
  • Why does a re-authentication timer make a poor primary exit path?
    It is unrelated to whether anything was fixed. A device that remediated in five minutes waits out the rest of the interval, so the interval becomes a support complaint and pressure to shorten it — which then re-evaluates the whole estate more often and raises policy-server load. A completion-driven change-of-authorization exits the device when it is actually ready; the timer is the fallback for devices that cannot report.
  • On the partner floor, what would you measure to show quarantine is working rather than just existing?
    How many sessions entered quarantine, how many exited automatically versus by hand, the median time a device spent there, and how many overrides are live right now. If nearly all exits are manual, quarantine is a ticket queue with a VLAN attached; if overrides never expire, the enforcement boundary is quietly shrinking every week.

saying these in an interview costs you the question

  • Assumes a device leaves quarantine on its own once it is patched
  • Thinks a change-of-authorization can change VLAN without the endpoint re-addressing
  • Grants a production override with no expiry and no named owner
  • Treats the manual override as an edge case rather than the common exit
  • Has no exit at all for a device that cannot run your health agent
  • Cannot say how long devices currently sit in quarantine

context