You place a probe host in four hundred branch segments - what have you just built for an intruder?
answer
- you added a host to your weakest segments
- its cross-segment traffic is expected and muted
- management crosses the boundaries under test
- the target list is an estate map
- no credentials, outbound only, narrow suppression
basics
~20 sA fleet whose declared purpose is to originate cross-segment traffic, present in every low-trust segment, centrally managed across your own boundaries, holding a map of which pairs should be open, and deliberately excluded from alerting. Design it to be worthless when captured: no credentials, outbound-only management, and narrow suppression.
solid answer
~60 sYou have deployed, into the least-attended segments you own, a device that is expected to talk to other segments, that crosses boundaries to be managed, that carries a target list describing your intended topology, and whose traffic analysts have been told to ignore. That is a pre-positioned pivot with an alibi. Make it a poor prize instead. Probes are unauthenticated connection attempts, so the host holds no credentials to any target and captures nothing when taken. Management is outbound-polling only, so nothing needs an inbound path into the branch. The host pulls only its own row of the target list, so it does not carry the estate map. Suppression is scoped to source address, destination and service inside a known window rather than a blanket exemption for the host. And the probe hosts themselves are cells in the matrix: probe from them and toward them. Operationally, a bricked host in a store on consumer broadband is unreachable until someone drives there, so the design must fail into unknown, never into pass.
go deeper
Be able to say that the probe host is itself a device in a segment, so it needs the same scrutiny as anything else you put there, and that it should not hold credentials for the systems it tests.
Explain the mechanics that make it a poor prize: outbound-only management polling, per-host target lists rather than the whole matrix, and suppression scoped to a declared schedule.
Show the full design under real constraints - unattended sites, unmanaged links, remote recovery, staged rollout - and the reporting rule that a non-reporting probe renders unknown rather than pass.
Own the trade that credible denial evidence is bought with new attack surface and a new management path across the boundaries under test, and be able to state that price plainly to whoever is asking for the evidence.
## The uncomfortable shape of the thing you built The probe fleet exists to produce evidence of denial, and every property that makes it good at that also makes it attractive to an intruder: - **It lives in the low-trust segments.** By design there is one in the branch, the store network, the device VLAN - the places with no on-site staff, the weakest physical control and the fewest eyes. - **Its job is to talk across boundaries.** Traffic from this host to other segments is expected. An intruder who lands on it inherits an established behavioural alibi. - **It is managed across your own boundaries.** Somebody built a path from a central system into every segment in the estate, or from every segment out to a central system, in order to control the thing that tests those boundaries. - **It carries intent.** The target list says which pairs are supposed to be denied and, by omission, which are supposed to be open. That is a better estate map than an intruder would normally build by hand. - **It has been muted.** Its probing looks exactly like internal enumeration, so somewhere a suppression exists to stop it paging anyone at three in the morning. Muted, expected, cross-segment traffic is the ideal cover. A candidate who says "we put a probe in every segment" and stops there has missed the second half of the question. The interviewer is testing whether you evaluate your own instrumentation as attack surface. ## Designing it to be a poor prize **Hold nothing worth stealing.** A denial probe is an unauthenticated connection attempt: it does not need to log in to anything. If the design ever requires credentials to targets, the fleet stops being a test harness and becomes a credential store distributed across your weakest segments. Same for results - the host reports outward and does not accumulate history locally. **Invert the management direction.** The host polls out for its schedule and pushes results out; nothing needs an inbound path into a branch segment. This removes the estate-wide inbound reach that is otherwise the most dangerous artefact of the whole programme, and it survives consumer broadband with a changing address and no inbound reachability. **Split the target list.** A host pulls only the pairs it is responsible for, not the whole matrix. Capturing one branch probe should reveal one branch's row, not the topology. **Scope the suppression narrowly.** Suppress on the specific source address, destination set, service and time window that the schedule declares. A blanket exemption for the host is the version an intruder wants, because then anything the host does is invisible. Better still, alert when the probe host does something *outside* its schedule - that inversion turns your instrumentation into a tripwire rather than a blind spot. **Put the fleet inside the matrix.** Probe from the probe hosts and toward them. They are hosts in segments like any other, and their own reachability is a claim worth testing - especially the claim that nothing can reach them inbound. ## The operational half nobody costs properly Four hundred stores on consumer broadband, no technical staff on site, and no appetite to send anyone. That produces constraints the security design does not: - **Failure must be recoverable without hands.** A device that can be bricked by an update is a device that will be dead in some fraction of sites permanently. Watchdogs, a known-good fallback, and an update rollout that goes in waves rather than everywhere at once. - **Absence must be a distinguishable state.** A store whose probe stopped reporting has produced no evidence. If the dashboard renders that as green, the estate's least reliable sites become its best-looking ones. Silence renders as unknown, and a growing unknown count is itself the alarm. - **The link is not yours.** A consumer connection drops, changes address and has no service target. The design must tolerate that without generating a false failing result for the boundary, which is precisely why every negative probe travels with a control flow: when the link is broken, both fail, and the cell goes unknown rather than red. - **Scale changes the meaning of a small defect.** A one-percent failure mode is four sites; a subtle clock or scheduling bug reproduces four hundred times before anyone notices. ## The honest summary Evidence of denial is not free, and its cost is not only money. It is a new fleet of hosts in your worst-controlled segments, a new management path that crosses the boundaries you are testing, and a new suppression rule in the alerting stack. That price is usually worth paying, because the alternative is asserting isolation from a configuration file. But an engineer who cannot state the price has not finished the design, and the assessor asking for the evidence is not the only person interested in how it is produced.
- How do you keep the probe traffic from burning analyst time without blinding yourself?Suppress on the declared schedule rather than on the host. The source address, destination set, service and time window are all known in advance, so the suppression can match exactly that and nothing else. Then invert it: activity from a probe host outside its schedule, or toward a destination not on its list, becomes a high-quality signal. The instrumentation turns into a tripwire instead of a blind spot.
- Why must a probe host that stops reporting not be rendered as a pass?Because it produced no measurement. At four hundred sites on unmanaged links, non-reporting is the most common event in the system, so if silence colours green, the least reliable sites look the healthiest and the coverage figure becomes fiction. Absence renders as unknown, and the count of unknown cells is itself a metric worth alerting on when it grows.
- Does the probe host need credentials to the destinations it tests?No, and it should not have them. Proving reachability or denial is an unauthenticated connection attempt - the outcome of the handshake is the whole result. Adding credentials would turn a test harness into a credential store sitting in your least-protected segments, and would convert the capture of one branch probe into access rather than merely information.
A key-testing service that keeps a key to every door, walks the corridors at night, and has told the guards to ignore it, is a burglary waiting for the right employee.
saying these in an interview costs you the question
- Never considers the probe fleet as attack surface
- Gives probe hosts credentials to the systems they test
- Builds inbound management reach into every segment
- Suppresses all alerts from the probe host wholesale
- Stores the full target matrix on every probe host
- Treats a non-reporting probe as a passing result
- Excludes the probe hosts from the coverage matrix