skip to content

Three destinations are exempt from your VPN tunnel - how do you prove an implant is not using that uninspected path?

level: seniorimportance: nice to knowfreq 33%

answer

  1. refuse the negative first
  2. unobserved is not the same as quiet
  3. you can buy a vantage back at a price
  4. coverage caps every host-based claim
  5. the tenant trail misses other tenants

basics

~20 s

You cannot, from the network - there is no vantage there by construction. You either rebuild one deliberately, fall back to endpoint and destination-side records with their limits stated, or say plainly that the path is unobserved.

solid answer

~50 s

Start by refusing the question as asked: the honest claim is "this path is not observed", never "no activity was seen on it". Then choose what to buy back. You can restore a vantage - route the exempt destinations through a metadata-only path, or re-include them for a sampled cohort or a fixed window and measure what was actually flowing, which costs exactly the capacity the exemption was meant to save. You can lean on the endpoint agent, remembering it is the asset you assume is compromised and that its answer is only as good as its coverage. You can read the destination's own tenant trail, which records activity in your tenant and is blind to traffic that reached somebody else's account inside the same address block. Each option has a price, and the choice is which price you are willing to pay for which strength of claim.

go deeper

for a junior

Know that no analysis can recover records a sensor never collected, and that an unobserved path supports no claim about what crossed it.

for a middle

Explain the difference between an unobserved path and a quiet one, and why endpoint coverage numbers bound every host-based statement you make.

for a senior

Show the sequence: bound the claim, establish agent coverage, use the destination trail for what it covers, then price a metadata path or a measured re-inclusion window against the residual uncertainty.

for a principal

Own the precondition: decide what evidence about an exempt path will be accepted before granting the exemption, or accept that answering later costs more than the exemption saved.

## The question contains a trap "Prove nothing is using the exempt path" asks for a negative from a place where you have deliberately removed every observer. No amount of analysis produces evidence a sensor never collected, and the first mark of a strong answer is naming that rather than producing a reassuring dashboard. The claims available to you are narrower than the question implies: - Available: *this path is unobserved by any corporate control*. - Available with caveats: *the endpoint agent recorded no matching process activity on the machines where it was healthy and reporting*. - Not available: *no exfiltration or command traffic used this path*. Confusing the second for the third is the failure this question exists to catch. ## Buying a vantage back, and what each option costs **Re-include and measure.** Withdraw the exemption for a sampled cohort, or for the whole fleet during a defined window, and let the traffic traverse the stack. This is the only option that produces evidence of the same class you lost. Its price is precisely the price the exemption was avoiding: concurrent sessions and egress at peak, plus a degraded experience for the cohort, plus somebody to own the change. Done as a window, it also only tells you about the window. **A metadata-only path.** Send the exempt destinations somewhere that records the five-tuple, volume and timing without the full inspection tier. It is cheaper than full re-inclusion and yields far less: it can show that bytes moved to a destination, never what they were. That is still a large improvement over nothing, because the shape of a transfer is often the first thing anyone notices. **The endpoint.** The agent records process and connection activity regardless of route, so it is the natural fallback - with three honest caveats. It runs on the machine you are assuming is compromised. Its coverage is a rollout and licensing fact, not a given, so "we saw nothing" is unqualified until you can say on how many devices the agent was actually healthy. And it answers about that host only. **The destination's own trail.** Where the exempt destination is a service you are a tenant of, its audit trail is real evidence about *your tenant*. Its blind spot is the important one here: an implant using an attacker-controlled account, or any other service answering inside the same shared address block, appears nowhere in your tenant's records. The exemption is keyed to addresses, and your tenant trail is keyed to your account. ## Ordering the response A workable sequence: state the bounded claim; check how many devices actually have healthy endpoint coverage, because that number caps every host-based statement you are about to make; pull the destination-side trail for what it does cover; then decide whether the residual uncertainty justifies re-including the destinations for a measured window. If it does, plan it as a capacity event with an owner and a rollback, not as a quiet experiment - re-tunnelling the heaviest destinations is exactly the load the head-end could not carry, which is why the exemption exists at all. ## The structural point Every answer above is more expensive than the exemption was, and that is the lesson worth carrying out of the question. An exemption is cheap when it is made and expensive every time anyone needs to say something about the traffic that uses it. Estates that grant exemptions without deciding, in advance, what evidence they will accept about that path end up in this exact position: a reasonable question, a control decision made two years earlier, and no way to answer without spending the money that was saved.

  • Is the SaaS destination's own audit trail an adequate substitute for network visibility here?
    Partly, and its blind spot is the one that matters. It records activity inside your tenant. Traffic from your fleet that reached an attacker-controlled account, or any other service answering inside the same shared address block, is exempt by address and invisible to your tenant's records. It is corroboration for one destination, not coverage of a path.
  • What does a temporary re-inclusion window actually buy you?
    Evidence of the class you gave up, for the duration of the window and no longer. It costs the peak capacity the exemption was avoiding and it degrades the cohort's experience, so it needs an owner, a change window and a rollback. Treat it as a measurement with a price rather than a quiet experiment.
  • How should you word the finding to a stakeholder who wants a yes or no?
    Say what is true: this path is not observed by any corporate control, so no statement about activity on it is available; here is what the endpoint agent covers and on how many devices; here is what the destination's trail covers; and here is what restoring a vantage would cost. Offering a false negative is the only genuinely wrong answer.

saying these in an interview costs you the question

  • Presents an absence of records as evidence nothing happened
  • Quotes endpoint findings without stating agent coverage
  • Treats the destination's tenant trail as full path coverage
  • Proposes re-inclusion without accounting for the peak load it returns
  • Claims flow analytics can cover a path no corporate device carries

context