skip to content

You run a new deny-by-default catch-all in log-only mode for 90 days first — what does that window hand an adversary?

level: seniorimportance: should knowfreq 48%

answer

  1. log-only is allow, with paperwork
  2. the discovery window is the exposure window
  3. observed becomes the exception list
  4. no owner means no complaint
  5. phase by destination, not by calendar

basics

~20 s

Ninety more days of allow-by-default on every unlisted subject, plus the risk that whatever an intruder does during the window becomes part of the baseline you promote into permanent exceptions. Log-only defers the denial; it does not de-risk it.

solid answer

~50 s

Log-only mode is not a safer version of deny-by-default — it is allow-by-default with better records, run for a defined period. Two things follow. First, the exposure that the programme was funded to close stays open for the whole window, and the window has to be long precisely because the rare, undocumented callers are the ones you are trying to find. Second, and worse, teams typically turn the observed set into the exception list on flip day. Anything an adversary was doing while you watched arrives on that list looking exactly like a legitimate integration: seen repeatedly, never denied, no complaints. You have documented the hole and given it a rule. The fix is not a shorter window but a different shape: deny immediately on destinations you can defend, require a claimed human owner before an observed flow becomes an exception, and phase by resource sensitivity instead of by calendar.

go deeper

for a junior

Understand that monitor or log-only mode still lets the traffic through; it records the decision it would have made. It buys knowledge, not protection.

for a middle

Be able to explain why the observation window is simultaneously a discovery window and an exposure window, and why rare integrations force it to be long.

for a senior

Show the trap: the observed set becomes the exception list, so an intruder active during monitoring gets a permanent rule. Argue for owner-claimed exceptions, expiry dates, and phasing by destination rather than by calendar.

for a principal

Be ready to defend the phasing plan to a sponsor who wants a single date and a single flip, and to explain what the organisation is buying with each additional month of monitoring.

## What log-only actually is Running a new catch-all in log-only ("monitor", "audit", "dry-run") mode means the enforcement point evaluates the rule, records what it *would* have done, and then lets the traffic through. This is genuinely useful — it is how you avoid denying four hundred flows you never knew about — but it is important to name it correctly. **For the duration of the window, the policy for every unlisted subject is allow.** The organisation has not reduced risk; it has scheduled a risk reduction and paid for the delay in exposure. That matters most in exactly the estate where this technique is reached for. A partner extranet has external callers, credentials issued years ago to integrations nobody owns, and appliances with no lifecycle. It is where you most want the deny, and it is where the observation window is longest, because the callers you are hunting for run monthly, quarterly or annually. ## The failure a strong senior candidate still walks into The common answer is "monitor for ninety days, review what would have been denied, write allow rules for those, then flip." The last step is where it breaks. The observed set is being converted into the exception list, and the observed set includes **everything that happened during the window**, including an adversary's traffic. An intruder using an old service credential, or an unowned integration appliance as a foothold, produces exactly the profile that survives the review: it appeared many times, it never caused an incident, and no owner complained about it — because there is no owner to complain. A reviewer working through a list of two hundred would-have-been-denied subjects on a deadline has no way to separate it from the file-transfer job that has run since 2014. The programme ends by writing that access a named rule, giving it an indefinite lifetime and removing it from the set the next default will ever touch. **You have laundered the adversary into policy.** There is a second-order version: the window teaches an adversary too. If enforcement is announced, or if would-have-been-denied decisions are visible from the client side, the useful move for an intruder is to establish presence during the observation period specifically so as to be grandfathered. ## What to do instead The answer is not "shorten the window" — a shorter window omits more rare callers and makes flip day worse. Change the shape: 1. **Split the estate by defensibility, not by date.** Some destinations already have a complete, owned list of callers. Deny there today; you gain real reduction immediately and you generate evidence that enforcement is survivable. 2. **Make an owner, not an observation, the ticket to an exception.** An observed flow becomes a *candidate*. It becomes a rule only when a named human accepts ownership of it. Anything nobody claims stays unclaimed and is decided by the default, which is the honest outcome. 3. **Put an expiry on every exception written from the window.** A rule created to survive flip day should be dated. Undated exceptions are how the next generation inherits the same problem. 4. **Keep observing after you enforce.** Denied decisions after flip day are a far better signal than would-have-been-denied decisions before it, because a real denial produces a complaint from a real owner within minutes — the fastest inventory instrument you will ever get. 5. **Pair enforcement with a fast, expiring break-glass.** If being wrong costs a ten-minute grant rather than a quarter of monitoring, you can afford to enforce earlier and learn from breakage instead of from logs. | Approach | Exposure while you learn | Risk on flip day | Adversary laundered into policy? | | --- | --- | --- | --- | | Log-only estate-wide for 90 days | Full, for 90 days | High and concentrated | Likely, if observed becomes allowed | | Deny on defensible destinations first | Reduced immediately for those | Spread over phases | No — those lists are owned | | Enforce with expiring break-glass | Short | Absorbed as minutes of grant | No — each grant has a requester | ## Directions to keep straight A would-have-been-denied record proves a request arrived that no rule names; it proves nothing about whether that request was legitimate. The absence of complaints during a log-only window proves the traffic was allowed, not that it was wanted. And ending the window is not the same as reducing the risk: the reduction happens on flip day, and its size is determined entirely by how many of the observed subjects you refused to grant a rule.

  • How do you separate an adversary's flows from undocumented legitimate ones in the observed set?
    Not by inspecting the traffic — both look like a subject that arrived and was allowed. You separate them by requiring a claimed human owner before writing any exception. The undocumented but legitimate integration eventually finds an owner because somebody's process depends on it; the adversary's does not, and stays in the unclaimed pile the default decides.
  • Is there any argument for a longer log-only window rather than a shorter one?
    Yes, and it is the honest tension: rare callers only appear over a full business cycle, so a longer window produces fewer surprises on flip day. That is why the answer is not to tune the number but to stop treating the whole estate as one switch — enforce where the caller list is already owned, and reserve the long observation for the parts that genuinely need it.

Propping the door open for three months to write down who walks through, then issuing a permanent key to everyone on the list — including whoever was already coming in uninvited.

saying these in an interview costs you the question

  • Calls log-only mode a risk reduction rather than a deferred one
  • Writes allow rules for every observed flow on flip day
  • Assumes no complaints during monitoring means no problem
  • Treats the estate as one switch on one date
  • Creates exceptions with no owner and no expiry
  • Shortens the window to reduce risk, omitting rare callers

context