An access proxy's first-seen records are your only asset list — how long do you watch, and which attacker paths never appear there?
answer
- the record only covers one vantage point
- rare callers are the undocumented ones
- a full business cycle, not thirty days
- watching is also exposing
- a reused credential looks like an enrolled subject
basics
~20 sWatch a full business cycle: quarterly and year-end callers are the undocumented ones. The records cover only subjects that reached that enforcement point, so a path bypassing it, or reuse of an already-enrolled subject, leaves no new entry.
solid answer
~50 sWhen the catalogue is incomplete, the enforcement point's own record of subjects it has seen asking for access becomes the discovery source of last resort. The window has to cover a full business cycle — month-end, quarter-end and any annual reconciliation — because the integrations nobody documented are usually the ones that run rarely, and a thirty-day sample confidently returns a list that is missing them. Two limits matter more than the window. First, the record only covers traffic that traversed that enforcement point; an east-west path inside the same segment, a legacy circuit, or the second access path still running from the migration produce nothing. Second, a first-seen entry proves a request arrived and presented whatever credential it presented — it does not prove the entity is legitimate, owned, or still needed. An adversary reusing an old service credential appears as a subject already on your list, not as a new one.
code
text · 8 lines2026-03-02T02:14:07Z first_seen subject=svc-ftx-batch src=203.0.113.44
dst=files.internal:22 auth=mtls-client-cert
matched_rule=catch-all decision=allow owner=<none>
2026-03-02T02:14:09Z first_seen subject=<none> src=203.0.113.90
dst=orders.internal:443 auth=none
matched_rule=catch-all decision=allow owner=<none>
...go deeper
Know that when the asset list is incomplete, what the access control point has actually seen asking for access is the fallback source, and that it can only show traffic that passed through it.
Be ready to explain why the window must span month-end, quarter-end and any annual job, and to state precisely what a first-seen entry proves: a request arrived with a credential, nothing about ownership or legitimacy.
Demonstrate that you would not wait for a complete list before acting — deny on the destinations you can already defend while observing the rest, and require a claimed owner before any observed subject becomes a rule.
Own the trade that observation time is exposure time, and be able to justify to a sponsor why the programme is spending a quarter watching rather than enforcing, with a defined stopping condition.
## Why the enforcement point becomes the inventory In a partner extranet — suppliers, brokers and their automation calling internal endpoints — the asset catalogue is almost never complete, and the reasons are structural rather than sloppy. Integrations are created during a commercial onboarding, not an IT project. Appliances arrive with a vendor contract that later lapses. A file-transfer service account created in 2014 still runs because the batch it feeds still settles money. None of these entities has a lifecycle owner, so none of them is in a system of record. When you need the list anyway, the **enforcement point's own record of subjects it has observed asking for access** is what you have left. Every identity-aware proxy, gateway or policy engine records something about each decision: when it first saw a subject, what identity that subject presented, what it asked for, and which rule matched. Reconciling that observed set against the catalogue produces three buckets: things in both (fine), things catalogued but never seen (candidates for removal), and **things seen but in no catalogue** — this leaf's subject. ## The window is a business cycle, not a number of days The instinct is to watch for thirty days. That produces a list with high confidence and a systematic bias: rare callers are missing, and rare callers are exactly the undocumented ones. A useful window covers: - **Month-end** — invoicing, reconciliation, statement generation. - **Quarter-end** — regulatory and partner reporting, the classic source of the 02:00 failure. - **Any annual cycle** you can name — renewal runs, audit extracts, tax or year-end jobs. - **Disaster-recovery or failover exercises**, where secondary paths and standby appliances speak for the only time all year. That is a long time to wait, and the waiting is itself a cost: while you observe, the default is still whatever it was, so a discovery window and an exposure window are the same window. You do not get to spend it for free, which is why observation is usually paired with immediate denial on the destinations you can already defend, rather than run estate-wide as a prerequisite. ## What a first-seen record proves, and what it does not Get the direction of the claim right, because it is where candidates lose the question: - It proves **a request arrived at this enforcement point and presented this identity**. It does not prove a particular machine, a particular team, or a legitimate business need. - A subject appearing every night for ten years proves **habit**, not authorisation. "It has always worked" is the reason it is uncatalogued, not evidence that it should be allowed. - An identity presented over mutual TLS proves **a private key was held**, not who held it. A credential lifted from an old appliance produces an entry indistinguishable from the appliance's own. ## The paths that never appear This is the half interviewers actually probe. Your observed list has a vantage point, and everything outside it is invisible: 1. **Traffic that never traverses the enforcement point.** East-west flows inside the same segment, a direct circuit from a partner into a legacy DMZ, or a route that predates the proxy. The list will not merely under-report these; it will report nothing at all, and its silence looks identical to their absence. 2. **The second access path.** During a perimeter-to-zero-trust migration the old path stays reachable, so an adversary choosing between a policy-enforced proxy and an unmodernised route picks the second. Nothing about that choice registers on the first. 3. **Reuse of a subject already on the list.** An adversary who replays a service credential inherits an identity that is already enrolled, already "seen", and about to become a documented exception. The reconciliation improves their position rather than exposing them. 4. **Anything that only ever fails.** If you are reconciling from allowed decisions, a subject that is already blocked upstream never appears, and you will happily remove the rule that was blocking it. ## Using the list without laundering the adversary The dangerous move is to convert the observed list directly into an allow list — that promotes every observed flow, including any adversary's, into a signed exception with a rule of its own. The safer shape is that observation produces **candidates that require a claimed human owner before they become rules**. An entity nobody will claim stays in the unclaimed pile and is decided by whatever the default becomes; it does not quietly acquire a permanent rule because it was busy during the observation window. Reconcile in both directions as well: catalogued entities never seen are as informative as seen entities never catalogued, and they are usually cheaper to remove.
- You reconcile and find catalogued entities that were never observed. What do you conclude?Only that they did not pass this enforcement point during the window. That could mean they are decommissioned, that they run less often than you watched, or that they reach their destination by a path you are not standing in. Treat it as a question for the listed owner, not as authority to delete the rule — the third case is the one that turns a cleanup into an outage.
- Why is promoting every observed flow straight into an allow rule a bad reconciliation?Because it launders whatever was already happening into policy. An adversary active during the window gets a named rule, an owner-less exception and an indefinite lifetime, and the programme has documented the hole rather than closed it. Observation should produce candidates that need a human owner to claim them before any rule is written.
saying these in an interview costs you the question
- Treats thirty days of observation as a complete inventory
- Says a long-standing observed flow is therefore authorised
- Converts every observed subject directly into an allow rule
- Forgets flows that never traverse the enforcement point
- Assumes a presented client certificate identifies who holds the key
- Ignores that the observation window is also an exposure window