How do you stage one simultaneous containment cut across three regions against an intruder holding two footholds?
answer
- you get one clean attempt
- enumerate first, then cut once
- a written list, one owner per row
- not over the path you are cutting
- capture before the destructive step
basics
~20 sEnumerate every foothold first, then run one written cut list — an owner and a tested step per row — inside a single window on one clock. Pre-position access that survives the cut, and capture evidence before any destructive step.
solid answer
~40 sYou get one clean attempt, so almost all the work is before T-0. Enumerate until you believe you have every foothold, because anything missed is the way back in and the cut announces you. Write a cut list: one row per action, each with an owner, a pre-tested step and a verification. Pre-position everything the cut will break — out-of-band access to the appliance rather than the VPN you are killing, break-glass credentials, standby images, hands in each region. Capture evidence before destructive steps, because reflashing the appliance destroys what proves the case. Then run it on one clock: a single T-0 in UTC, everyone executing within minutes rather than in sequence. Keep an explicit abort criterion, and if one region misses T-0, proceed anyway and isolate that region at the network layer.
go deeper
Understand why every foothold has to be removed in the same window: cutting one at a time warns the adversary and leaves them somewhere to go.
Explain the mechanics of the plan — a written cut list with owners and verification, out-of-band access that does not depend on what you are cutting, and evidence capture before destructive steps.
Show the judgment: when enumeration stops, how the window is run on one clock across regions, what the abort criterion is, and what you do when a region misses T-0.
Own the trade between a longer enumeration and accruing loss, and be able to defend to executives why the estate was left compromised for another day to buy a cut that only had to happen once.
## Why simultaneity is the whole design An adversary with two homes — say an implant in the edge VPN appliance's firmware and a dormant inbox rule in the mail platform — is only contained when both go at once. Cutting one first does not halve the problem; it converts a covert investigation into an open contest, gives them a surviving channel and hands them the information about which one you found. So the containment is designed as a single event with a defined start, not as a series of improvements. ## Before T-0 **Enumerate to the point of a decision.** You will never be certain the list is complete. What you need is a defensible statement: here are the footholds we have found, here is the telemetry we have swept for others, here is what we would expect to see if a third exists. Enumeration has a stopping rule, and the stopping rule is usually the loss rate — when damage accruing per hour exceeds what another day of hunting is likely to buy, you stop and cut. **Build the cut list.** One row per action. Each row carries: the target, the exact step (a command, a console action, an API call) that has been tested somewhere safe, the person who will run it, what it depends on, how it will be verified in the first minute, and what to do if it fails. The list is the artefact the whole operation runs from and it should be readable by someone who was not in the planning. **Pre-position everything the cut will break.** This is the step most often missed. If you are taking the VPN appliance offline, you cannot manage it over the VPN — you need console or out-of-band access proven working beforehand. If identity changes are part of the cut, someone must hold break-glass credentials that are not affected by them. Replacement appliances or firmware images should be staged in each region already. And you should not be staging any of this inside a system the adversary can read. **Freeze the estate.** Ordinary change during the window makes verification impossible: you will not be able to tell whether the anomaly at T+10 is the adversary or a routine deployment. Pause non-essential change and tell the change owners as much as they need to know. **Capture before you destroy.** Your own remediation is destructive. Reflashing or replacing the appliance takes its volatile state with it; deleting the inbox rule removes the live object; rebuilding a host removes the only copy of an implant. Decide per item what is captured first — appliance configuration and running state, an export of the mail audit records covering the rule's life, disk or memory images where they matter — and treat that capture as a numbered row in the cut list, not an afterthought. ## At T-0 **One clock.** Announce a single time in UTC and count down to it. Three regions means three sets of hands, and the aim is that every row executes inside a window of a few minutes, not a sequence that walks around the world over an afternoon. **Order inside the window matters less than the window itself,** but there is still a sensible order: kill the adversary's access paths and the identities together, then remove persistence, then verify. Do not leave identity revocation for after the network cut simply because it is harder to coordinate. **Verify each row, not the operation.** Each owner confirms their own step landed — the appliance is off the network, the rule is gone, the credential no longer authenticates — and reports it. An unverified row is a row that did not happen. **Have an abort.** Define, in advance, what makes you stop mid-cut: a destructive reaction that changes the priority to recovery, or discovery of a foothold in something the cut would not touch. Without a stated abort, the decision is made under stress by whoever is loudest. ## After the cut Expect a reaction in the final minutes and immediately after: a burst of exfiltration, an attempt to re-enter through a path you did not know about, or nothing at all. Measure what you can — volume out during the window, authentication attempts against the revoked identities, connections to the removed channel — because those attempts are the clearest evidence of what they still had. Then the watch begins, and containment is not eradication: persistence removal and the argument that no path back remains are separate work. ## The failure everyone has seen One region misses T-0. The wrong instinct is to halt everything and reschedule, which leaves two regions cut and one live — the worst of both worlds, since the adversary now knows and still has a home. The right call is to proceed, isolate the failed region at the network boundary as a blunt substitute, and treat it as compromised until its rows are complete.
- What is your stopping rule for enumeration, given you can never prove the list is complete?The loss rate against the expected yield of more hunting. While damage is low and the adversary is unaware, another day of enumeration usually buys more than it costs. Once loss is accruing quickly, or you find evidence they have noticed, the balance flips and you cut with the list you have, carrying an explicit hypothesis that a foothold remains and a watch designed to catch it.
- One region cannot execute its rows at T-0. Do you halt the operation?No. Halting leaves two regions cut and one live, which is the worst outcome: the adversary is warned and still has a home. Proceed everywhere else, apply the bluntest available substitute in the failing region — isolate it at the network boundary — and treat it as compromised until its rows complete and are verified.
- Why capture the appliance's state before reflashing it, when reflashing is the remediation?Because the remediation destroys the evidence. The implant, its configuration and its volatile state exist only on that device; once the image is replaced, the proof that it was there, what it did and when it was installed goes with it. You need that to size the intrusion, to build detections for the same behaviour elsewhere, and to defend the claim later. Capture is a numbered step in the cut list, not an optional extra.
- How do you tell whether the cut worked in the first hour?By verification per row plus watching for the reaction. Each owner confirms their step: the device is unreachable, the rule is absent, the credential fails. Then you watch the paths you just closed — connection attempts to the removed channel, authentications with revoked credentials, new rule creation in the mail platform. Attempts are expected and are evidence; silence in the first hour is not yet proof of anything.
A synchronised arrest across three cities: rehearsal, one radio clock and simultaneous doors, because the first knock warns everyone else.
saying these in an interview costs you the question
- Cuts one foothold now and schedules the other for later
- Plans to manage the appliance over the VPN being taken down
- Reflashes or rebuilds before capturing any evidence
- Halts the whole cut when one region falls behind
- Treats a completed cut as eradication with no watch after