Your entry-point list is ranked by internet exposure — what does that ranking miss?
answer
- reachability is only one axis
- rare does not mean low risk
- ask what it can do afterwards
- would you know who used it
- the emergency path that skips SSO
basics
~20 sExposure is only one axis. The others are privilege — what the path can do once used — and attribution: whether a use binds to a person and would be noticed. A rarely used break-glass admin route can outrank a public form.
solid answer
~50 sRanking by reachability alone assumes the anonymous internet attacker is the only adversary that matters. Rank on three axes instead: how reachable the path is, how much privilege it carries once used, and how well its use is attributed and monitored. The clearest case is a break-glass administrative path in an incident runbook. It is reachable only from a bastion, it is used perhaps twice a year, and by design it bypasses SSO and MFA so that responders can get in when identity is the thing that is broken. It grants full production rights, and it authenticates with a shared credential, so a misuse traces to a team rather than a person. Low exposure, maximum privilege, near-zero attribution — that belongs at the top of the list, above the public claim form, and the adversary you are modelling there is a compromised or coerced operator, not an anonymous stranger.
go deeper
Know that entry points are not equal and that a ranking exists. Be able to say that a path granting administrative rights matters more than one that returns a public page.
Explain the axes and how they interact: reachability, what the path can do once used, and whether its use is attributed. Show why the axes often pull in opposite directions.
Expect to defend a ranking out loud on a whiteboard, naming the adversary and the asset per row, and to place an emergency or administrative path correctly without being led there.
Own how the organisation spends threat-modelling attention: what the ranking is allowed to decide, what it must not be read as, and how emergency access is designed so it stops dominating every model.
## Why the list needs an order at all A finished entry-point inventory for a real system runs to dozens of rows. You cannot threat-model all of them at equal depth, so the ranking is the decision about where the exercise spends its time. Getting the ranking wrong does not just misprioritise fixes; it means the deepest analysis is aimed at the wrong door. ## The three axes **Exposure — who can reach it.** This is a ladder, not a boolean: anyone on the internet, any authenticated user of the product, any tenant with a paid account, an employee on the corporate network, another workload holding a service credential, an operator on a bastion, someone with physical access. Most teams rank on this axis alone because it is the easiest to read off a network diagram. **Privilege — what the path can do once used.** Read one record belonging to the caller, read any tenant's records, mutate a balance, change an authorization rule, or obtain a shell in production. Privilege is the axis that decides how bad the outcome is, and it is often inversely correlated with exposure: the paths that fewest people can reach are frequently the ones that can do the most. **Attribution and monitoring — would you know who did it, and would you notice.** Does the path bind to an individual identity, is each use logged, is the log outside the reach of whoever used the path, and would an unexpected use raise an alert? A path that grants a lot but records nothing is worse than the same path with per-use approval and alerting, and this axis is what most rankings omit entirely. ## The worked case: a break-glass path An incident runbook contains an emergency access procedure. It exists for a good reason — if the identity provider is the outage, an SSO-gated admin console is useless — so it deliberately bypasses SSO and MFA, and the credential lives in a vault the on-call team can open. Scored on the three axes: exposure is low (bastion only, a handful of people); privilege is maximal (full production rights, including the ability to change the very controls that constrain other paths); attribution is weak (a shared credential means a misuse traces to the on-call rota, not a person). The adversary here is a compromised, phished or coerced operator, or anyone who obtains the vault entry. The assets are credentials and, importantly, **audit truth** — a path that can alter or delete records of its own use attacks the evidence, not just the data. That combination puts it at or near the top of the ranking, ahead of the public claim form, even though the form takes millions of requests and the break-glass path takes two a year. A ranking that cannot express this outcome is not measuring the right things. ## Failure modes in ranking - **Ranking by traffic volume.** Volume measures usage, not consequence. It systematically buries the administrative paths. - **Treating network position as a control.** "Internal only" is a statement about the current network, not about the adversary. Once you model a compromised operator, a malicious insider or a compromised workload, internal placement stops helping. - **Ranking by recency of change.** Recently touched code is a fine input to code review, but an untouched high-privilege path is not safer for being old — it is less reviewed. - **Collapsing to one number silently.** A single score with no statement of what dominated it cannot be argued with, and interviewers will push exactly there. - **Ranking paths instead of relationships.** Two routes with identical reach and rights are one row; the one route exempt from the shared authentication is its own row at a different rank. ## Defending a rank A rank is a claim, and senior interviews ask you to defend it out loud. The defensible form names the adversary and the asset: "I put the break-glass path above the public form because the adversary there is a compromised operator, the asset is production credentials and the audit record itself, and nothing on that path binds a use to a person. The form is reachable by everyone, but a successful abuse of it yields one claimant's data and is fully logged." That sentence survives challenge; "it scored 8.5" does not. It also tells you what would change the rank. Privilege drops if the emergency path grants a scoped role rather than everything. Attribution improves if each responder has an individual emergency identity, if the use requires a second approver, and if the resulting alert goes somewhere the user of the path cannot suppress. Those are changes to the axes; adding a control that leaves privilege and attribution untouched leaves the rank where it was. ## What the ranking is for Be clear that the output is *attention*, not a fix list. The top of the ranking is where you draw the boundary most carefully, where you analyse threats in the most depth, and where you insist on evidence rather than assurances. The bottom of the list is not declared safe; it is declared cheap to be wrong about this quarter.
- How does a service-to-service entry point authenticated by a workload credential rank?Rank it on the rights that credential holds, not on its network position. Internal callers are routinely granted broad access because the call is 'internal', which puts privilege high while exposure looks low. And exposure is not really low: a compromised dependency or build system inside the calling service inherits the credential and speaks on that path.
- Does adding MFA to the break-glass path move it down the ranking?Only partly, and it may not be available — the path exists for outages where identity is broken. What genuinely moves the rank is reducing privilege to a scoped emergency role, replacing the shared credential with individual emergency identities, requiring a second approver, and alerting to a destination the user of the path cannot suppress. Those change the axes; a bolted-on check does not.
- How do you present the ranking to a team that disagrees with the top entry?State the axes explicitly and name the adversary and asset at each contested row. Disagreement then localises: they think privilege is narrower than you do, or that a use would be noticed. Both are checkable claims about the system, which converts an argument about scores into a question someone can go and answer.
The master key kept in a sealed envelope is used twice a year and hangs behind two locked doors, and it still opens every room in the building.
saying these in an interview costs you the question
- Ranks purely by whether the path faces the internet
- Treats a rarely used path as automatically low risk
- Ignores what the path can do once someone is on it
- Calls internal network placement a security control
- Ranks by request volume or by how recently code changed
- Gives a single score without saying what dominated it