A business owner refuses a fleet-wide block on disk-image attachments. Which control class removes this loader chain instead?
answer
- list the preconditions before naming a control
- no vulnerability appears on that list
- the wrapper is their cheapest input to change
- scope it, do not fleet-wide it
- every exception needs an owner and an expiry
basics
~20 sWork from the chain's preconditions and pick the one whose exception list has a willing owner. Application control removes the final precondition whatever the container, but it is a programme measured in quarters, so scope the narrow blocks meanwhile.
solid answer
~50 sChoose from the chain's preconditions, and choose the one whose exception list has an owner. The chain needs four things: a container that reaches a person without the internet-zone marking following the payload inside, a person who runs the file, a reachable staging server, and permission for the fetched code to execute. Removing any one ends it. Application control — only approved code runs — removes the last precondition regardless of container and is the strongest option, but it is an inventory-and-exception programme measured in quarters, not a change window. Meanwhile, scope the container block to the population that does not need it rather than the whole fleet, remove standard users' ability to mount image files, and give the refusing owner a named, expiring exception they sign for. Restricting egress is weakest: that address is the cheapest thing the operator can change.
go deeper
Know that this chain needs a container, a person who runs the file, a reachable server and permission for the fetched code to execute — and that blocking one file type only removes today's container.
Explain each control class against the precondition it removes, and say why blocking a format is temporary while controlling what may execute is not.
Show that you would scope rather than fleet-wide, sequence the cheap control ahead of the expensive one, and state the residual exposure the scoping leaves behind.
Own the negotiation: who signs for the exception, how it expires, how the holding action is prevented from being recorded as closure, and how you get an execution-control programme funded on the strength of this chain.
## Start from preconditions, not from the format The instinct is to argue about the file type. The better move is to write down what the chain needs and price each removal, because the argument with the business owner is then about a specific cost rather than about your judgement. A split-delivery chain needs all four of: 1. **A container reaches a person**, and it is one whose payload does not inherit the internet-origin marking. 2. **A person runs the file inside it.** 3. **The first stage reaches its staging server** and is judged a match. 4. **The fetched capability is permitted to execute.** No software vulnerability appears anywhere on that list. "We are fully patched" is not an answer to this technique, and saying so early usually reframes the conversation productively. ## The control classes, and what each actually costs **Blocking the container format at the boundary (precondition 1).** Cheap, immediate, and narrow. It removes today's wrapper, and the operator answers by choosing another one — this has already happened several times as marking propagation was closed off in one format after another. Its real cost is not technical: it is a permanent exception list with no natural owner, growing by one entry every time someone's supplier sends something unusual. **Removing the ability to mount image files for standard users (precondition 1, differently).** Middle cost, considerably more durable than a boundary block on one file type, because it removes the capability wherever the file arrived from. Breaks a genuinely small set of workflows. **Changing what a person can be asked to run (precondition 2).** This is training and process, it never reaches zero, and pretending otherwise is how organisations end up with a control strategy that blames the recipient. Useful as a supporting measure and never as the load-bearing one. **Restricting where hosts may fetch from (precondition 3).** The weakest of the four in this chain, because the staging address is the operator's cheapest input to change. It has value for other reasons; it is not the thing that ends this. **Application control (precondition 4).** Only approved code executes. This is the precondition-complete answer: no container can launder an approval that was never granted, and the capability arriving on disk changes nothing if it cannot run. It is also, honestly, the expensive one — an inventory of what the estate actually runs, an exception process, a rollout that must not brick the finance team's ancient reporting tool, and a change in who is allowed to install software. Quarters, not weeks. ## The judgment the question is really asking for You cannot buy the whole precondition set at once, so the decision is about sequencing under a constraint you do not control. Three principles hold up in front of a refusing owner: - **Scope beats fleet-wide.** A block that applies to the ninety-five per cent who never receive image containers, with the exempt group named and enumerated, gets agreement where a fleet-wide block gets a veto. It also converts a policy argument into a much smaller one about who is in the exempt group. - **Every exception has a named owner and an expiry.** The owner who refuses the block should sign for the exception, in their name, with a review date. This is not bureaucracy for its own sake — it is the mechanism by which the exception list stops growing, and it moves the risk to the person who is actually accepting it. - **The cheap control buys time for the expensive one.** Say out loud that the container block is a holding action with a known bypass, and that the durable answer is deciding what may execute. Otherwise the cheap control gets recorded as the solution and the programme is never funded. ## What you concede, and say so Be explicit about residual exposure, because a control decision presented as complete is the one that gets you criticised later. With a scoped block and an exempt group, the chain still completes for anyone in that group. Your compensating position is that the group is small, enumerated and known, that its members are the ones you would prioritise for application control first, and that the exemption expires by default rather than by decision. ## The claim to avoid making Do not tell anyone the campaign is over because the wrapper is blocked. The first stage is priced to be burned and the wrapper is the cheapest thing in the chain to replace; the operator's response to a format block is a different format, at a cost to them of approximately one afternoon. Only the fourth precondition — what is allowed to run — is expensive for them to defeat, and that is why it is the one worth spending a programme on.
- Why is restricting egress to the staging server the weakest of these options?Because that address is the cheapest thing in the chain for the operator to replace — new infrastructure per campaign is already routine, and staging traffic is shaped to look like ordinary web traffic to ordinary hosting. It has value for other reasons, but as the load-bearing control against split delivery it buys the least durable time.
- How do you stop the container-format block being recorded as the solution?State its known bypass in the same sentence you propose it, and record it as a holding action with a review date rather than as closure. Pair the decision with the funded next step so the durable control has a start date. A control accepted without its limitation written down is one nobody revisits.
- What do you tell the owner who refuses the block?That you are not overriding them: their group is exempt, enumerated and signed for in their name, with an expiry. That the exemption means the chain still completes for their people, which is a risk they are accepting rather than one you are absorbing. And that their group goes first when execution control lands, because they are the residual exposure.
saying these in an interview costs you the question
- Names a file-type block as the durable answer
- Argues the estate is safe because it is fully patched
- Proposes application control with no account of its rollout cost
- Leaves an exception with no named owner or expiry
- Reports the campaign as closed once the wrapper is blocked