skip to content

Network Security & Defense

You will learn how networks are actually defended: firewalls and ACLs, intrusion detection and prevention, DDoS mitigation, segmentation and access control, through to zero-trust designs. Interviewers for network and security roles treat this as core canon — nearly every network-engineer loop probes at least firewalls, IDS/IPS, and segmentation.

on this pageshow

explore

questions

271 · 8 sections

In an ordered firewall policy, a broad permit sits above a deny naming the same traffic — what reaches the server, and what does the deny still claim?

level: juniorimportance: must knowfreq 72%
basics
~20 s

The traffic arrives. The earlier permit decides and the deny below it is never evaluated. The deny still sits in the policy, still reads as an enforced control in review and audit, and never logs anything.

open as a page

Why is the wide firewall permit opened at 02:00 to end an outage still an intruder's route in two years later?

level: juniorimportance: must knowfreq 68%
basics
~20 s

An emergency permit survives because nothing removes it: the change was recorded as an outage fix rather than as a permit with an end date and a named owner, and later nobody can prove that deleting the rule is safe.

open as a page

A partner-facing exchange tier terminates inbound sessions but may never open one inward — what does that deny an intruder who lands on it?

level: juniorimportance: must knowfreq 62%
basics
~20 s

It denies them a network path they can start: no socket opened from a tier host reaches an interior service. It does not deny them the tier's own data, or content the interior later collects of its own accord.

open as a page

An egress ACL at your internet edge permits only your own source prefixes: what does it stop, and who benefits?

level: juniorimportance: must knowfreq 58%
basics
~20 s

It stops hosts inside your network from putting forged source addresses onto the internet. The victim of that spoofing is almost always another network, so the filter mostly protects strangers while you pay to keep the prefix list accurate.

open as a page

An intruder pivots between two VMs on one hypervisor: why does the perimeter firewall log nothing, and what does catching that flow cost?

level: juniorimportance: must knowfreq 72%
basics
~20 s

Two guests on one hypervisor exchange packets switched in software inside that host; nothing crosses a wire, so no border device receives them. Blocking that pivot means paying for a filter inside the host — an in-guest agent or a hypervisor firewall.

open as a page

A WAF at a rented edge fronts your public site — what does it stop for an attacker who has the origin's own address?

level: juniorimportance: must knowfreq 70%
basics
~20 s

An edge WAF judges only requests that arrive through the hostname it fronts. An attacker who addresses the origin directly never crosses it, so the honest claim is coverage of one path, not protection of the service.

open as a page

A WAF rule blocking one payload stands in for an unshipped fix — what has it changed about the bug, and what does keeping it cost?

level: juniorimportance: must knowfreq 70%
basics
~20 s

A stopgap WAF rule changes nothing about the bug. The code is still vulnerable; only requests matching that pattern, arriving through that proxy, are stopped. It costs a permanent rule nobody owns and a fix that stops feeling urgent.

open as a page

How does software learn an egress proxy exists, and why is the exception for an agent that cannot be told one useful to an implant?

level: juniorimportance: must knowfreq 65%
basics
~20 s

Software learns a proxy from an operating-system setting, a PAC file located by WPAD, or proxy environment variables. An agent with a hard-coded destination reads none of them, so you write a direct-egress exception every process on that host inherits.

open as a page

Why can a server segment hold an outbound destination allow-list when a user segment never can, and what does that give an intruder?

level: juniorimportance: must knowfreq 62%
basics
~20 s

A server segment talks to a finite, owned set of destinations that changes under change control, so it can be enumerated. A user population needs the whole internet, so no allow-list holds. Malware landing there leaves unblocked.

open as a page

A branch office's filtering DNS resolver blocks a malicious name — what has to be true for that block to apply?

level: juniorimportance: must knowfreq 62%
basics
~20 s

The endpoint has to send that query to your resolver. A filtering resolver is a control the client opts into: a host that asks a different resolver, or ships its own, is never offered the block.

open as a page

A Zeek-style sensor holds state per connection: what does it log about an intruder's session on a protocol no analyzer supports?

level: juniorimportance: must knowfreq 52%
basics
~20 s

Only a connection record - five-tuple, duration, byte counts, connection state - with the service field empty. No protocol facts, no filenames, no hashes, no certificate subjects. A byte-matching engine can still search that same payload for a fixed string.

open as a page

An intrusion rule that has alerted on intruder traffic for months is set to drop - what changes about the cost of a wrong match?

level: juniorimportance: must knowfreq 65%
basics
~20 s

In alert mode a wrong match costs an analyst an hour. Inline, the identical match severs a live session. The rule's accuracy does not change - only who pays for its mistakes, which moves to whoever owns that traffic.

open as a page

When an inline IPS reboots at a single-box branch, what does its bypass relay do, and what does that cost against an intruder?

level: juniorimportance: must knowfreq 58%
basics
~20 s

A hardware bypass relay shorts the two inline ports together when the engine stops, so the branch link keeps carrying packets. You buy availability with inspection: everything in that window, an intruder's traffic included, crosses unjudged.

open as a page

An IDS suppression silences one signature for a scanner's whole /16 — what does an intruder inside that range gain?

level: juniorimportance: must knowfreq 62%
basics
~10 s

A suppression scoped to a /16 blinds the sensor for every host in that range, not just the scanner. Any address inside it can generate the matching traffic and the sensor emits nothing.

open as a page

Your inline IPS reassembles only the first megabyte of each flow to hold its latency budget — what does that give an intruder?

level: juniorimportance: must knowfreq 58%
basics
~20 s

Everything past the first megabyte of that flow leaves uninspected, so an intruder puts the payload behind a benign prefix. The limit exists because deeper reassembly costs buffer memory on every concurrent flow and adds latency.

open as a page

A 200 Gbps flood hits your 10 Gbps uplink: what can a rented scrubbing centre do that your edge firewall cannot?

level: juniorimportance: must knowfreq 72%
basics
~20 s

Nothing at your edge helps, because the transit link is already saturated before packets reach your firewall. A scrubbing provider has far more inbound capacity, absorbs and filters the flood upstream, and forwards only cleaned traffic to you.

open as a page

What does a BGP blackhole announcement for a flooded /32 stop, and what does it finish?

level: juniorimportance: must knowfreq 62%
basics
~20 s

It stops the flood from reaching your access link, because the upstream discards those packets inside its own network. It finishes the outage: every packet to that address is dropped, so legitimate users lose the service too.

open as a page

One address announced from twelve sites absorbs a flood, yet no site's rate threshold fires — why?

level: juniorimportance: must knowfreq 62%
basics
~20 s

Each site sees only its own share of the flood. A per-site threshold is compared against roughly one twelfth of the total, so an attack far above your planning number can stay under every local trigger and never alert anyone.

open as a page

Why does a bits-per-second DDoS threshold never fire when an attacker's 400 search requests a minute exhaust the database pool behind a public API?

level: juniorimportance: must knowfreq 62%
basics
~20 s

Because the threshold and the damage are measured in different units. Four hundred small, well-formed requests are a trivial number of bits and packets; the cost lands as work per request inside the service, which the border never counts.

open as a page

Launch morning traffic is 30x normal: what does the request-rate graph alone prove about who is sending it?

level: juniorimportance: must knowfreq 70%
basics
~20 s

Only that requests arrived. A rate count carries no sender identity, no intent and no outcome. A flood shaped to look like growth and a real launch draw the same curve, which is exactly why an attacker picks that hour.

open as a page

A segment allow-list built from 30 days of observed flows permits an intruder's sessions too - why can the records not tell them apart?

level: juniorimportance: must knowfreq 58%
basics
~20 s

A flow record only says bytes moved between two endpoints on a port. It carries no payload, no user and no purpose, so a compiler turning records into permits cannot separate a designed dependency from an intruder who was present.

open as a page

An infusion pump takes no patch or agent: what still constrains an attacker who lands on it, and what does that cost?

level: juniorimportance: must knowfreq 62%
basics
~20 s

You cannot fix the host, so the only control is what the segment permits it to originate and receive. The price is a standing exception with a named owner and a renewal date, and an intruder who lands there inherits it.

open as a page

All 900 hotel guest rooms sit in one VLAN — what does a compromised laptop there reach without ever crossing the firewall?

level: juniorimportance: must knowfreq 70%
basics
~20 s

Every other host in that VLAN — with three devices a room, roughly 2,700 of them. Traffic between hosts in one broadcast domain is switched, never routed, so the inter-VLAN firewall neither filters nor logs it.

open as a page

Every segment is permitted to the same DNS, time, directory and log services and cannot function without them — why does an adversary who takes one of those hosts defeat the segmentation?

level: juniorimportance: must knowfreq 62%
basics
~20 s

That permission already exists in every segment's rule set. Segmentation limits who may reach whom, but the shared tier is exempt by design, so owning it hands an adversary an approved path into every segment.

open as a page

What does approving one microsegmentation allow rule prove about what an intruder on that workload reaches?

level: juniorimportance: must knowfreq 60%
basics
~20 s

Almost nothing. It proves one named source group may reach one destination on those ports. What an intruder reaches is the union of every allow covering that workload's groups, then the same from each host it lands on.

open as a page

What does MAC authentication bypass prove about a device whose address an attacker can read off the chassis, and what does the allow-list entry cost?

level: juniorimportance: must knowfreq 62%
basics
~20 s

MAC authentication bypass proves only that a frame carrying an allow-listed address reached the port. The address is a printed label, not a secret. Its value is inventory and logging, and each entry is a permanent exception someone must own.

open as a page

Why does 802.1X with PEAP-MSCHAPv2 still admit an attacker holding a password pulled from a stolen laptop image, and what does EAP-TLS cost instead?

level: juniorimportance: must knowfreq 72%
basics
~20 s

PEAP-MSCHAPv2 authenticates a password, and a password travels: whoever holds it authenticates from any laptop. So 802.1X admits a credential, not a device. EAP-TLS binds admission to a per-device key, but every device must be enrolled first.

open as a page

On an 802.1X Wi-Fi SSID, what does server-certificate validation in the client actually stop?

level: juniorimportance: must knowfreq 60%
basics
~20 s

It stops an attacker's radio that beacons your SSID from becoming the server your device authenticates to. Without it the supplicant builds its EAP tunnel to whoever answered and sends the credential exchange inside it.

open as a page

An attacker patches a laptop into an 802.1X access port: what passes before authentication, and what does that cost you?

level: juniorimportance: must knowfreq 62%
basics
~20 s

Only EAPOL. The port's uncontrolled channel carries 802.1X frames; DHCP, ARP and everything else are dropped until authentication authorizes the controlled channel. Anything with no supplicant - imaging, headless kit - therefore sees a dead socket.

open as a page

A visitor left alone in a meeting room plugs into the live wall socket — what does that port hand them, and what does shutting unused ports cost?

level: juniorimportance: must knowfreq 62%
basics
~20 s

A socket that never got admission control hands a stranger a DHCP lease and layer-2 adjacency to everything in that room's VLAN. Shutting unused ports removes that, at the cost of a ticket every time a room is re-cabled.

open as a page

Malware runs on a laptop whose VPN exempts one SaaS range to save head-end capacity - what does network inspection see?

level: juniorimportance: must knowfreq 62%
basics
~10 s

Nothing. Exempted traffic never enters the tunnel, so it never reaches the head-end or anything behind it. An exemption removes the vantage point entirely rather than reducing what gets logged.

open as a page

A remote-access VPN authenticates a user with MFA and hands out a pool address - what does that session then reach?

level: juniorimportance: must knowfreq 78%
basics
~20 s

A tunnel session reaches whatever the routing table and the filters behind the address pool allow, which by default is everything the concentrator can route to. Authentication decides who gets an address; it never decides which destinations that address may open.

open as a page

An intruder inside a partner's network arrives over their site-to-site tunnel — what did that tunnel's authentication prove, and what must you run behind it?

level: juniorimportance: must knowfreq 66%
basics
~20 s

It proves only that the far-end device held the agreed key or certificate — nothing about the hosts behind it. Traffic leaving the tunnel is ordinary unauthenticated traffic, so your side needs its own default-deny filter on the extranet zone.

open as a page

A remote-access concentrator lands its inside leg on the core VLAN — what filters the decrypted traffic?

level: juniorimportance: must knowfreq 68%
basics
~20 s

Nothing except the concentrator itself. ESP is decapsulated at its inside leg, so plaintext appears already on the core and no independent device sees it. Enforcement there means paying for a second filter and a second hop.

open as a page

What does always-on VPN lockdown block, and what is still exposed on the local network?

level: juniorimportance: must knowfreq 64%
basics
~20 s

Lockdown makes the endpoint's own packet filter drop every flow except the tunnel and a few named exceptions. It protects traffic, not the machine: the interface is still on the hostile segment, and whatever the exceptions allow is reachable there.

open as a page

Why does an internal app that trusts corporate-network reachability still serve an intruder, and what does replacing that check cost?

level: juniorimportance: must knowfreq 78%
basics
~20 s

Reachability proves only that a packet arrived from an address the network will route; anything that lands inside inherits it. Replacing it means building the login the app never had - a front door on its host, or a rewrite.

open as a page

An attacker's tunnel outlives the account being disabled: what must an access broker do to end it, and who else gets dropped?

level: juniorimportance: must knowfreq 55%
basics
~20 s

Disabling an account only changes the answer given the next time something asks, and an established flow is never asked again. The broker must hold session state and actively terminate matching sessions, which also drops legitimate users the same rule catches.

open as a page

Zero trust admits a stolen but valid credential on a compliant device - what did the model actually remove?

level: juniorimportance: must knowfreq 72%
basics
~20 s

Zero trust removed network position as evidence, so being inside no longer grants reach. It never claimed to remove credential theft: a real credential on a compliant device is a true input, and every enforcement point downstream will correctly allow it.

open as a page

A compromised laptop's agent reports disk encryption on and EDR running. What did the access gateway actually verify, and what does distrusting it cost?

level: juniorimportance: must knowfreq 60%
basics
~20 s

Only that something holding the device's credential sent a document containing those claims. The values are the endpoint's own word, and an attacker with code on it can write any of them. Distrusting them costs a narrower grant.

open as a page

A zero-trust deny runs at your platform's front gateway — which paths to the same application never touch it?

level: juniorimportance: must knowfreq 62%
basics
~20 s

Usually several: an operator opening a shell inside a running workload, node-level access to the host, the platform's own control API on a management network, workload-to-workload calls that never leave, and outbound batch traffic. A front gateway only sees what routing sends it.

open as a page