Network Security & Defense
You will learn how networks are actually defended: firewalls and ACLs, intrusion detection and prevention, DDoS mitigation, segmentation and access control, through to zero-trust designs. Interviewers for network and security roles treat this as core canon — nearly every network-engineer loop probes at least firewalls, IDS/IPS, and segmentation.
on this pageshowhide
explore
- Firewalls & ACLs32 questions
- The Filter's Inputs8 questions
- Choosing the Chokepoint12 questions
- The Ageing Rulebase12 questions
- NGFW & WAF39 questions
- Depth of Inspection16 questions
- Controlling the Exits12 questions
- Judging a Request11 questions
- IDS/IPS40 questions
- The Sensor's Position16 questions
- Expressing a Detection12 questions
- Standing in the Path12 questions
- DDoS Detection & Mitigation28 questions
- State You Never Allocate8 questions
- Somebody Else's Capacity12 questions
- Low-Volume Denial8 questions
- Segmentation & Microsegmentation44 questions
- A Boundary's Worth20 questions
- Rules from Observation8 questions
- Starting from Flat16 questions
- NAC & 802.1X32 questions
- Admitting a Device20 questions
- The Day It Denies12 questions
- VPNs & Encrypted Transport24 questions
- The Tunnel's End16 questions
- An Estate Left Connected8 questions
- Zero Trust Architecture32 questions
- The Model's Claim12 questions
- Somewhere to Enforce12 questions
- Leaving the Perimeter8 questions
questions
271 · 8 sectionsIn an ordered firewall policy, a broad permit sits above a deny naming the same traffic — what reaches the server, and what does the deny still claim?
basics
~20 sThe traffic arrives. The earlier permit decides and the deny below it is never evaluated. The deny still sits in the policy, still reads as an enforced control in review and audit, and never logs anything.
Why is the wide firewall permit opened at 02:00 to end an outage still an intruder's route in two years later?
basics
~20 sAn emergency permit survives because nothing removes it: the change was recorded as an outage fix rather than as a permit with an end date and a named owner, and later nobody can prove that deleting the rule is safe.
A partner-facing exchange tier terminates inbound sessions but may never open one inward — what does that deny an intruder who lands on it?
basics
~20 sIt denies them a network path they can start: no socket opened from a tier host reaches an interior service. It does not deny them the tier's own data, or content the interior later collects of its own accord.
An egress ACL at your internet edge permits only your own source prefixes: what does it stop, and who benefits?
basics
~20 sIt stops hosts inside your network from putting forged source addresses onto the internet. The victim of that spoofing is almost always another network, so the filter mostly protects strangers while you pay to keep the prefix list accurate.
An intruder pivots between two VMs on one hypervisor: why does the perimeter firewall log nothing, and what does catching that flow cost?
basics
~20 sTwo guests on one hypervisor exchange packets switched in software inside that host; nothing crosses a wire, so no border device receives them. Blocking that pivot means paying for a filter inside the host — an in-guest agent or a hypervisor firewall.
A WAF at a rented edge fronts your public site — what does it stop for an attacker who has the origin's own address?
basics
~20 sAn edge WAF judges only requests that arrive through the hostname it fronts. An attacker who addresses the origin directly never crosses it, so the honest claim is coverage of one path, not protection of the service.
A WAF rule blocking one payload stands in for an unshipped fix — what has it changed about the bug, and what does keeping it cost?
basics
~20 sA stopgap WAF rule changes nothing about the bug. The code is still vulnerable; only requests matching that pattern, arriving through that proxy, are stopped. It costs a permanent rule nobody owns and a fix that stops feeling urgent.
How does software learn an egress proxy exists, and why is the exception for an agent that cannot be told one useful to an implant?
basics
~20 sSoftware learns a proxy from an operating-system setting, a PAC file located by WPAD, or proxy environment variables. An agent with a hard-coded destination reads none of them, so you write a direct-egress exception every process on that host inherits.
Why can a server segment hold an outbound destination allow-list when a user segment never can, and what does that give an intruder?
basics
~20 sA server segment talks to a finite, owned set of destinations that changes under change control, so it can be enumerated. A user population needs the whole internet, so no allow-list holds. Malware landing there leaves unblocked.
A branch office's filtering DNS resolver blocks a malicious name — what has to be true for that block to apply?
basics
~20 sThe endpoint has to send that query to your resolver. A filtering resolver is a control the client opts into: a host that asks a different resolver, or ships its own, is never offered the block.
A Zeek-style sensor holds state per connection: what does it log about an intruder's session on a protocol no analyzer supports?
basics
~20 sOnly a connection record - five-tuple, duration, byte counts, connection state - with the service field empty. No protocol facts, no filenames, no hashes, no certificate subjects. A byte-matching engine can still search that same payload for a fixed string.
An intrusion rule that has alerted on intruder traffic for months is set to drop - what changes about the cost of a wrong match?
basics
~20 sIn alert mode a wrong match costs an analyst an hour. Inline, the identical match severs a live session. The rule's accuracy does not change - only who pays for its mistakes, which moves to whoever owns that traffic.
When an inline IPS reboots at a single-box branch, what does its bypass relay do, and what does that cost against an intruder?
basics
~20 sA hardware bypass relay shorts the two inline ports together when the engine stops, so the branch link keeps carrying packets. You buy availability with inspection: everything in that window, an intruder's traffic included, crosses unjudged.
An IDS suppression silences one signature for a scanner's whole /16 — what does an intruder inside that range gain?
basics
~10 sA suppression scoped to a /16 blinds the sensor for every host in that range, not just the scanner. Any address inside it can generate the matching traffic and the sensor emits nothing.
Your inline IPS reassembles only the first megabyte of each flow to hold its latency budget — what does that give an intruder?
basics
~20 sEverything past the first megabyte of that flow leaves uninspected, so an intruder puts the payload behind a benign prefix. The limit exists because deeper reassembly costs buffer memory on every concurrent flow and adds latency.
A 200 Gbps flood hits your 10 Gbps uplink: what can a rented scrubbing centre do that your edge firewall cannot?
basics
~20 sNothing at your edge helps, because the transit link is already saturated before packets reach your firewall. A scrubbing provider has far more inbound capacity, absorbs and filters the flood upstream, and forwards only cleaned traffic to you.
What does a BGP blackhole announcement for a flooded /32 stop, and what does it finish?
basics
~20 sIt stops the flood from reaching your access link, because the upstream discards those packets inside its own network. It finishes the outage: every packet to that address is dropped, so legitimate users lose the service too.
One address announced from twelve sites absorbs a flood, yet no site's rate threshold fires — why?
basics
~20 sEach site sees only its own share of the flood. A per-site threshold is compared against roughly one twelfth of the total, so an attack far above your planning number can stay under every local trigger and never alert anyone.
Why does a bits-per-second DDoS threshold never fire when an attacker's 400 search requests a minute exhaust the database pool behind a public API?
basics
~20 sBecause the threshold and the damage are measured in different units. Four hundred small, well-formed requests are a trivial number of bits and packets; the cost lands as work per request inside the service, which the border never counts.
Launch morning traffic is 30x normal: what does the request-rate graph alone prove about who is sending it?
basics
~20 sOnly that requests arrived. A rate count carries no sender identity, no intent and no outcome. A flood shaped to look like growth and a real launch draw the same curve, which is exactly why an attacker picks that hour.
A segment allow-list built from 30 days of observed flows permits an intruder's sessions too - why can the records not tell them apart?
basics
~20 sA flow record only says bytes moved between two endpoints on a port. It carries no payload, no user and no purpose, so a compiler turning records into permits cannot separate a designed dependency from an intruder who was present.
An infusion pump takes no patch or agent: what still constrains an attacker who lands on it, and what does that cost?
basics
~20 sYou cannot fix the host, so the only control is what the segment permits it to originate and receive. The price is a standing exception with a named owner and a renewal date, and an intruder who lands there inherits it.
All 900 hotel guest rooms sit in one VLAN — what does a compromised laptop there reach without ever crossing the firewall?
basics
~20 sEvery other host in that VLAN — with three devices a room, roughly 2,700 of them. Traffic between hosts in one broadcast domain is switched, never routed, so the inter-VLAN firewall neither filters nor logs it.
Every segment is permitted to the same DNS, time, directory and log services and cannot function without them — why does an adversary who takes one of those hosts defeat the segmentation?
basics
~20 sThat permission already exists in every segment's rule set. Segmentation limits who may reach whom, but the shared tier is exempt by design, so owning it hands an adversary an approved path into every segment.
What does approving one microsegmentation allow rule prove about what an intruder on that workload reaches?
basics
~20 sAlmost nothing. It proves one named source group may reach one destination on those ports. What an intruder reaches is the union of every allow covering that workload's groups, then the same from each host it lands on.
What does MAC authentication bypass prove about a device whose address an attacker can read off the chassis, and what does the allow-list entry cost?
basics
~20 sMAC authentication bypass proves only that a frame carrying an allow-listed address reached the port. The address is a printed label, not a secret. Its value is inventory and logging, and each entry is a permanent exception someone must own.
Why does 802.1X with PEAP-MSCHAPv2 still admit an attacker holding a password pulled from a stolen laptop image, and what does EAP-TLS cost instead?
basics
~20 sPEAP-MSCHAPv2 authenticates a password, and a password travels: whoever holds it authenticates from any laptop. So 802.1X admits a credential, not a device. EAP-TLS binds admission to a per-device key, but every device must be enrolled first.
On an 802.1X Wi-Fi SSID, what does server-certificate validation in the client actually stop?
basics
~20 sIt stops an attacker's radio that beacons your SSID from becoming the server your device authenticates to. Without it the supplicant builds its EAP tunnel to whoever answered and sends the credential exchange inside it.
An attacker patches a laptop into an 802.1X access port: what passes before authentication, and what does that cost you?
basics
~20 sOnly EAPOL. The port's uncontrolled channel carries 802.1X frames; DHCP, ARP and everything else are dropped until authentication authorizes the controlled channel. Anything with no supplicant - imaging, headless kit - therefore sees a dead socket.
A visitor left alone in a meeting room plugs into the live wall socket — what does that port hand them, and what does shutting unused ports cost?
basics
~20 sA socket that never got admission control hands a stranger a DHCP lease and layer-2 adjacency to everything in that room's VLAN. Shutting unused ports removes that, at the cost of a ticket every time a room is re-cabled.
Malware runs on a laptop whose VPN exempts one SaaS range to save head-end capacity - what does network inspection see?
basics
~10 sNothing. Exempted traffic never enters the tunnel, so it never reaches the head-end or anything behind it. An exemption removes the vantage point entirely rather than reducing what gets logged.
A remote-access VPN authenticates a user with MFA and hands out a pool address - what does that session then reach?
basics
~20 sA tunnel session reaches whatever the routing table and the filters behind the address pool allow, which by default is everything the concentrator can route to. Authentication decides who gets an address; it never decides which destinations that address may open.
An intruder inside a partner's network arrives over their site-to-site tunnel — what did that tunnel's authentication prove, and what must you run behind it?
basics
~20 sIt proves only that the far-end device held the agreed key or certificate — nothing about the hosts behind it. Traffic leaving the tunnel is ordinary unauthenticated traffic, so your side needs its own default-deny filter on the extranet zone.
A remote-access concentrator lands its inside leg on the core VLAN — what filters the decrypted traffic?
basics
~20 sNothing except the concentrator itself. ESP is decapsulated at its inside leg, so plaintext appears already on the core and no independent device sees it. Enforcement there means paying for a second filter and a second hop.
What does always-on VPN lockdown block, and what is still exposed on the local network?
basics
~20 sLockdown makes the endpoint's own packet filter drop every flow except the tunnel and a few named exceptions. It protects traffic, not the machine: the interface is still on the hostile segment, and whatever the exceptions allow is reachable there.
Why does an internal app that trusts corporate-network reachability still serve an intruder, and what does replacing that check cost?
basics
~20 sReachability proves only that a packet arrived from an address the network will route; anything that lands inside inherits it. Replacing it means building the login the app never had - a front door on its host, or a rewrite.
An attacker's tunnel outlives the account being disabled: what must an access broker do to end it, and who else gets dropped?
basics
~20 sDisabling an account only changes the answer given the next time something asks, and an established flow is never asked again. The broker must hold session state and actively terminate matching sessions, which also drops legitimate users the same rule catches.
Zero trust admits a stolen but valid credential on a compliant device - what did the model actually remove?
basics
~20 sZero trust removed network position as evidence, so being inside no longer grants reach. It never claimed to remove credential theft: a real credential on a compliant device is a true input, and every enforcement point downstream will correctly allow it.
A compromised laptop's agent reports disk encryption on and EDR running. What did the access gateway actually verify, and what does distrusting it cost?
basics
~20 sOnly that something holding the device's credential sent a document containing those claims. The values are the endpoint's own word, and an attacker with code on it can write any of them. Distrusting them costs a narrower grant.
A zero-trust deny runs at your platform's front gateway — which paths to the same application never touch it?
basics
~20 sUsually several: an operator opening a shell inside a running workload, node-level access to the host, the platform's own control API on a management network, workload-to-workload calls that never leave, and outbound batch traffic. A front gateway only sees what routing sends it.