skip to content

Starting from Flat

Getting a flat estate segmented: how wide the layer-2 domains stay, how fine a rule set stays reviewable, the hosts nothing can fix, and the shared services every segment must still reach.

on this pageshow

explore

questions

16

An infusion pump takes no patch or agent: what still constrains an attacker who lands on it, and what does that cost?

level: juniorimportance: must knowfreq 62%

answer

  1. nothing can be installed on it
  2. policy written about it, not on it
  3. reach in, originate out - that is all
  4. the permit is inherited on arrival
  5. an exception with an owner and an expiry

basics

~20 s

You cannot fix the host, so the only control is what the segment permits it to originate and receive. The price is a standing exception with a named owner and a renewal date, and an intruder who lands there inherits it.

solid answer

~50 s

Nothing can be installed on the device, so every control has to be written *about* it by the first device upstream: the switch port and the segment boundary. Those can assert two things only, what may reach the pump and what the pump may originate, and that is the whole control surface. Say plainly what it does not do: the unpatched flaw is exactly as exploitable as before, so this is blast-radius reduction, not remediation. It is also inherited. An attacker who gets code running on the pump does not need to escalate or evade anything; every permitted flow is now theirs, from an address that looks expected in the register. And the permit is not free: it is a documented exception with an owner, an expiry and a review, and in a clinical estate that owner usually outranks the network team.

go deeper

for a junior

Be ready to say what is left when patching, agents and credentials are all unavailable: only what the network permits the device to send and receive. Say clearly that this does not fix the vulnerability.

for a middle

Explain the mechanics of the compensating control - default deny, an enumerated per-device permit, and the fact that the boundary sees traffic and not host state. Be able to list what the segment cannot claim.

for a senior

Demonstrate that you plan for the device being compromised: narrow the origination set to the point of boredom, keep evidence that the rest is denied, and know exactly what an intruder inherits from the permit you wrote.

for a principal

Own the exception as a managed object rather than a rule: who renews it, when it expires, how it is enumerated per device, and how it is answered to a regulator or an auditor without using the word segmentation as a substitute for evidence.

## What unpatchable actually means A device is unpatchable when nothing you control can change its state. The vendor ships no fix; or a fix exists but the support contract voids if you apply it yourself; or the platform underneath went end-of-life years before the device was installed; or there is no agent build for it; or the only account is a shared service password printed in the installation manual. In a hospital that describes infusion pumps, imaging modalities and an anaesthesia workstation, each bought as a certified system rather than as a computer. The shape recurs wherever equipment is purchased whole and certified against a regulator. ## Every normal control lives on the host, and none of them are available Patch it, install a sensor, rotate the credential, disable the listening service, enforce a local firewall: all of those act on the host. Here none can be used. What remains is policy written **about** the device by the first device upstream of it - the access port it is plugged into and the boundary between its segment and everything else. That policy can assert exactly two things: - what may reach the device, and - what the device may originate. That is the entire control surface, and stating it that starkly is the point of the question. It forces the honest next sentence: none of it reduces the vulnerability. The pump remains precisely as exploitable as it was. What changed is who can reach the flaw and where an intruder can travel afterwards. ## What the segment can and cannot claim | The segment can | The segment cannot | | --- | --- | | Stop unrelated hosts reaching the device's listening service | Stop its authorised clinical peer reaching it, which is the path that matters | | Stop the device originating flows nobody authorised | Distinguish a legitimate flow from an intruder using the same permit | | Record that bytes moved to a permitted destination | See inside an encrypted session, or produce host telemetry | | Deny by default and produce evidence of the denial | Prove the device is not already compromised | The right-hand column is what a strong candidate volunteers. A weak one says the device is safe because it is segmented, which confuses a reduced reachable set with a fixed defect. ## Inheritance: what an intruder gets for free This is the framing the question exists for. On an ordinary server an attacker must escalate, evade a sensor, steal a credential, and move. On a device everybody agreed never to constrain, the attacker skips all of that. Every flow the exception permits is now theirs, sourced from an address that appears in the register as expected, at hours nobody reviews, from a host that generates no local log you can read. The exception you wrote precisely because the device could not be fixed is the same exception the intruder receives on arrival. That is why the permitted origination set has to be narrow to the point of being boring: one destination, one port, one direction, and a default deny for everything else. ## The price, and who actually pays it The control is not free and interviewers want to hear the bill: - **An exception record per device**, not a blanket one, with what it may originate and why. - **A named owner** who renews it. In a clinical estate that is a clinical-engineering or biomedical department, not the network team, and the counter-argument in the room is patient safety. - **An expiry**, because the failure mode is an exception approved once for a go-live that is still in the rule base a decade later, attached to a device nobody can identify and that nobody dares delete. - **Addressing discipline**, because the permit is keyed to something that must not change. - **Evidence**, because when an auditor or a regulator asks how the risk is managed, the answer is not the word segmentation, it is the enumerated permit list plus proof the boundary denies the rest. ## How to answer this in a loop Three beats: the control moved off the host and onto the segment; the segment constrains reach and origination and does not fix the flaw; the constraint is a standing exception with an owner and an expiry that an intruder inherits intact. A candidate who gives all three has shown they understand both halves - the mechanism and the bill - and they have not pretended the problem was solved.

  • Why is saying the pump is behind a firewall not an answer on its own?
    A boundary permits things. The question is what it permits: the device's allowed flows are also the intruder's allowed flows. Without the enumerated origination list and a default deny behind it, being behind a firewall says only that traffic passes through a box, not that anything is denied.
  • If segmentation does not fix the flaw, what do you tell an auditor who asks how the risk is managed?
    That the risk is not remediated but bounded, and then show the bound: the per-device permit list, the default deny, the evidence that denied attempts are recorded, the exception owner and its renewal date. Naming it a compensating control without producing that evidence is the answer that fails.
  • What makes the origination direction the more important half here?
    Inbound rules limit who can trigger the flaw. Outbound rules limit what the attacker does after they already have. Since you must assume the device can be exploited by anything permitted to reach it, the value of the segment is mostly in the second: an exploited pump that may originate exactly one flow to one destination is a poor position to work from.

You cannot cure the patient, so you control the doors of the ward. The illness is unchanged; what changed is how far it travels.

saying these in an interview costs you the question

  • Says segmentation makes the unpatched device safe
  • Claims the device is fine because it is not internet-facing
  • Assumes an agent or credential can be forced onto it anyway
  • Treats the exception as permanent and nobody's property
  • Forgets the intruder inherits every permitted flow

context

open as a page

All 900 hotel guest rooms sit in one VLAN — what does a compromised laptop there reach without ever crossing the firewall?

level: juniorimportance: must knowfreq 70%

basics

~20 s

Every other host in that VLAN — with three devices a room, roughly 2,700 of them. Traffic between hosts in one broadcast domain is switched, never routed, so the inter-VLAN firewall neither filters nor logs it.

open as a page

Every segment is permitted to the same DNS, time, directory and log services and cannot function without them — why does an adversary who takes one of those hosts defeat the segmentation?

level: juniorimportance: must knowfreq 62%

basics

~20 s

That permission already exists in every segment's rule set. Segmentation limits who may reach whom, but the shared tier is exempt by design, so owning it hands an adversary an approved path into every segment.

open as a page

What does approving one microsegmentation allow rule prove about what an intruder on that workload reaches?

level: juniorimportance: must knowfreq 60%

basics

~20 s

Almost nothing. It proves one named source group may reach one destination on those ports. What an intruder reaches is the union of every allow covering that workload's groups, then the same from each host it lands on.

open as a page

A red team crossed your 40,000-rule microsegmentation policy using only approved allows - how do you recover a set you can state?

level: seniorimportance: must knowfreq 52%

basics

~20 s

Stop trying to read the rules. State a short list of pairs that must never be reachable, compute effective reachability over rule text and current membership, test those invariants on every change, and show reviewers the reach delta.

open as a page

Segment rules for an unpatchable imaging modality are keyed to its fixed IP. How can an attacker inherit that permit?

level: middleimportance: should knowfreq 45%

basics

~20 s

An address-keyed permit trusts a field in the packet, not an identity the device proves, so whoever answers at that address inherits it. Holding the binding true costs static addressing, a hand-kept register and change coordination on every device swap.

open as a page

Private VLAN isolation stops guest-to-guest attacks, yet DHCP still works and casting to the room screen fails — why?

level: middleimportance: should knowfreq 45%

basics

~20 s

An isolated port may exchange frames only with promiscuous ports, where the gateway and the address relay sit — so assignment still completes. Two guest devices are both isolated, so the host-to-host discovery casting depends on is dropped.

open as a page

Segments may reach the shared resolver, directory and log collector outbound only, and the permit cannot be narrowed — what does an adversary who owns one of those hosts still reach?

level: middleimportance: should knowfreq 48%

basics

~10 s

Everything that asked. A stateful permit carries replies back inside the same connection, so a hostile service answers every client in every segment. Outbound-only constrains who starts the conversation, never who supplies the content.

open as a page

How can a workload gain new microsegmentation reach with no rule change and no reviewer seeing it?

level: middleimportance: should knowfreq 46%

basics

~20 s

By joining a group. Policy is written against groups and compiled per virtual NIC, so a tag set by build automation, in a change queue no reviewer watches, grants every existing rule naming that group.

open as a page

A modality vendor demands a standing remote-support path or voids support: how do you grant it, and what does an intruder inherit?

level: seniorimportance: should knowfreq 38%

basics

~20 s

Grant it brokered and time-boxed rather than standing: the vendor terminates on a broker you control, the path opens on request and expires by itself. A permanent permit is a doorway an intruder inherits into the segment holding your widest exceptions.

open as a page

Segmenting a flat 4,000-host site into per-floor VLANs to contain an intruder hairpins east-west traffic through one firewall — what fills first?

level: seniorimportance: should knowfreq 50%

basics

~20 s

Usually the firewall's session table and connection-setup rate, plus an uplink now carrying every flow twice. And you cannot size it from flow records: the traffic you are relocating never crossed a routed hop, so none was ever exported.

open as a page

The resolver, directory and time services every segment must reach now sit behind an inspecting chokepoint, added after one segment was compromised — what does that cost you?

level: seniorimportance: should knowfreq 41%

basics

~20 s

It puts one device on every flow in the estate: latency on services that precede every other call, a failure domain wider than any segment, capacity sized for the aggregate, and a fail-open or fail-closed choice where both answers hurt.

open as a page

Port isolation breaks the shared-screen meeting rooms the venue sells — who decides, and what do you write down?

level: principalimportance: should knowfreq 33%

basics

~20 s

The events business owns the decision, because the revenue is theirs to trade; you own stating the cost accurately. Write a per-room exception with a named owner, an expiry tied to the booking, and what one guest reaches.

open as a page

Clinical engineering asks you to renew a blanket exception for 60 unpatchable devices. What do you sign, refuse or change?

level: principalimportance: nice to knowfreq 28%

basics

~20 s

Refuse the shape rather than the devices. Convert a blanket, indefinite exception into per-device enumerated permits with an expiry and a named owner, and get the residual risk accepted in writing by someone senior enough to accept it.

open as a page

Every segment is already permitted to your shared identity, resolution and log tier, so an intruder anywhere has a path to it — how do you fund and enforce it as the estate's strongest boundary?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Argue from reachability, not asset value: this is the one tier every segment may already reach, so its blast radius is the whole estate. Buy the change windows, the separate administration path and the evidence with that argument.

open as a page

Your change board rubber-stamps 200 microsegmentation approvals a month - what do you ask the funder to buy or give up?

level: principalimportance: nice to knowfreq 34%

basics

~20 s

An intruder's path is assembled from individually approved changes, so rubber-stamping is the failed control. Name the real ceiling - review capacity, not rule count - and make the funder choose: pay for reachability testing, or accept a coarser grain.

open as a page