skip to content

The Universal Allow-List

Default-deny still leaves a short list every segment must reach, and that list is a permitted path from everywhere to a handful of hosts. Interviewers ask what segmentation concentrated.

on this pageshow

questions

4

Every segment is permitted to the same DNS, time, directory and log services and cannot function without them — why does an adversary who takes one of those hosts defeat the segmentation?

level: juniorimportance: must knowfreq 62%

answer

  1. count the rule sets it appears in
  2. a foothold versus a standing grant
  3. you cannot delete the allowance
  4. prerequisites of segmentation, not exceptions to it

basics

~20 s

That permission already exists in every segment's rule set. Segmentation limits who may reach whom, but the shared tier is exempt by design, so owning it hands an adversary an approved path into every segment.

solid answer

~50 s

Segmentation works by making most paths absent, and the universal set is the deliberate hole in that. Resolution, time, directory and log transport are prerequisites for everything else, so every segment's policy carries a permit to the same small destination set. Taking a segment gets an adversary a foothold they still have to expand; taking the universal tier gets them a standing, approved reachability relationship with every segment, plus influence over what those segments do — a resolver picks the next destination, a directory decides whether an authentication succeeds, a collector is where the evidence would have gone. You cannot fix it by deleting the permit; the estate stops. The levers are keeping the set small, splitting the four so one compromise does not yield all of them, and giving that tier the strongest boundary and tightest administration path you own.

go deeper

for a junior

Be ready to name the services every segment must reach and say plainly why a permit that exists in every rule set is different from a path an intruder has to find.

for a middle

Explain the mechanics per service: what controlling resolution, time, directory or log transport actually gives someone, and why clock drift is an authentication problem rather than a reporting one.

for a senior

Show the operating response — splitting the set, minimising membership, a dedicated zone with its own administration path, and a recovery path that does not depend on the tier being recovered.

for a principal

Own the framing that a tier's protection level should follow its reachability rather than its asset value, and be able to defend the funding and change control that follows from it.

## What "the universal set" means When you segment a flat estate, you replace "everything can reach everything" with a policy where most paths simply do not exist. But a handful of services are prerequisites for a machine being usable at all, and they end up permitted from every segment: - **Name resolution.** Almost nothing connects to a literal address any more. If a host cannot resolve, it cannot start. - **Time.** Authentication is time-sensitive: Kerberos rejects tickets outside a configured clock-skew tolerance (commonly five minutes), and certificate validity windows are checked against local time. Drift breaks logins, not just log timestamps. - **Directory / identity.** Authentication and authorisation decisions come from somewhere, and that somewhere is reachable from every segment that has users or services in it. - **Log transport.** If records cannot leave a segment, that segment is unobserved, so the collector or ingest endpoint is reachable from everywhere too. Those four are the set this question is about. In a remote-first estate with no office they are usually subscriptions rather than racks — every "segment" is a home network or a hosted environment, and the universal destination is a provider endpoint — but the topology of the permission is identical. ## The asymmetry Here is the point an interviewer is listening for. **A segment taken is a foothold. The universal tier taken is a permission that already exists.** An adversary who lands in one segment has to find a path outward, and a good segmentation design is exactly the absence of those paths. An adversary who lands on a host in the universal tier does not need a path: every segment's rule base was written, reviewed and approved to permit reaching it. Nothing has to be bypassed. The control did what it was designed to do and the intruder is still adjacent to the whole estate. That is why this tier is segmentation's weakest joint — not because the machines are more valuable, but because their **reachability** is universal by construction. ## What each one actually buys an adversary - **Resolution.** Whoever answers the query chooses the address the client connects to next. This is influence over every subsequent connection in every segment, without ever opening one. - **Time.** Skewing it is a denial capability with estate-wide reach: push clocks outside the tolerance and authentication starts failing everywhere, which looks like an outage rather than an attack. - **Directory.** Identity crosses zone boundaries legitimately. A network segmentation model says nothing about whether an account that is honoured in segment A is also honoured in segment B — it usually is. So an adversary who controls authentication decisions has bypassed the network control without touching it. - **Log transport.** Least immediately powerful, but it is both a host every segment connects to and the destination of the evidence you would use to notice any of the above. Losing it is silent: producers keep running and nothing arrives. ## The price you cannot avoid The honest answer includes what you cannot do. You cannot remove the allowance — the estate depends on it, and "deny it and see what breaks" breaks everything simultaneously. You also cannot make the set arbitrarily small: each of the four is genuinely required. What you can do: 1. **Keep the set minimal and gated.** Every service added to the universal list is a permit written into every segment's policy, forever. Growth is one-way, because removing one later breaks something nobody can name. 2. **Split it.** Four services on one host is one compromise that yields all four. Separate hosts, separate credentials and separate administration turn a single universal grant into four narrower ones. 3. **Give it the strongest boundary you own.** Its own zone, its own administration path, no shared credentials with anything it serves, and change control appropriate to something the whole estate depends on. 4. **Constrain direction and protocol.** Segments reach the tier on specific ports for specific services; the tier itself should have very little reason to originate connections outward, and that outbound is the most useful thing you can watch. 5. **Do not let the tier depend on itself.** A recovery path that requires the directory in order to log in to fix the directory is not a recovery path. ## The framing to say out loud Segmentation's own prerequisites are exempt from segmentation. That is not a design mistake to be corrected; it is a structural property, and the correct response is to treat the universally-reachable tier as the highest-assurance thing in the estate precisely because every segment is already permitted to it.

  • Does splitting the four services across separate hosts actually help?
    Yes, materially. One host running resolution, time, directory and log ingest turns a single compromise into all four capabilities. Separate hosts with separate credentials and separate administration mean taking the time service does not yield authentication decisions. The cost is a larger tier to defend and four universal permits instead of one, so it is a trade rather than a free win.
  • Why argue for keeping the universal set as small as possible?
    Because every addition is a permit written into every segment's policy and a new host with estate-wide reachability. Additions are easy and removals are almost impossible, since nobody can enumerate what depends on the service. Treat a request to add a fifth universal service the way you would treat a firewall exception, with a named owner and a review date.

A building can put a badge reader on every door and still need corridors, lighting and the fire panel to be reachable from every room. Whoever owns the fire panel is already standing in every room's approved path.

saying these in an interview costs you the question

  • Thinks segmentation still contains an intruder who owns a shared service
  • Says the shared tier is safe because it only answers requests
  • Proposes denying the allowance without saying what stops working
  • Argues the tier matters because of the data it holds, not its reachability
  • Treats time sync as a logging nicety rather than an authentication dependency

context

open as a page

Segments may reach the shared resolver, directory and log collector outbound only, and the permit cannot be narrowed — what does an adversary who owns one of those hosts still reach?

level: middleimportance: should knowfreq 48%

basics

~10 s

Everything that asked. A stateful permit carries replies back inside the same connection, so a hostile service answers every client in every segment. Outbound-only constrains who starts the conversation, never who supplies the content.

open as a page

The resolver, directory and time services every segment must reach now sit behind an inspecting chokepoint, added after one segment was compromised — what does that cost you?

level: seniorimportance: should knowfreq 41%

basics

~20 s

It puts one device on every flow in the estate: latency on services that precede every other call, a failure domain wider than any segment, capacity sized for the aggregate, and a fail-open or fail-closed choice where both answers hurt.

open as a page

Every segment is already permitted to your shared identity, resolution and log tier, so an intruder anywhere has a path to it — how do you fund and enforce it as the estate's strongest boundary?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Argue from reachability, not asset value: this is the one tier every segment may already reach, so its blast radius is the whole estate. Buy the change windows, the separate administration path and the evidence with that argument.

open as a page