skip to content

A Boundary's Worth

A zone boundary stops reachability, not an intruder holding a working account, it stops nothing that never crosses it, and it may not be on the traffic path. Interviewers hear what it does not buy.

on this pageshow

explore

questions

20

A zone diagram shows a firewall between two subnets that traffic no longer traverses - what does an intruder gain, and what has to move?

level: juniorimportance: must knowfreq 64%

answer

  1. a drawing is not in the forwarding path
  2. routing decides reachability, not the diagram
  3. a filter never asked logs nothing
  4. enforcement moves on a change night

basics

~20 s

A diagram is a claim, not a control. If routing carries the traffic around the firewall, an intruder crossing between those subnets meets no filter at all. Only moving the enforcement point onto the real path fixes it, and that costs a change window.

solid answer

~50 s

The intruder gains a path with no policy on it. They never read the drawing; they follow the forwarding decision the fabric makes hop by hop, and if a newer path - a second pod, a stretched overlay segment, a direct interconnect built after an acquisition - reaches the same destination without transiting that device, the rules on the device are simply not evaluated. So the answer to "is the zone enforced" is a question about the path, not about the rule base. Fixing it means the packets have to have no way round: either the enforcement point is placed where every path between the two zones already converges, or the routing is changed so they converge on it. Both are change-window work with an owner and a rollback, and often a re-addressing problem underneath. Redrawing the diagram to match reality changes nothing an attacker experiences.

go deeper

for a junior

Be ready to say plainly that a diagram is an intention and the routing is the reality, and that a filter which is never on the path filters nothing.

for a middle

Explain the concrete ways a path appears that the diagram never showed - a new pod, a stretched overlay segment, an interconnect built after a merger - and why none of them raise an alarm.

for a senior

Show that you would treat 'is it enforced' as a path question first, and that you can name what relocating enforcement costs: a path change, a policy translation, flow discovery, a window and a rollback.

for a principal

Own the framing that segmentation is a claim your organisation makes to auditors, customers and its own board, and that the claim is only as good as the last time somebody reconciled it with the forwarding path.

## What a zone diagram actually asserts A zone diagram asserts *intent*: these two groups of systems are meant to be separated, and this box is meant to be the thing that separates them. It is an architectural claim made by people. It is not consulted by any packet. What is consulted by a packet is the forwarding state of every device between source and destination: routing tables, the fabric's overlay mappings, the switching decision inside a hypervisor, a route learned over an interconnect. If that chain never includes the device holding the policy, the policy has no effect on the traffic. A rule base that is not on the path is documentation with a CLI. | The diagram asserts | What actually decides | | --- | --- | | Zone A and Zone B are separated by a filter | Whether every path from A to B transits the filtering device | | The rule base is the policy between the zones | Which device makes the forwarding decision for that address pair | | The boundary is where the drawing puts it | The boundary is wherever packets have no way round | ## Why the drawing and the network drift apart Zone models are drawn once and the estate keeps growing. The characteristic case is a merged estate a year after an acquisition: two address plans, two zone diagrams, two of everything shared, and a fabric built in a hurry so the two sides can talk. That fabric is a path nobody drew. The same thing happens without an acquisition - a second leaf-spine pod stood up for capacity, a segment stretched across an overlay so a workload could move without changing address, a direct interconnect added for a latency-sensitive integration. Each is a legitimate engineering decision, and each can reach the destination without traversing the routed aggregation boundary that was cut between the two zones years ago. Nobody experiences this as a failure. The applications work. The diagram still hangs in the wiki. Nothing alerts, because a filter that is never asked a question logs no denies. ## What the intruder gains An intruder who has landed anywhere in Zone A and wants Zone B does not need to defeat the filter, evade a signature, or find a permitted flow to ride. They need reachability, and reachability is exactly what the unmapped path hands them. The whole value of the boundary - that it subtracts destinations - is gone for every pair that path serves. Worse for the defender, the gap is invisible in the place a defender would look: the firewall's logs are quiet, and quiet reads like healthy. Be precise about the direction of the claim in an interview. A quiet rule base proves that the device was not asked, not that nothing crossed. A green architecture review proves that the drawing was reviewed, not that traffic obeyed it. ## What it costs to make it true again This is the part candidates skip, and it is what the question is really testing. Making the boundary true is not an edit; it is one or more of: - **A path change** - withdraw or re-scope the routes that let traffic bypass, so the pair converges on the enforcement point. That changes the traffic path of live applications. - **A policy move** - the rule set has to exist at the new enforcement point, translated to that device's interfaces and to whatever addressing is really in use on both sides. - **A discovery step** - you cannot write the permit set from the old rule base alone, because the old rule base only ever saw the flows that transited it. - **Sometimes re-addressing** - two merged estates with overlapping ranges cannot be filtered on address until one side moves, which is a project, not a night. Every one of those needs a maintenance window, a change owner who will be on the call when something breaks, and a rollback. That is the real price of a boundary: not the appliance, but the sequence of nights in which the estate has to keep working while enforcement is relocated. ## The line to say out loud "A boundary is real only where the packets have no other way round it." Everything else - the drawing, the rule base, the review - is a claim about a boundary, and claims are what get inherited from the last architect.

  • Someone proposes updating the diagram to match how traffic really flows. Is that remediation?
    No. It is honest documentation, and it is worth doing, but it removes no reachability. After the redraw the intruder has exactly the same unfiltered path they had before. Remediation is the enforcement point moving onto that path, with the change windows and rollback that implies. Treating the redraw as the fix is how a known gap gets closed on a tracker while staying open on the wire.
  • You copy the old rule set onto a device on the new path. Is the zone now enforced?
    Only if that device is on every path between the two zones, including the overlay and any interconnect, and only if the rules were translated to the addressing actually in use on both sides. A partial move leaves a bypass, and a bypass is the whole gap. Also expect the copied rule set to be incomplete: it only ever saw flows that transited the old device.
  • The firewall's deny counters are at zero for that zone pair. What does that tell you?
    Almost nothing on its own. Zero denies is equally consistent with a well-behaved estate, with a permit rule matching everything first, and with no traffic ever reaching the device. It is a prompt to check whether the device sees the pair at all, not evidence that the boundary held.

A floor plan showing a locked door between two wings does not lock anything. If someone cut a corridor between them last year, the door is still locked and completely irrelevant.

saying these in an interview costs you the question

  • Treats the architecture diagram as evidence that traffic is filtered
  • Says updating the documentation closes the gap
  • Assumes a device in the path on paper is in the path in the fabric
  • Reads a quiet rule base as proof nothing crossed
  • Ignores that moving enforcement needs an outage window and an owner

context

open as a page

Why is a firewall rule export not evidence that a segment boundary actually denies traffic?

level: juniorimportance: must knowfreq 55%

basics

~20 s

A rule export shows intent, not effect. It cannot show whether the traffic ever reaches that device, whether an earlier or later rule matches first, or whether the device is in the path at all. Only traffic originated from inside the segment produces an outcome.

open as a page

An intruder pivots between two PCs on one flat office VLAN - why does the perimeter firewall log nothing, and what would have to change first?

level: juniorimportance: must knowfreq 72%

basics

~20 s

Two hosts in the same subnet talk directly through the switch and never reach the default gateway, so a border firewall is simply not on that path and records nothing. Only splitting them into separately routed subnets puts a device in the way.

open as a page

Microsegmentation cut hundreds of real flows: what does it still not remove from an intruder on a valid session?

level: juniorimportance: must knowfreq 62%

basics

~10 s

It removes destinations, not authority. An intruder driving a working, authenticated session keeps every permission that account already held; segmentation only shortens the list of places the account can be used from.

open as a page

An intruder gets a session on your firewall's management console — what does that let them do that evading the firewall never would?

level: juniorimportance: must knowfreq 62%

basics

~20 s

They rewrite the policy instead of slipping past it. A permit they add is enforced as legitimate, the traffic that follows looks authorised in every downstream record, and the device's local change log is theirs to edit too.

open as a page

How does subnetting a flat office VLAN create an interior chokepoint against an intruder, and what does that new hop cost?

level: middleimportance: must knowfreq 58%

basics

~20 s

Splitting one subnet into several forces traffic between them to a default gateway, and a policy applied at that routed hop is the first thing an intruder's lateral movement must cross. The cost is hairpinned traffic, added latency, a new failure domain and full re-addressing.

open as a page

Your zone firewall exports no flow for a busy subnet pair - how do you tell a bypass an intruder can use from missing collection before booking a window?

level: middleimportance: should knowfreq 46%

basics

~20 s

Absence of flow records is ambiguous: it means the device never saw the traffic, or that export was never configured, sampled it away, or dropped it. Confirm the forwarding path itself before you claim a bypass, because the claim buys an outage window somebody has to authorise.

open as a page

Your segmentation probe to another segment times out - what different situations does that one result hide?

level: middleimportance: should knowfreq 46%

basics

~20 s

A timeout proves only that no reply came back. It covers a filter silently discarding the packet, the packet never reaching the enforcing device at all, and the packet arriving at a destination that was off or not listening while the reply was dropped. A pass and a broken probe look identical.

open as a page

What does a host policy agent distinguish about an intruder's session that a segment boundary cannot, and what does it cost to run?

level: middleimportance: should knowfreq 47%

basics

~20 s

On the wire the session is just an allowed address pair; on the workload an agent can tie the rule to the process that opened it. It still cannot see who drives that process, and it must run everywhere.

open as a page

Your firewall, sensor and access-control consoles authenticate admins against the same corporate directory as email — what does an intruder holding one group membership reach?

level: middleimportance: should knowfreq 50%

basics

~20 s

Everything those consoles trust. Device-administration AAA hands the logon decision to the directory, so one account in the right group is an administrator on the firewall, the sensor and the access-control policy at the same time.

open as a page

How do you order the change windows to move a zone's enforcement onto the real traffic path, when an intruder keeps the unfiltered path until the last one?

level: seniorimportance: should knowfreq 44%

basics

~20 s

Observe first, then move in the smallest reversible steps: build the permit set from real flows over a full business cycle, separate the routing change from the policy change, cut one zone pair or direction per night with a written rollback and a named owner, and accept that the gap stays open, with a dated end, until the last step.

open as a page

Your segmentation matrix has twelve zones and you can probe only a slice of the pairs - which?

level: seniorimportance: should knowfreq 37%

basics

~20 s

Measure directed pairs, not zones: twelve zones give 132 ordered source-to-destination pairs before you count services. Spend the budget on low-trust sources into high-value destinations, on pairs whose denial is an actual control claim, and on pairs a change touched - and show every untested pair as unknown.

open as a page

After a segmentation rollout, how far can an intruder on a valid session still reach, counting every exception you left open?

level: seniorimportance: should knowfreq 41%

basics

~20 s

Compute it as a closure, not a feeling. From the compromised origin list every allow entry still matching it, exceptions included, then repeat from each destination reached. The answer is that set times the account's rights.

open as a page

One NOC seat reaches the firewall and sensor consoles of forty client estates — what does an intruder on that seat rewrite, and what does separating the seats cost?

level: seniorimportance: should knowfreq 38%

basics

~20 s

Forty policies, from one seat. A shared management plane collapses forty boundaries into one, and each rewrite arrives at the client as an authorised provider change. Separating the seats spends exactly the efficiency that justified sharing them.

open as a page

You place a probe host in four hundred branch segments - what have you just built for an intruder?

level: seniorimportance: nice to knowfreq 24%

basics

~20 s

A fleet whose declared purpose is to originate cross-segment traffic, present in every low-trust segment, centrally managed across your own boundaries, holding a map of which pairs should be open, and deliberately excluded from alerting. Design it to be worthless when captured: no credentials, outbound-only management, and narrow suppression.

open as a page

An executive reads empty border firewall logs after an internal intrusion as proof the controls held - how do you answer, and what would have to be in the path before a record could exist?

level: seniorimportance: nice to knowfreq 30%

basics

~20 s

Empty border logs prove only that the traffic did not cross the border. A control that is not on the path produces no evidence in either direction. A record of interior movement exists only once you fund a routed hop and a device that inspects it.

open as a page

Your segmentation diagram backs a customer contract, but an intruder would meet no filter on the real path - what do you do, and who signs for it?

level: principalimportance: nice to knowfreq 32%

basics

~20 s

Separate three problems: an unenforced boundary, an assertion already made to a third party, and a remediation nobody has funded. The technical gap gets compensating controls and a dated plan; the assertion is a legal and contractual question that is not the network team's to sit on; the outage windows belong to business owners who can refuse them.

open as a page

Application owners refuse to sever a batch flow an intruder would also use: how do you decide, and who accepts the residual?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Turn the refusal into a priced choice. Show how many destinations that single flow keeps reachable, offer narrowed versions instead of all or nothing, and if the owner still refuses, write the residual reach down and have them accept it by name.

open as a page

You want the firewalls reachable only from an out-of-band management path — who signs that nobody can reach them when that path fails?

level: principalimportance: nice to knowfreq 26%

basics

~20 s

The owner of the service whose availability the outage would hit, not the security team. A path that alone reaches the controls means its failure blocks every fix, so that risk needs a named owner's written acceptance and a tested break-glass.

open as a page