Segmentation & Microsegmentation
You will learn how to carve a network into zones — VLANs, DMZs, private VLANs — and how microsegmentation extends that to per-workload east-west policy with security groups. Interviewers probe it with 'design a network for X' questions, since segmentation is the primary blast-radius control after a breach.
on this pageshowhide
explore
- A Boundary's Worth20 questions
- Reach Removed, Rights Kept4 questions
- The Traffic Inside4 questions
- Zones No Longer True4 questions
- Consoles Above the Controls4 questions
- Evidence It Denies4 questions
- Rules from Observation8 questions
- The Allow-List Learns Everything4 questions
- Labels Instead of Addresses4 questions
- Starting from Flat16 questions
- Splitting the Broadcast Domain4 questions
- Policy Nobody Can Read4 questions
- The Universal Allow-List4 questions
- The Unpatchable Population4 questions
questions
page 2 of 2You must size an interior firewall for east-west campus traffic an intruder would have to cross - why is the internet link's bandwidth the wrong number?
basics
~20 sNorth-south volume is shaped by a purchased circuit; east-west is LAN traffic at switch speed - backups, imaging, file shares - and it is usually far larger and burstier. Size on measured crossing traffic, new connections per second and session count, not on the internet pipe.
After a segmentation rollout, how far can an intruder on a valid session still reach, counting every exception you left open?
basics
~20 sCompute it as a closure, not a feeling. From the compromised origin list every allow entry still matching it, exceptions included, then repeat from each destination reached. The answer is that set times the account's rights.
One NOC seat reaches the firewall and sensor consoles of forty client estates — what does an intruder on that seat rewrite, and what does separating the seats cost?
basics
~20 sForty policies, from one seat. A shared management plane collapses forty boundaries into one, and each rewrite arrives at the client as an authorised provider change. Separating the seats spends exactly the efficiency that justified sharing them.
Port isolation breaks the shared-screen meeting rooms the venue sells — who decides, and what do you write down?
basics
~20 sThe events business owns the decision, because the revenue is theirs to trade; you own stating the cost accurately. Write a per-room exception with a named owner, an expiry tied to the booking, and what one guest reaches.
You relabel a compromised workload to a quarantine label, but its outbound session keeps running — why, and what else must isolation do?
basics
~10 sA label change is evaluated for new connections; established state is not re-checked, and the write takes time to reach every enforcement point. Isolation must flush that state and verify the flows stopped.
You place a probe host in four hundred branch segments - what have you just built for an intruder?
basics
~20 sA fleet whose declared purpose is to originate cross-segment traffic, present in every low-trust segment, centrally managed across your own boundaries, holding a map of which pairs should be open, and deliberately excluded from alerting. Design it to be worthless when captured: no credentials, outbound-only management, and narrow suppression.
An executive reads empty border firewall logs after an internal intrusion as proof the controls held - how do you answer, and what would have to be in the path before a record could exist?
basics
~20 sEmpty border logs prove only that the traffic did not cross the border. A control that is not on the path produces no evidence in either direction. A record of interior movement exists only once you fund a routed hop and a device that inspects it.
A derived allow-list goes live and leadership wants the plant declared segmented - what do you refuse to claim, given an intruder may have been inside the learning window?
basics
~20 sRefuse to say that permitted equals authorised, that every conduit has a purpose, or that lateral movement is prevented. Claim only that traffic absent from the window is denied, and price what a stronger claim would cost.
Clinical engineering asks you to renew a blanket exception for 60 unpatchable devices. What do you sign, refuse or change?
basics
~20 sRefuse the shape rather than the devices. Convert a blanket, indefinite exception into per-device enumerated permits with an expiry and a named owner, and get the residual risk accepted in writing by someone senior enough to accept it.
Every segment is already permitted to your shared identity, resolution and log tier, so an intruder anywhere has a path to it — how do you fund and enforce it as the estate's strongest boundary?
basics
~20 sArgue from reachability, not asset value: this is the one tier every segment may already reach, so its blast radius is the whole estate. Buy the change windows, the separate administration path and the evidence with that argument.
Your change board rubber-stamps 200 microsegmentation approvals a month - what do you ask the funder to buy or give up?
basics
~20 sAn intruder's path is assembled from individually approved changes, so rubber-stamping is the failed control. Name the real ceiling - review capacity, not rule count - and make the funder choose: pay for reachability testing, or accept a coarser grain.
Your segmentation diagram backs a customer contract, but an intruder would meet no filter on the real path - what do you do, and who signs for it?
basics
~20 sSeparate three problems: an unenforced boundary, an assertion already made to a third party, and a remediation nobody has funded. The technical gap gets compensating controls and a dated plan; the assertion is a legal and contractual question that is not the network team's to sit on; the outage windows belong to business owners who can refuse them.
Application owners refuse to sever a batch flow an intruder would also use: how do you decide, and who accepts the residual?
basics
~20 sTurn the refusal into a priced choice. Show how many destinations that single flow keeps reachable, offer narrowed versions instead of all or nothing, and if the owner still refuses, write the residual reach down and have them accept it by name.
You want the firewalls reachable only from an out-of-band management path — who signs that nobody can reach them when that path fails?
basics
~20 sThe owner of the service whose availability the outage would hit, not the security team. A path that alone reaches the controls means its failure blocks every fix, so that risk needs a named owner's written acceptance and a tested break-glass.
showing 31–44 of 44