skip to content

VPNs & Encrypted Transport

Where a tunnel is landed, what it lets past unexamined, and what an always-connected estate costs to hold. Interviewers use VPN design to separate run experience from protocol recital.

on this pageshow

explore

questions

24

Malware runs on a laptop whose VPN exempts one SaaS range to save head-end capacity - what does network inspection see?

level: juniorimportance: must knowfreq 62%

answer

  1. ask where the sensor physically sits
  2. packets never cross the head-end
  3. not thinner visibility - absent visibility
  4. only the endpoint and the destination still record
  5. capacity was bought with visibility

basics

~10 s

Nothing. Exempted traffic never enters the tunnel, so it never reaches the head-end or anything behind it. An exemption removes the vantage point entirely rather than reducing what gets logged.

solid answer

~40 s

Under full tunnelling every packet goes up the tunnel and out through the corporate stack, so the firewall, proxy and sensors sit behind the concentrator. An exemption is a routing decision made on the client: those destinations leave the laptop's local interface directly. A device only records traffic it carries, so for exempt destinations there is no flow record, no TLS metadata, no proxy entry - not a thinner view, no view. The only records left are on the endpoint itself and at the destination, and the endpoint is exactly the asset you are assuming is compromised. That gap was bought deliberately: the exemption exists because concentrator sessions, egress bandwidth and inspection licensing cost money. Malware on that laptop inherits a lane the policy already permits and nothing on the network watches.

go deeper

for a junior

Be ready to say where each control physically sits and to follow one packet. If it never crosses the head-end, no device behind the head-end can log it.

for a middle

Explain the client route set that produces the split, and be precise that a flow record is written by the forwarding device - so exemption means no record at all, not a coarser one.

for a senior

Show that you can state the bounded claim out loud: this path is unobserved, so no assertion about activity on it is available. Then name what you would rebuild a vantage with and what it costs.

for a principal

Own the framing that visibility was traded for capacity without appearing on any budget line, and that an untracked exemption is a permanent liability created by a temporary shortfall.

## What an exemption actually is A remote-access client installs a route set when it connects. Under **full tunnelling** the client claims the default route, so every destination - corporate and public alike - is encapsulated and delivered to the concentrator, which forwards it out through whatever the organisation has built: a filtering firewall, a web proxy, a decryption tier, flow exporters, DNS controls. Under **selective tunnelling** the client keeps a list of destinations that are *not* claimed, and those packets go straight out of the laptop's own interface to the local network and its internet path. That is the whole mechanism, and everything else follows from it. ## The stack is behind the concentrator, so exempt traffic is not near it A network control can only see what physically traverses it. Every corporate control in this design sits at or behind the head-end. Traffic that never reaches the head-end is not partially inspected, sampled or logged at a lower fidelity - it is simply not present at any device you own. | Position | Sees tunnelled traffic | Sees exempt traffic | |---|---|---| | VPN concentrator | five-tuple, volume, session | nothing | | Egress firewall / proxy | destination, TLS metadata, policy verdict | nothing | | Flow exporter behind it | five-tuple, bytes, packets, timestamps | nothing | | Endpoint agent on the laptop | process and connection events | process and connection events | | Destination service's own trail | tenant activity | tenant activity, if you are the tenant | The common wrong answer is that flow data still shows *something*, because flow feels like a passive, always-on fact of the network. It is not: a flow record is written by the device forwarding the packets, and no device you administer forwards these. ## What the absence of a record means, and what it does not This is where the direction of the claim matters. The absence of a flow record on this path proves nothing about what moved. It does not mean the volume was small, the destination was benign, or that nothing happened. It only means the path is unobserved. The strongest honest sentence a defender can say about an exempt destination is *"we do not observe this path"* - never *"we saw no activity there"*. ## Why anyone agreed to it Exemptions are rarely made for elegance. In an estate where every employee's only route to work is the tunnel, the head-end pair carries the entire workforce's internet traffic. Session counts, egress bandwidth and per-seat inspection licensing all scale with headcount, and real-time media in particular is a large, continuous, latency-sensitive byte stream. When the capacity line is refused or arrives late, exempting a destination is the fix that costs nothing today. The bill is paid in visibility rather than in currency, which is precisely why it does not appear on any budget. ## The adversary's side of the same fact An implant on the laptop is a process on the same host, subject to the same route set. It does not need to defeat a control, tunnel inside another protocol, or find a misconfiguration; it addresses a destination the organisation has already decided to permit and to not watch. Two properties compound this: the exempt list lives on the device, readable by anything running there, so the uninspected path is discoverable rather than guessed at; and modern exemptions are keyed to large cloud or CDN address blocks that host far more than the one vendor you intended. ## What is left to work with Endpoint telemetry still records process and connection activity, but it lives on the machine you are assuming is compromised, and its coverage is a licensing and rollout question rather than a given. The destination's own audit trail records what happened inside *your* tenant - useful, and blind to anything that used your uninspected lane to reach somebody else's account at the same address range. Neither is a substitute for a control in the path; both are what you have left after removing one.

  • Doesn't the concentrator's flow data at least show that the laptop contacted the exempt destination?
    No. A flow record is produced by the device that forwards the packets. Exempt packets leave the laptop's local interface and never reach the head-end, so nothing there can write a record for them. And the missing record proves nothing on its own - it is evidence about your sensor placement, not about the traffic.
  • If the exemption covers only real-time media over UDP, is the visibility loss proportionally smaller?
    The share of bytes you stop inspecting is large, but exposure is not proportional to bytes. Any process on the host can address the exempt destination range over the same permitted path. Narrowing an exemption by destination and by transport shrinks the reachable surface, but on whatever remains your vantage is zero, not reduced.
  • Does enrolling the laptop in the corporate proxy client change the answer?
    Only if the proxy path is on the packets' route. If the exemption bypasses the client's forwarding for those destinations, enrolment is bookkeeping: the device is managed, the traffic is still unseen. Enrolment tells you which laptop should be sending you records, not that this traffic produced any.

Adding a camera to the loading dock tells you nothing about the side door, and no amount of camera tuning will. The exemption is a side door you cut on purpose.

saying these in an interview costs you the question

  • Claims flow records still exist for exempt destinations
  • Says visibility is reduced rather than absent
  • Assumes the proxy sees it because the device is enrolled
  • Treats an endpoint agent as an equivalent replacement for a path control
  • Reads the missing record as evidence nothing happened

context

open as a page

A remote-access VPN authenticates a user with MFA and hands out a pool address - what does that session then reach?

level: juniorimportance: must knowfreq 78%

basics

~20 s

A tunnel session reaches whatever the routing table and the filters behind the address pool allow, which by default is everything the concentrator can route to. Authentication decides who gets an address; it never decides which destinations that address may open.

open as a page

An intruder inside a partner's network arrives over their site-to-site tunnel — what did that tunnel's authentication prove, and what must you run behind it?

level: juniorimportance: must knowfreq 66%

basics

~20 s

It proves only that the far-end device held the agreed key or certificate — nothing about the hosts behind it. Traffic leaving the tunnel is ordinary unauthenticated traffic, so your side needs its own default-deny filter on the extranet zone.

open as a page

A remote-access concentrator lands its inside leg on the core VLAN — what filters the decrypted traffic?

level: juniorimportance: must knowfreq 68%

basics

~20 s

Nothing except the concentrator itself. ESP is decapsulated at its inside leg, so plaintext appears already on the core and no independent device sees it. Enforcement there means paying for a second filter and a second hop.

open as a page

What does always-on VPN lockdown block, and what is still exposed on the local network?

level: juniorimportance: must knowfreq 64%

basics

~20 s

Lockdown makes the endpoint's own packet filter drop every flow except the tunnel and a few named exceptions. It protects traffic, not the machine: the interface is still on the hostile segment, and whatever the exceptions allow is reachable there.

open as a page

Your VPN head-end keeps a weak legacy proposal enabled for devices that cannot be reconfigured. Who can select it?

level: juniorimportance: must knowfreq 64%

basics

~20 s

Every caller that can reach the gateway. A head-end's accepted proposal set is policy for the listener, not a per-device setting, so a caller offering only the weak proposal is given it. The exception is not scoped to the devices you meant.

open as a page

A managed-service provider reports a breach and their tunnel into your extranet is still up — what do you do first, and what can you establish?

level: seniorimportance: must knowfreq 54%

basics

~20 s

Cutting the tunnel stops the service the provider runs for you, so the business owner decides. Narrow the policy, revoke the accounts they hold inside your estate, and expect your records to show that bytes moved, not what they were.

open as a page

A VPN exempt list keyed to a SaaS vendor's published IP ranges is reviewed quarterly - what can an adversary reach through it?

level: middleimportance: should knowfreq 47%

basics

~20 s

Anything reachable at an address inside those blocks. The exemption is keyed to addresses, not to the vendor's identity, so shared cloud space and blocks the vendor has released stay exempt until someone reviews the list.

open as a page

Internal logs show a VPN pool address, not a user - how do you bind a flow to an account?

level: middleimportance: should knowfreq 55%

basics

~20 s

Join the flow to the concentrator's address-assignment record using the flow's own timestamp: that record says which account held which pool address, and when. Pool addresses are reassigned, so a join without time attributes the flow to the wrong person.

open as a page

A partner announces prefixes over your site-to-site tunnel that the contract annex never listed — what limits their reach, and what does holding that limit cost?

level: middleimportance: should knowfreq 45%

basics

~20 s

The accepted-route filter and the zone policy limit reach; the annex is paper and enforces nothing. Cost: someone must own an inbound prefix list and a source-address filter per partner, and every legitimate change becomes a ticket with an outage risk.

open as a page

Why might the filter behind your VPN head-end see only the forward direction of decrypted traffic?

level: middleimportance: should knowfreq 46%

basics

~20 s

Routing decides the path, not the diagram. If the core reaches the VPN client pool over an adjacency that skips the filter, return packets never traverse it — and flows still work, so the gap stays silent.

open as a page

What does an always-on VPN client open for a captive portal, and for how long?

level: middleimportance: should knowfreq 47%

basics

~20 s

The client probes a known URL over plain HTTP; a redirect instead of the expected empty response means a portal. It then opens a timed exception - the DHCP-supplied resolver plus the portal host - while the tunnel stays down.

open as a page

What do a VPN head-end's negotiation logs prove about which peers still need the legacy proposal?

level: middleimportance: should knowfreq 47%

basics

~20 s

They prove which peer identities agreed the legacy set during the logged window, and nothing more. Absence shows only that a peer did not connect in that window, and a peer offering both sets is capable of the modern one and is not blocking you.

open as a page

VPN head-end capacity runs out next quarter and the cheapest fix is exempting the two heaviest SaaS destinations - which traffic do you hand an adversary?

level: seniorimportance: should knowfreq 54%

basics

~20 s

Rank candidates by exposure, not by bytes. Real-time media over UDP is the defensible first exemption: huge volume, narrow and stable destinations, almost no inspection yield. A general-purpose file or web SaaS is the opposite on every axis.

open as a page

An adversary owns your VPN head-end outright — how does the inside leg's position change what they originate?

level: seniorimportance: should knowfreq 44%

basics

~20 s

Owning the box deletes its own policy as a control: the adversary now originates traffic and chooses source addresses. From a core-VLAN landing they reach whatever the core routes; from a screened tier, only what a device they cannot administer permits.

open as a page

You cannot retire a weak VPN proposal for a year. What compensates for it meanwhile?

level: seniorimportance: should knowfreq 41%

basics

~20 s

Treat those tunnels as transport, not trust: terminate the legacy group somewhere narrow, allow it only the destinations those devices actually need, alert when the legacy proposal is selected by an identity not on the inventory, and time-box the arrangement with an owner and an expiry.

open as a page

Shrinking VPN pool reach needs app-by-app discovery nobody will staff - what do you deliver and who signs?

level: principalimportance: should knowfreq 41%

basics

~20 s

Stop enumerating what remote users need and start removing what they never need, in tranches ordered by consequence. Deliver a falling reachable-destination count per pool, and have a named risk owner accept the remainder with an expiry.

open as a page

Always-on VPN lockdown leaves a traveller with no network at all. What recovery path do you sign for?

level: principalimportance: should knowfreq 38%

basics

~10 s

Choose one and name its owner: hard lockdown plus an out-of-band, time-limited, per-machine unlock the helpdesk logs, or a bounded automatic fail-open. The unlock is what a caller claiming to be stranded will target.

open as a page

Three destinations are exempt from your VPN tunnel - how do you prove an implant is not using that uninspected path?

level: seniorimportance: nice to knowfreq 33%

basics

~20 s

You cannot, from the network - there is no vantage there by construction. You either rebuild one deliberately, fall back to endpoint and destination-side records with their limits stated, or say plainly that the path is unobserved.

open as a page

One remote-access VPN lands into two merged estates using overlapping RFC1918 space - how do you scope reach?

level: seniorimportance: nice to knowfreq 32%

basics

~20 s

Give each population its own pool, keep the two overlapping address plans in separate routing tables, and translate only the few flows that must cross. One shared pool routed into both estates lets the unassessed directory's accounts reach your core.

open as a page

A user asks for local-subnet access on an always-on VPN laptop so they can print at home. What do you grant?

level: seniorimportance: nice to knowfreq 31%

basics

~20 s

Grant the ports printing needs, outbound-initiated, with an owner and an expiry - not the whole subnet. The exception follows whatever prefix DHCP just handed the laptop, so at a conference it reaches hundreds of strangers' devices.

open as a page

You move the legacy VPN proposal onto a second listener restricted to known peers. What does that buy?

level: seniorimportance: nice to knowfreq 31%

basics

~20 s

It takes the weak option off the surface every caller touches, so an arbitrary host dialling the main head-end can no longer select it. It does not improve the legacy tunnels themselves, and repointing devices that cannot be reconfigured may cost the outage you were avoiding.

open as a page

A business-critical supplier refuses a security audit and refuses an offboarding clause with teardown evidence — what do you require, and what do you build anyway?

level: principalimportance: nice to knowfreq 31%

basics

~20 s

Require what a supplier will actually sign: breach notification to a tested contact, declared flows, and the right to disable. Build default-deny and a tunnel expiry that fails closed. Escalate the residual risk for named acceptance.

open as a page

How do you justify a second enforcement hop behind the VPN head-end when cost and a peer argue for one box?

level: principalimportance: nice to knowfreq 32%

basics

~20 s

Stop arguing defence in depth. Write what a fully-owned head-end could originate from each candidate position, have a risk owner sign it, price the second hop honestly, and offer the variant that needs no purchase.

open as a page