Malware runs on a laptop whose VPN exempts one SaaS range to save head-end capacity - what does network inspection see?
answer
- ask where the sensor physically sits
- packets never cross the head-end
- not thinner visibility - absent visibility
- only the endpoint and the destination still record
- capacity was bought with visibility
basics
~10 sNothing. Exempted traffic never enters the tunnel, so it never reaches the head-end or anything behind it. An exemption removes the vantage point entirely rather than reducing what gets logged.
solid answer
~40 sUnder full tunnelling every packet goes up the tunnel and out through the corporate stack, so the firewall, proxy and sensors sit behind the concentrator. An exemption is a routing decision made on the client: those destinations leave the laptop's local interface directly. A device only records traffic it carries, so for exempt destinations there is no flow record, no TLS metadata, no proxy entry - not a thinner view, no view. The only records left are on the endpoint itself and at the destination, and the endpoint is exactly the asset you are assuming is compromised. That gap was bought deliberately: the exemption exists because concentrator sessions, egress bandwidth and inspection licensing cost money. Malware on that laptop inherits a lane the policy already permits and nothing on the network watches.
go deeper
Be ready to say where each control physically sits and to follow one packet. If it never crosses the head-end, no device behind the head-end can log it.
Explain the client route set that produces the split, and be precise that a flow record is written by the forwarding device - so exemption means no record at all, not a coarser one.
Show that you can state the bounded claim out loud: this path is unobserved, so no assertion about activity on it is available. Then name what you would rebuild a vantage with and what it costs.
Own the framing that visibility was traded for capacity without appearing on any budget line, and that an untracked exemption is a permanent liability created by a temporary shortfall.
## What an exemption actually is A remote-access client installs a route set when it connects. Under **full tunnelling** the client claims the default route, so every destination - corporate and public alike - is encapsulated and delivered to the concentrator, which forwards it out through whatever the organisation has built: a filtering firewall, a web proxy, a decryption tier, flow exporters, DNS controls. Under **selective tunnelling** the client keeps a list of destinations that are *not* claimed, and those packets go straight out of the laptop's own interface to the local network and its internet path. That is the whole mechanism, and everything else follows from it. ## The stack is behind the concentrator, so exempt traffic is not near it A network control can only see what physically traverses it. Every corporate control in this design sits at or behind the head-end. Traffic that never reaches the head-end is not partially inspected, sampled or logged at a lower fidelity - it is simply not present at any device you own. | Position | Sees tunnelled traffic | Sees exempt traffic | |---|---|---| | VPN concentrator | five-tuple, volume, session | nothing | | Egress firewall / proxy | destination, TLS metadata, policy verdict | nothing | | Flow exporter behind it | five-tuple, bytes, packets, timestamps | nothing | | Endpoint agent on the laptop | process and connection events | process and connection events | | Destination service's own trail | tenant activity | tenant activity, if you are the tenant | The common wrong answer is that flow data still shows *something*, because flow feels like a passive, always-on fact of the network. It is not: a flow record is written by the device forwarding the packets, and no device you administer forwards these. ## What the absence of a record means, and what it does not This is where the direction of the claim matters. The absence of a flow record on this path proves nothing about what moved. It does not mean the volume was small, the destination was benign, or that nothing happened. It only means the path is unobserved. The strongest honest sentence a defender can say about an exempt destination is *"we do not observe this path"* - never *"we saw no activity there"*. ## Why anyone agreed to it Exemptions are rarely made for elegance. In an estate where every employee's only route to work is the tunnel, the head-end pair carries the entire workforce's internet traffic. Session counts, egress bandwidth and per-seat inspection licensing all scale with headcount, and real-time media in particular is a large, continuous, latency-sensitive byte stream. When the capacity line is refused or arrives late, exempting a destination is the fix that costs nothing today. The bill is paid in visibility rather than in currency, which is precisely why it does not appear on any budget. ## The adversary's side of the same fact An implant on the laptop is a process on the same host, subject to the same route set. It does not need to defeat a control, tunnel inside another protocol, or find a misconfiguration; it addresses a destination the organisation has already decided to permit and to not watch. Two properties compound this: the exempt list lives on the device, readable by anything running there, so the uninspected path is discoverable rather than guessed at; and modern exemptions are keyed to large cloud or CDN address blocks that host far more than the one vendor you intended. ## What is left to work with Endpoint telemetry still records process and connection activity, but it lives on the machine you are assuming is compromised, and its coverage is a licensing and rollout question rather than a given. The destination's own audit trail records what happened inside *your* tenant - useful, and blind to anything that used your uninspected lane to reach somebody else's account at the same address range. Neither is a substitute for a control in the path; both are what you have left after removing one.
- Doesn't the concentrator's flow data at least show that the laptop contacted the exempt destination?No. A flow record is produced by the device that forwards the packets. Exempt packets leave the laptop's local interface and never reach the head-end, so nothing there can write a record for them. And the missing record proves nothing on its own - it is evidence about your sensor placement, not about the traffic.
- If the exemption covers only real-time media over UDP, is the visibility loss proportionally smaller?The share of bytes you stop inspecting is large, but exposure is not proportional to bytes. Any process on the host can address the exempt destination range over the same permitted path. Narrowing an exemption by destination and by transport shrinks the reachable surface, but on whatever remains your vantage is zero, not reduced.
- Does enrolling the laptop in the corporate proxy client change the answer?Only if the proxy path is on the packets' route. If the exemption bypasses the client's forwarding for those destinations, enrolment is bookkeeping: the device is managed, the traffic is still unseen. Enrolment tells you which laptop should be sending you records, not that this traffic produced any.
Adding a camera to the loading dock tells you nothing about the side door, and no amount of camera tuning will. The exemption is a side door you cut on purpose.
saying these in an interview costs you the question
- Claims flow records still exist for exempt destinations
- Says visibility is reduced rather than absent
- Assumes the proxy sees it because the device is enrolled
- Treats an endpoint agent as an equivalent replacement for a path control
- Reads the missing record as evidence nothing happened