skip to content

Zero Trust Architecture

You will learn the zero-trust model as NIST SP 800-207 defines it — never trust by network location, verify continuously — and the architectures that implement it: ZTNA, SDP, identity-aware proxies, and SASE. Interviewers increasingly close network-security rounds with it, asking how you would migrate a perimeter-based network to zero trust.

on this pageshow

explore

questions

page 1 of 2

Why does an internal app that trusts corporate-network reachability still serve an intruder, and what does replacing that check cost?

level: juniorimportance: must knowfreq 78%

answer

  1. a routing fact, not an identity claim
  2. who else lands in the same place
  3. the app was never taught to ask
  4. each flow carries its own credential
  5. front door or rewrite - nothing is free

basics

~20 s

Reachability proves only that a packet arrived from an address the network will route; anything that lands inside inherits it. Replacing it means building the login the app never had - a front door on its host, or a rewrite.

solid answer

~50 s

Being on the internal network is a statement about routing, not about who is calling. A plant fabric hands the same position to an employee laptop, a vendor notebook plugged in for a commissioning visit, an unattended shop-floor terminal, and any of those hosts once an intruder owns it - none of which involved anyone proving an identity. That is the single tenet of NIST SP 800-207: network location is not evidence, so each flow must carry its own authenticated identity and be authorised per request. The uncomfortable part with a twenty-year-old ERP or licence server is that it has nowhere to put that credential and no code path that asks for one. So the decision has to be added from outside - an identity-aware front door in the path, or a rewrite - and until someone funds that, `inside` is the whole authentication.

go deeper

for a junior

Be ready to say plainly what an internal source address proves: a packet was routed, nothing more. Have two concrete examples of something non-employee that holds a position on a corporate network.

for a middle

Explain the mechanics of the replacement - a credential presented per flow, a decision made per request, and an audit record naming the caller - and why an application with no login cannot do any of that by itself.

for a senior

Show you have costed it: the enforcement point has to go somewhere, the machine callers need service identities, and the cutover has an outage window. Talk about the inventory before you talk about the design.

for a principal

Own the framing that this is a portfolio decision across dozens of legacy applications, not one project, and that some of them will be accepted with a signed residual rather than fixed.

### The claim, in one line NIST SP 800-207 rests on a tenet that is easy to nod at and hard to implement: **network location is not evidence**. Where a packet came from is a fact about cabling, address assignment and routing tables. It is not a statement that anybody proved who they were. ### Why a self-hosted plant fabric makes this vivid In a single-tenant data centre serving a manufacturer, the application population is old: an ERP, a shop-floor scheduling app, a licence server, a handful of reporting tools. Their authentication story, stated honestly, is: *the port is only reachable from the corporate fabric, and the corporate fabric only carries our people.* The second half of that sentence has never been true, and it decays every year: - a machine builder's engineering notebook, plugged in for a commissioning visit and never removed from the estate; - a shared terminal on the shop floor that nobody signs out of; - a print server, a building-management controller or a camera recorder that speaks outbound to the internet and accepts commands; - a remote-support path granted to a vendor a decade ago; - an intruder who has taken over any one of the above. Every one of those events grants a **network position**. Not one of them authenticated a person. The ERP's entire access check is therefore satisfied by whoever most recently obtained a route - which is precisely the property an adversary works to acquire first, because acquiring it is the whole login. ### What position actually proves, stated precisely A connection arriving on an internal address proves that *some* host with a routable address opened a socket. It does not prove the caller is an employee, that the device is managed, that the credential behind it is unstolen, or that the human who owns the workstation is the one typing. Direction matters here: reachability is a property of the network; identity is a property of the caller; and the network never observed the second one. ### What has to carry the decision instead Under the model, every flow carries its own authenticated identity, and access is decided per request against that identity plus context - the resource asked for, the state of the device, the time. Position degrades to, at best, one weak signal among several. The practical shape is: something in the path must (a) authenticate the caller, (b) decide, and (c) record what it decided, for **each** request rather than once per network admission. ### The price, which is the half interviews actually probe For an application written in the last fifteen years this is configuration: it already speaks a token or a session, and you point it at an identity provider. For this estate it is not, because the application has no field to carry a credential and no code path that asks for one. That leaves three genuinely different positions, and each costs something: | Option | What you get | What you pay | |---|---|---| | Front it | A real identity on every human session, now | An enforcement point installed on the app host itself, an exception list for every machine caller, connection-level rather than action-level decisions | | Rewrite it | Per-action authorisation and an audit trail with a user on each action | Money and 12-24 months, during which nothing changes | | Accept it | No engineering spend | A shrunken reachability list, recorded sessions, and a named person who signs the residual risk with a review date | There is a fourth cost that all three share and that people forget to fund: **finding out who actually calls the application**. In an estate this age the callers are mostly machines - a nightly batch, a monitoring poller, a reporting server, a script on somebody's desktop from 2013 - and each of them connected straight to the port with no credential because none was ever needed. Until that inventory exists, any change to reachability is an unplanned outage waiting for a cutover window. ### The wrong answer to avoid saying out loud The common senior-level miss is treating this as a labelling exercise - redraw the zones, call the fabric untrusted, declare the programme underway - without noticing that the applications themselves cannot participate. The model does not remove trust from the network by decree; it *moves* the check into something that can make it, and if nothing in the path can make it, someone has to build or buy that thing. That is the whole conversation.

  • Someone argues the plant fabric is physically isolated, so position is good enough - what do you say?
    Physical isolation is a claim about a room, not about a flow. The maintenance laptop, the vendor's remote-support path and any machine that spans both sides all deliver position without identity. Isolation also degrades silently: nothing alerts when somebody adds a route or bridges a network for a project, so the control you are relying on can stop existing without anyone noticing.
  • Which internal callers make it hardest to switch this on?
    The machine ones. A nightly batch, a monitoring poller, a reporting server and a few forgotten scripts connect straight to the port with no human to prompt for a credential. Each needs a service identity issued and a route through the new front door before cutover, and every one you failed to inventory fails during the outage window - which is why the discovery work gets funded regardless of which option wins.
  • Does putting the app behind stronger perimeter filtering address the same problem?
    No. Filtering at the perimeter changes who can reach the fabric from outside; it does nothing about the callers already inside it, which is where the entire population of positions this app trusts lives. It also still decides on addresses and ports rather than on an identity, so a caller who qualifies gets everything the app offers.

A road that reaches your house proves a car can arrive. It says nothing about whether the driver was expected, or who is behind the wheel.

saying these in an interview costs you the question

  • Says the firewall already authenticated whoever is inside
  • Treats a private internal source address as a trusted identity
  • Assumes only employees can obtain a network position
  • Thinks zero trust is a product you install rather than a decision you move
  • Claims the change is free because the app already works

context

open as a page

An attacker's tunnel outlives the account being disabled: what must an access broker do to end it, and who else gets dropped?

level: juniorimportance: must knowfreq 55%

basics

~20 s

Disabling an account only changes the answer given the next time something asks, and an established flow is never asked again. The broker must hold session state and actively terminate matching sessions, which also drops legitimate users the same rule catches.

open as a page

Zero trust admits a stolen but valid credential on a compliant device - what did the model actually remove?

level: juniorimportance: must knowfreq 72%

basics

~20 s

Zero trust removed network position as evidence, so being inside no longer grants reach. It never claimed to remove credential theft: a real credential on a compliant device is a true input, and every enforcement point downstream will correctly allow it.

open as a page

A compromised laptop's agent reports disk encryption on and EDR running. What did the access gateway actually verify, and what does distrusting it cost?

level: juniorimportance: must knowfreq 60%

basics

~20 s

Only that something holding the device's credential sent a document containing those claims. The values are the endpoint's own word, and an attacker with code on it can write any of them. Distrusting them costs a narrower grant.

open as a page

A zero-trust deny runs at your platform's front gateway — which paths to the same application never touch it?

level: juniorimportance: must knowfreq 62%

basics

~20 s

Usually several: an operator opening a shell inside a running workload, node-level access to the host, the platform's own control API on a management network, workload-to-workload calls that never leave, and outbound batch traffic. A front gateway only sees what routing sends it.

open as a page

A zero trust broker authorises a connection once at setup: what can an implant on that laptop then do, and what does per-request checking cost?

level: juniorimportance: must knowfreq 70%

basics

~20 s

A connection-scoped grant authorises the pipe, not the messages inside it: an implant on that laptop can send anything the protocol allows down it, uncredentialed. Deciding per request closes that, at a parse and a lookup per request.

open as a page

Which rule decides access for an internal service in no asset catalogue, and what does each default cost when an attacker finds it?

level: juniorimportance: must knowfreq 62%

basics

~10 s

The catch-all at the bottom of the policy decides it, because nothing above it matches. Allow-by-default hands an adversary a path no reviewer ever looks at; deny-by-default breaks integrations nobody can name in advance.

open as a page

You now pay for two access paths to one app and the old one still works — what has an attacker actually lost?

level: juniorimportance: must knowfreq 62%

basics

~20 s

Close to nothing. An attacker takes whichever path is cheapest, so the application's exposure is the most permissive of the two, not the average. You are now funding two policy sets and getting the weaker one's security.

open as a page

You rebind a legacy app to loopback behind an on-host identity front door - what can an intruder still reach, and what breaks?

level: middleimportance: should knowfreq 50%

basics

~20 s

Loopback removes network reach, not local reach: any process or account on that host still opens the port, and the app cannot tell callers apart. It also silently cuts every batch job and integration that connected directly.

open as a page

A compromised laptop fails posture mid-session: what can the broker kill, what can only the tunnel client kill, and what breaks?

level: middleimportance: should knowfreq 44%

basics

~20 s

The broker can close only the sessions it terminates or proxies, and refuse new ones. Flows that never traverse it — local network, split-tunnel exclusions — die only if the endpoint's tunnel client drops them, and that client runs on the device you just declared untrustworthy.

open as a page

What does a device-compliance claim carried into an access decision assert, and what does it never assert?

level: middleimportance: should knowfreq 55%

basics

~20 s

It asserts a device satisfied a defined checklist - patch level, encryption, management enrolment - when posture was last evaluated. It never asserts that no adversary is operating there, and that answer stands until the claim expires or is re-evaluated.

open as a page

A posture document carries a TPM quote plus agent-reported fields. Which facts does the quote vouch for once an attacker has post-boot code execution?

level: middleimportance: should knowfreq 46%

basics

~20 s

Only the boot-time measurements it signed, freshly, with a key that cannot leave the hardware. It says nothing about what is running now, so an implant loaded after boot leaves the quote valid and every other field still a claim.

open as a page

Front gateway, device agent, or a proxy beside the workload: which still denies a compromised workload's call to its peer?

level: middleimportance: should knowfreq 55%

basics

~20 s

Only the proxy in the workload's own network path. A front gateway never sees a call that does not route to it, and a device agent enforces for a user's endpoint — a compromised workload is not an enrolled device. The proxy's price is one enforcement point per workload to keep consistent.

open as a page

A zero trust connector decides per request for an internal HTTP console but not for a database listener: why, and what does an implant gain?

level: middleimportance: should knowfreq 55%

basics

~20 s

Per-request decisions need the connector to reconstruct discrete requests, which needs the protocol's framing and semantics. For a database, remote-desktop or vendor binary protocol it cannot, so the grant is all-or-nothing and an implant inherits the whole session.

open as a page

An access proxy's first-seen records are your only asset list — how long do you watch, and which attacker paths never appear there?

level: middleimportance: should knowfreq 45%

basics

~20 s

Watch a full business cycle: quarterly and year-end callers are the undocumented ones. The records cover only subjects that reached that enforcement point, so a path bypassing it, or reuse of an already-enrolled subject, leaves no new entry.

open as a page

You hold two policy sets for one application — a rented edge you do not operate plus your own firewall — so which policy does an attacker actually face?

level: middleimportance: should knowfreq 44%

basics

~20 s

The union of what the two permit, chosen by the attacker. Neither box evaluates the other's decision, so a deny added at one is not a deny for the application. Holding both costs two reviews and two incomplete evidence sets.

open as a page

A revoked contractor's flow to an internal database was still moving bytes 40 minutes later: how do you close that gap without re-authenticating the whole estate hourly?

level: seniorimportance: should knowfreq 36%

basics

~20 s

Trace the chain: where the decision changed, what learned about it, and what was actually torn down. Long-lived pooled flows with keepalives are never re-decided, so cap session age at the enforcement point and push revocations — and scope aggressive re-decision to high-value applications, not everything.

open as a page

Consultants on client-owned laptops you cannot enrol need access. How do you scope that exemption so an attacker cannot simply claim it, and what does it cost?

level: seniorimportance: should knowfreq 38%

basics

~20 s

Make the exemption a server-side property of an identified person and engagement, set out of band, never something the connecting device asserts. Then make the exempt tier deliberately thin, because whoever steals those credentials lands in exactly that tier.

open as a page

An app's accept log shows connections from the node network, not the ingress gateway — what does that prove and what does it not?

level: seniorimportance: should knowfreq 44%

basics

~20 s

It proves the application accepted connections from a source that is not the enforcement point, so a path exists around the deny. It does not prove malice, does not identify who was behind them, and covers only the paths used during that window — not every path that exists.

open as a page

An application team wants a connection-scoped grant on its busiest internal service to protect p99: how do you weigh that against the open pipe?

level: seniorimportance: should knowfreq 42%

basics

~20 s

Measure the real added latency and where it comes from, then decide per endpoint rather than per service. Concede on high-volume read paths, and state plainly what one open pipe lets a compromised device do on that service.

open as a page

You run a new deny-by-default catch-all in log-only mode for 90 days first — what does that window hand an adversary?

level: seniorimportance: should knowfreq 48%

basics

~20 s

Ninety more days of allow-by-default on every unlisted subject, plus the risk that whatever an intruder does during the window becomes part of the baseline you promote into permanent exceptions. Log-only defers the denial; it does not de-risk it.

open as a page

Before you cut the legacy circuit an attacker can still use, what evidence would justify spending a two-hour trading outage on it?

level: seniorimportance: should knowfreq 47%

basics

~20 s

Positive evidence over a full business cycle, not silence. Sampled flow records and a short retention window hide low-volume clients, so run a reversible deny-and-log period first and let the complaints be your inventory before you spend the outage.

open as a page

An unauthenticated ERP serves any caller inside the fabric and your steering group funds exactly one of front it, rewrite it or accept it - how do you frame the choice?

level: principalimportance: should knowfreq 40%

basics

~20 s

Present three residual-risk positions, not three designs: what each leaves an intruder able to do, what it costs, who signs it and when it is reviewed. A two-year rewrite accepts today's exposure for two years.

open as a page

Zero trust shipped, standing grants are reviewed quarterly and every owner approves everything - what do you tell the executive it buys?

level: principalimportance: should knowfreq 38%

basics

~20 s

Say plainly that the attestation buys an audit artefact and an owner of record, not narrower grants. Redirect the same review capacity to the grants that would most help an adversary, and let the long tail expire.

open as a page

A shop-floor fat client speaks a proprietary TCP port with no login or redirect, so any host that reaches the port is served - where can a per-user decision live, and what will it still not cover?

level: seniorimportance: nice to knowfreq 32%

basics

~20 s

Not in the protocol - it moves to the transport: a per-user, mutually authenticated tunnel terminating on the app host, with the app on loopback behind it. That decides who may connect, never which action they may perform.

open as a page

Two directories federated after an acquisition: an account made in the weaker one reaches your systems - how do you bound that edge?

level: seniorimportance: nice to knowfreq 33%

basics

~20 s

Stop treating the far directory's identities as equivalent to yours. Grant them explicitly and narrowly on your side instead of mapping group to group, time-box those grants, require your own step-up for sensitive systems, and measure the other estate's deprovisioning lag.

open as a page

An implant reused a connection-scoped grant to an internal console: with only flow records and the broker's session log, what can you show it carried?

level: seniorimportance: nice to knowfreq 35%

basics

~20 s

Almost nothing about content. Flow records prove bytes moved between two endpoints, with counts, timestamps and no payload; the broker's log proves a grant was issued and a pipe existed. Neither shows which records or exports the session carried.

open as a page

Finance wants to cut broker headroom that is only used when a stolen-credential incident forces a mass revocation — what do you argue, and what disconnect time do you sign for?

level: principalimportance: nice to knowfreq 26%

basics

~20 s

Argue that the headroom buys the ability to actually fire a mass revocation: without it, the reconnect wave takes the broker down and the response becomes one nobody dares run. Then commit only to a measured, scoped number, with offline clients excluded.

open as a page

Your posture schema is mostly signals a compromised endpoint could compose, and the client's risk owner will not sign. What do you present, and what do you fund?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Present a signal-by-signal provenance table — attested, inferred, claimed — and state plainly what each survives under a compromised endpoint. Then offer costed choices: fund attesting hardware, shrink what the claimed tier reaches, or keep data off the device.

open as a page

The platform team keeps a standing break-glass path around the enforcement point — how do you govern it?

level: principalimportance: nice to knowfreq 31%

basics

~20 s

Treat the bypass as its own control: one named owner, an expiry that defaults to removal, its own strong authentication, and every use reviewed by someone who did not make it. Then make the normal path fast enough at 3am that nobody prefers the bypass.

open as a page

showing 1–30 of 32