skip to content

The Exfiltration Tax

Volume is the one property of a transfer an operator cannot make cheap, so the sharper decision is what never moves at all. Interviewers ask how the data leaves and hear a covert tunnel back.

on this pageshow

explore

questions

4

We block USB drives and personal webmail - can a bulk copy still leave a SaaS document tenant?

level: juniorimportance: must knowfreq 58%

answer

  1. two exits closed, class of exit open
  2. the carrier is chosen last
  3. business-critical destinations cannot be blocked
  4. share link, sync client, pre-signed upload
  5. read scope is the real dependency

basics

~20 s

Blocking removable media and personal webmail closes two exits, not the class of exit. A bulk copy leaves through the sanctioned cloud storage, sharing links and sync the business itself requires and cannot switch off.

solid answer

~50 s

Yes, easily. Removable media and consumer webmail are the carriers an operator uses when nothing else is available; in a document-heavy SaaS tenant they are never the only option. Someone holding broad read access can create a share link on a document, let a sanctioned sync client carry a folder outward, export a repository to the tenant's own object storage, or upload an archive into a bucket in the same cloud provider the business already trusts - often through a pre-signed URL, which carries its own authorisation and expiry in the link, so no account inside the victim tenant is used at all. Every one of those destinations resolves to a hostname the estate must permit for people to work. The carrier is the operator's last decision and the cheapest one; the expensive part is already done by the time anything moves.

go deeper

for a junior

Be ready to name at least three outward paths in a SaaS estate that survive a removable-media and webmail block: a sharing link, a sanctioned sync client, and an upload to storage in a cloud provider the company already uses.

for a middle

Explain why permitted destinations are substitutable and cheap for the operator, and what a pre-signed URL changes - authorisation lives in the link, so no identity inside the tenant is spent on the upload.

for a senior

Show that you would spend effort on standing read scope rather than on adding carriers to a block list, and be able to say what closing a business-critical sync path would actually cost the company.

for a principal

Own the framing with an executive who believes the estate is closed: state plainly which exits are load-bearing for revenue, and redirect the conversation to how much one compromised or trusted identity can assemble.

## The claim being tested "We block removable media and personal webmail, so data cannot leave" is one of the most common wrong answers in a security interview, and it is wrong in an instructive way: it treats exfiltration as a *channel* problem when it is an *authorisation* problem. The two named controls do real work - they remove the two exits an unsophisticated actor reaches for first. What they do not do is remove the class of exit, because in a modern document estate several exits are load-bearing for the business. ## What a permitted carrier looks like Picture a document-heavy SaaS tenant: shared drives, a search service the platform itself provides, and a sanctioned object-storage destination in the same cloud provider. An actor - an external operator who has taken over one account, or an insider whose job is to read these documents - has broad read access and needs to move a set of files outward. Available to them, with nothing installed and nothing unusual: - **A sharing link.** The platform is designed to publish a document to someone outside the tenant. Creating one moves nothing across the network from the victim's side at all; the recipient pulls it. - **A sanctioned sync client.** Files placed in a synced folder leave as ordinary, encrypted, business-critical traffic to the vendor the company pays. - **An export to the tenant's own object storage**, then a copy from there. Both hops are inside services the estate permits. - **An upload to a bucket the operator controls in the same cloud provider.** This is the one that surprises reviewers. If the destination is a *pre-signed URL*, the authorisation to write is embedded in the URL itself, along with an expiry - the request does not authenticate as anyone in the victim's tenant, and no credential of the victim's is involved. To the estate it is a `PUT` to a hostname belonging to a provider that hosts a large fraction of the internet. None of those needs a USB port or a consumer mail account. ## Why blocking carriers one at a time is a losing race Carriers are substitutable and cheap; the operator picks whichever the estate permits, and permitted destinations exist because people need them. Close consumer webmail and the share link remains. Close external sharing and the sync client remains. Close the sync client and you have broken the product the business bought. Each closure raises the operator's cost by minutes, because the choice of carrier is the last decision in the sequence and the one with the most alternatives. What the operator *cannot* substitute is read access to the documents. Everything before the transfer - finding out which of a million files is the one, and getting a copy of it into one place - depends on what a single identity is allowed to read. That is the dependency worth attacking. ## The insider case makes the point sharply An employee whose job is to read the customer folder needs no exploit, no implant and no unusual behaviour to obtain the data; obtaining it *is* their job. For that person the only meaningful question is what they are permitted to read, because copying is indistinguishable from working. A control that filters exits has nothing to say about someone who is entitled to the content and can pick from a dozen permitted destinations. ## How to answer this in an interview Say the two controls are worth having and name what they cover: the ad-hoc, low-effort exit. Then reframe: in a SaaS estate the outward paths are business-critical and encrypted, so the honest defence is narrowing standing read scope so that any one identity - taken over or trusted - can assemble far less. Finish by noting that the carrier is chosen last, from what is permitted, which is why an inventory of blocked exits is not a statement about exposure. ## What not to say Do not claim that encrypting the transfer is what defeats the controls; the controls named never inspected content in the first place. Do not claim that a bulk copy must involve malware - a share link and a browser are sufficient. And do not answer with a longer list of carriers to block, because listing carriers concedes the frame the question is testing.

  • What does a pre-signed upload URL specifically change for the operator?
    It puts the authorisation in the link. The URL is issued by the operator's own storage account and carries a signature and an expiry, so the upload does not authenticate as anyone inside the victim tenant and consumes none of the victim's credentials. From the estate's side it is an ordinary write to a very widely used provider hostname.
  • If you could close one more carrier, would you close the sanctioned sync client?
    Almost certainly not. It is business-critical, and closing it leaves share links, exports and provider-hosted storage untouched, so the operator's cost rises by minutes while the company's cost is permanent. Carrier-by-carrier closure is a losing race; the effort belongs on how much a single identity may read.
  • Does this argument change if the actor is an insider rather than an intruder?
    It gets stronger. An insider is entitled to the content, so there is no unusual access to remove - only the breadth of what they may read. Every carrier available to an intruder is also available to them, plus the entirely ordinary act of sharing a document with an outside party as part of their job.

Bricking up the back door and the kitchen window, in a building whose front doors are held open all day because customers walk through them.

saying these in an interview costs you the question

  • Claims blocked USB and webmail mean data cannot leave
  • Treats exfiltration as always requiring malware
  • Answers with a longer list of carriers to block
  • Assumes a theft must use an unusual destination
  • Ignores the insider who is entitled to the content

context

open as a page

Why does 'a real theft would show up as a huge transfer' miss an espionage operator?

level: seniorimportance: must knowfreq 52%

basics

~20 s

Size intuition only catches the objective that is inherently bulky. An espionage objective is usually tens of megabytes - one design, one term sheet - and the price its operator pays is weeks of time on target, not bandwidth.

open as a page

Why does an operator index and stage documents on the victim's own hosts before exfiltrating?

level: middleimportance: should knowfreq 45%

basics

~20 s

Holding read access is not the same as knowing what is worth taking. Enumerating and indexing inside the estate builds a candidate list cheaply, so only the small set the objective needs is archived and moved once.

open as a page

The business refuses to block the sanctioned cloud storage everyone uploads to - what do you change instead?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Attack the dependency an operator cannot substitute: how much one standing identity may read and how easily the estate reveals what is worth taking. The carrier stays open; the value of any single compromised or trusted account falls.

open as a page