Firewalls & Security Groups
Default-deny, stateful rules, and restricting egress as well as ingress.
5 to work through
-
intermediate
An auditor asks you to prove the reporting service cannot reach the payments database. What evidence would you produce, and why is a screenshot of the security group not it?
3 min answer -
intermediate
An enterprise platform has accumulated thousands of network security rules over years, and nobody can determine whether a given rule is still needed. What is the diagnosis and what would you change?
2 min answer -
intermediate
Automated traffic is 60% of your requests, distorting analytics and consuming capacity. Where do you handle it and how?
2 min answer -
advanced
An attacker compromises one container in your cluster. What should your network controls prevent, and what can they not help with?
2 min answer -
advanced
Security requires default-deny egress across the estate. Engineering says it will cause constant outages. How do you deliver it?
2 min answer
3 terms in this topic
Default Deny
A firewall posture in which nothing is permitted unless explicitly allowed, as opposed to blocking known-bad traffic.
conceptFirewalls and Security Groups
Network-level access control, its real value as a second layer, and why the perimeter model stopped being sufficient.
conceptStateful Packet Filtering
Filtering that tracks connection state, so return traffic for an allowed outbound connection is permitted automatically.
Neighbouring topics
Networking
General material on the network path underneath an architecture.
TCP/IP
Handshakes, congestion control, head-of-line blocking and connection reuse.
HTTP/1.1, HTTP/2 & HTTP/3
Multiplexing, prioritisation and the transport each is built on.
DNS
Resolution, TTL behaviour, traffic steering and failover latency.
TLS & Certificates
Encryption, integrity, authentication, termination points and expiry.
Layer 4 vs Layer 7
Connection-level versus request-level balancing, and what each unlocks.
Reverse Proxies
One place for TLS, routing, caching, compression and rate limiting.
Content Delivery Networks
Edge caching, origin offload, spike absorption and dynamic content.
NAT & Egress
Outbound-only connectivity, its per-gigabyte cost and its zone binding.
VPC Design
Address planning, peering and the ranges you can never resize.
Subnetting
Tiering, zone binding, and sizing for an address-hungry platform.
Routing & BGP
How traffic finds you, anycast, and route withdrawal as a failure mode.
Service Mesh Networking
Sidecar proxies supplying mTLS, retries and traffic policy.
WebSockets & Realtime
Persistent bidirectional connections and the capacity model they impose.
gRPC Transport
HTTP/2 multiplexing, binary encoding and streaming semantics.
API Gateways
The single entry point, and the business logic that must stay out of it.
Network Performance
Latency floors, bandwidth-delay product, and what no code change fixes.
Private Connectivity
Private endpoints, peering and dedicated links to managed services.
Network Troubleshooting
Flow logs, packet paths, and localising a problem to a hop.