Network Security
Segmentation, egress control and limiting lateral movement.
3 to work through
-
intermediate
An enterprise wants to segment its network so that a compromised application server cannot reach the database directly. What does segmentation actually buy, and what commonly undermines it?
2 min answer -
advanced
All outbound traffic from a cluster passes through an egress proxy that enforces allowlists and TLS inspection. The proxy does not fail; it gets slow, with p99 rising from 20 ms to 6 s. What happens across the platform over the next ten minutes?
3 min answer -
advanced
You propose egress filtering. Engineering says it will break builds and slow delivery. How do you proceed?
2 min answer
3 terms in this topic
Egress Filtering
Restricting what a workload may connect out to, which is the control that turns a compromise into a contained one.
conceptSecurity Group Sprawl
The accumulation of firewall and security group rules that nobody can safely remove, producing a permissive posture nobody chose.
toolWeb Application Firewall
A filter in front of an application that inspects HTTP requests and blocks those matching known attack patterns — useful as a layer, dangerous as a s…
Neighbouring topics
Security Architecture
General material on securing an architecture.
Authentication
Establishing who a principal is, and how strong that claim needs to be.
Authorization
RBAC, ABAC and ReBAC, and centralising the decision but not the enforcement.
OAuth 2.0 & OIDC
Delegated authorisation, and the identity layer that makes login safe.
Tokens & JWTs
Stateless validation, revocation, and pinning the algorithm.
Identity & Access Management
Workload identity, roles, permission boundaries and usage-based review.
Secrets Management
Runtime injection, dynamic credentials and rotation applications survive.
Encryption
At rest, in transit, and at the application layer — three different threats.
Key Management
Rotation, separation of duty, envelope encryption and crypto-shredding.
Zero Trust
No implicit trust from network position; authorise every request.
Threat Modelling
Walking trust boundaries with STRIDE before anything is built.
OWASP Risks
The recurring web and API risk classes, several of which are design flaws.
Secure API Design
Object-level authorisation, input validation and safe error responses.
Supply Chain Security
Dependencies, SBOMs, build provenance and artefact signing.
Auditability
Tamper-evident, attributed records that survive async boundaries.
Compliance Frameworks
SOC 2, ISO 27001, PCI DSS — scope as an architectural lever.
Privacy Engineering
Minimisation, purpose limitation, and erasure that is implementable.
Data Classification
Knowing which fields are regulated, because every control depends on it.
Security Incident Response
Detection, scoping, containment and notification clocks.