Zero Trust, Segmentation, and Service-to-Service Security Questions
Designing network and service-communication trust models where no implicit trust is granted by network location. Covers zero-trust access, microsegmentation and identity-aware perimeters, least-privilege network access, lateral-movement prevention, and segmenting environments to contain blast radius, together with securing service-to-service communication in distributed and microservices architectures: mutual authentication between services, service mesh security, multi-tenancy isolation, east-west traffic, and the security implications of scale and geographic distribution. The architectural trust-boundary pattern and its enforcement across decomposed, high-scale systems, distinct from device-level firewall configuration.
Describe the difference between VLANs and IP subnets. Provide concrete examples of when you would use VLAN segmentation without changing subnets and when you would separate by subnets. Explain implications for broadcast domains, inter-VLAN routing, and where you would apply ACLs in each case.
Design a migration plan to move from a flat network to a segmented architecture for Kubernetes-based applications where production and non-production currently share the same cluster. Include steps to implement network policies, service mesh, WAF, and continuous compliance verification. Provide a rollback plan and risk mitigation steps for each phase.
Describe a practical plan to validate and test network segmentation controls after deployment and on a recurring basis. Include automated tests (policy-as-code), passive flow verification, active scanning, host-based verification, scheduled penetration tests, and how to safely remediate failed controls without causing downtime.
Translate this hybrid connectivity scenario into routing and firewall controls: on-prem network 10.0.0.0/16 connects to AWS via Direct Connect with two VPCs (10.1.0.0/16 and 10.2.0.0/16). You must allow only web traffic from the internet to 10.1.0.0/16 DMZ, allow 10.1.0.0/16 to reach 10.2.0.0/16 App through an inspection gateway, and prevent direct VPC-to-VPC lateral movement. Provide a BGP/routing sketch and the firewall (or Security Group/NACL) rules necessary to enforce these constraints.
You discover evidence of lateral movement inside a segmented environment: an internal host in the App zone is beaconing to an internal C2 IP in the Management zone. Draft an incident containment plan that uses segmentation controls (ACL changes, microsegmentation, host-based firewall policies) to contain the compromise while minimizing disruption. Include short-term and long-term remediation steps and how you'd validate containment.
Unlock Full Question Bank
Get access to all 33 Zero Trust, Segmentation, and Service-to-Service Security interview questions and detailed answers.
Sign in to ContinueJoin thousands of developers preparing for their dream job.