Learn · Network and Infrastructure Defense · Lesson 2

Validating Segmentation and Access Controls

Validate intended paths, expected denies, exceptions, and bypasses without assuming a VLAN or configured rule proves enforcement.

Summary

Segmentation can involve zones, VLANs, subnets, virtual networks, host firewalls, network firewalls, ACLs, security groups, identity-aware policy, proxies, VPNs, and shared services. Configuration is evidence, not proof that the intended path is enforced.

Learning objectives and prerequisites

Use the exposure lesson or understand routing and policy. You should be able to identify enforcement points, policy order, object groups, exceptions, logging gaps, bypasses, and positive and negative validation cases.

Why this matters

Separate VLANs do not automatically prove segmentation. Different subnets do not automatically imply filtering. A configured control may not be active on the intended path; policy order and object groups can change the effective result. Absence of logs does not prove a block.

Guided workflow

  1. Define the segmentation objective and protected sources, destinations, and services.
  2. Identify all enforcement points, routes, policy order, objects, inherited rules, shared services, VPN, proxy, and management paths.
  3. Review temporary exceptions, expiry, and logging coverage.
  4. Design bounded positive and negative tests; record expected allow, expected deny, bypass, partial coverage, or insufficient evidence with an owner and next action.

Fictional worked example

A user network, server network, and management network have a jump host, DNS and backup dependencies, a broad temporary firewall rule, a disabled host firewall on one server group, and incomplete denied-traffic logs. A permitted backup path is expected; a broad user-to-server path is a bypass candidate. Validate both directions, preserve the exception owner and expiry, and avoid claiming all paths are isolated.

Decision exercise

Classify controls as validated, partially validated, configured but unverified, bypassed, exception active, or insufficient evidence. State evidence, limitation, owner, and next validation or remediation step.

Knowledge checks and answer explanations

  1. Does a VLAN prove segmentation? No; effective filtering and paths still need evidence.
  2. Why review policy order? Earlier rules can change the effective result.
  3. Why inspect object groups? Unexpected members can broaden an allow.
  4. What is negative validation? Testing that an expected deny is actually denied.
  5. Why track exceptions? They need owner, expiry, and dependency review.

Common misconceptions

Configured means enforced, no logs means blocked, one successful test proves every path, or a temporary exception is harmless.

Practical takeaway

Keep an evidence record of objective, path, enforcement point, effective rule, positive and negative result, exception, gap, owner, and reassessment trigger.

Related content

Network Access Control Operations, Investigation Evidence Quality, Remediation Ownership and Closure, CIDR Calculator, DNS Investigation Worksheet, and CISA KEV.

Limitations

This lesson cannot prove complete segmentation, complete logging, or every possible path in a real environment.

Last reviewed: Unknown. Recheck local evidence before acting.