Home/Labs/Zero Trust Blast Radius
All 280 Labs
INTERACTIVE LAB🏰

Zero Trust Lateral Movement Lab (Interactive)

Compromise one laptop; count how far the attacker walks with and without micro-segmentation. Contrast flat VPN trust against BeyondCorp-style identity-aware proxy, SPIFFE mTLS, and Cilium policies by computing reachable nodes, exposed datastores, and traversal logs.

Castle-and-Moat vs Zero Trust Blast Radius

Compromise one foothold, then measure exactly how far the attacker walks. Network locality conveys zero privilege.

Initial foothold (phished / exploited)

Every east-west hop requires a valid, unexpired X.509 SVID bound to the workload's SPIFFE ID — stolen IPs alone cannot impersonate a service, and certs auto-rotate before exfiltration windows open.

Blast radius

33%

of internal nodes reachable

Sensitive stores exposed

1 / 3

HR PII · prod DB · backups

Attacker traversal log

  • foothold acquired: Contractor Laptop (endpoint)
  • Contractor Laptop → HR Web App: IAP: Okta SSO + FIDO2 + device posture → this one app only
  • Contractor Laptop → Metrics Dashboard: IAP grant for observability team
  • Contractor Laptop → CI Runner Pod: CiliumNetworkPolicy DROP + missing SVID: mTLS handshake aborts before bytes flow
  • Contractor Laptop → Billing Service: CiliumNetworkPolicy DROP + missing SVID: mTLS handshake aborts before bytes flow
  • Contractor Laptop → Prod PostgreSQL: CiliumNetworkPolicy DROP + missing SVID: mTLS handshake aborts before bytes flow
  • Contractor Laptop → S3 Nightly Backups: CiliumNetworkPolicy DROP + missing SVID: mTLS handshake aborts before bytes flow

Contractor Laptop

● COMPROMISED

CI Runner Pod

■ ISOLATED

HR Web App

▲ REACHED

Billing Service

■ ISOLATED

Metrics Dashboard

▲ REACHED

Prod PostgreSQL

■ ISOLATED

S3 Nightly Backups

■ ISOLATED

Lateral movement succeeded — perimeter trust is breachedOne phished credential (or one supply-chained CI pod) placed the attacker on a flat east-west network — exactly the failure mode Google BeyondCorp eliminated after Operation Aurora. Data staged to S3 and exfiltrated over the same VPN tunnel the employee "legitimately" uses.

Interview framing (NIST SP 800-207): replace the VPN concentrator with an Identity-Aware Proxy that evaluates user identity + device posture (disk encrypted, OS patched, EDR heartbeat) on every request; replace static service credentials with SPIRE-issued 1-hour SVIDs rotated in-memory by the mesh sidecar; replace subnet ACLs with workload-identity network policies. Accept ~0.5–1ms mTLS overhead per hop and an internal PKI as the price of eliminating the inside-out attack class.

How It Works Under the Hood

Castle-and-moat security assumes anyone inside the perimeter is trusted, so one phished contractor VPN credential delivers unrestricted east-west movement: subnet scans, unpatched internal servers, and database dumps all reachable without re-authentication. Zero Trust (NIST SP 800-207) asserts network locality conveys zero privilege: an identity-aware proxy admits the user to exactly one application after checking device posture, services authenticate each RPC with short-lived SPIRE-issued SVIDs, and eBPF micro-segmentation denies workload-to-workload flows lacking an explicit least-privilege policy. The lab BFS-walks the live policy graph from whichever node you compromise, exposing how identity-at-ingress alone, without east-west enforcement, silently reverts to the flat network.

Core Architectural Principles

  • VPN-mode reachability is a complete graph: every internal node accepts east-west connections.
  • Zero Trust reachability is BFS over explicit policy edges like IAP app grants and billing-to-postgres:5432.
  • Disabling micro-segmentation while keeping ingress checks leaves workload-to-workload movement unpoliced.
Interview Round Script

Open with the mantra: never trust, always verify; network locality conveys zero privilege. Tell the lateral-movement story, then name the building blocks: identity-aware proxy replacing the VPN, SPIFFE/SPIRE short-lived SVIDs for mTLS, and micro-segmented egress policies. Quantify the cost honestly: internal PKI, MDM agents, and ~0.5-1 ms per mesh hop.

Key Trade-Offs

Zero Trust eliminates the inside-out attack class but buys that containment with PKI, posture agents, and per-hop crypto overhead.

Related Curriculum Chapter

Zero Trust Architecture: "Never Trust, Always Verify"

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs