Guided pathThis is part of Understand security: protocols, identity and secure architectureBack to the path

The network attack surface

P58.network-foundations.01 · Audience: guest, it-ml, language-pro · Prerequisites: Certificates & chains of trust

Real LLM grading for this pageLLM grading (this page):

Welcome to Cloud & Network Security — the last pillar of the Security discipline. Before any protocol or identity check runs, one question decides most of your risk: what can reach this service at all?

This track answers it twice: a firewall that denies by default (rules are first-match, so ordering is the policy), and an exposure classifier that tells you whether a service is reachable from this machine only, from a private network, or from the entire internet. Most cloud incidents are not clever exploits — they are a database bound to 0.0.0.0.

This platform makes exactly that call for its own servers: bind loopback, expose over the private tailnet, or publish deliberately via Funnel (ADR-027).

Same thread as every module here: concept → protocol → attack → defence. Nothing touches a socket — you evaluate policies, never probe hosts.

Ask the mentor about this module

Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.

Images, PDF or text. Kept on this device only.
Keeping your files on this device

Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.

Ctrl/Cmd + Enter to send
Rung 1 — a firewall that denies by default

Loading exercise…

Rung 2 — classify a service's exposure

Loading exercise…

My notes on this module

Loading your notes...

The network attack surface — TransformerLab