Problem Statement
How would you assess risky egress paths at the network edge without causing impact?
Explanation
Work with the owner to list approved destinations like updates, identity, and CDN hosts. Send a handful of small, benign requests to a few disallowed categories to verify blocks. Log results with timestamps and source IP. Check if DNS allows external resolvers or only the corporate resolver. Recommend egress allow-lists and DNS egress pinning if gaps are found.
Code Solution
SolutionRead Only
Test: curl https://blocked.example (expect deny) DNS: dig @8.8.8.8 example.com (expect blocked)
