Case FF10AE · Network · L3 Applied
TLS Inspection Trade-offs
Practise as: Explain it · Interview
Interview questionShould an enterprise decrypt TLS at the proxy? Argue both sides.
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Proxy terminates TLS using an internal CA trusted by managed endpoints, inspects, then re-encrypts upstream
- Gains: malware and DLP inspection, visibility into C2 over HTTPS
- Risks: proxy becomes a high-value target, may weaken upstream validation or ciphers, privacy and legal issues
- Breaks certificate pinning and mutual TLS; exempt banking, health and pinned apps via bypass lists
- TLS 1.3 mandates forward secrecy and encrypts the certificate, so passive decryption with a server key fails; MITM is required
If the interviewer pushes back
- Encrypted Client Hello hides SNI. What visibility is left for a network defender?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.