Repair ordered access without losing service or isolation

A hands-on N10-009 lab. You produce the real artefact and 9 automated checks verify it behaves the way the exam expects.

Try this labAll N10-009 practice

Certification
N10-009
Format
Structured configuration
Difficulty
medium
Estimated time
35 min
Automated checks
9

The brief

Edit access-policy.json using exactly defaultAction and rules. Set defaultAction to deny. Keep at most 32 ordered rule records, each with id, action, transport, source, destination, sourcePorts and destinationPorts. Each id must be unique, 1..80 characters and trimmed. Actions are allow or deny. Transport is tcp, udp or tcp+udp; the latter means those two transports only, not every IP protocol. Source and destination use canonical IPv4 CIDRs, including /32 for a single address. Each port field is an inclusive two-integer range within 0..65535, such as [443,443] for one port or [1024,65535] for the full client range. Rules run in list order: the first rule matching both address ranges, both port ranges and transport decides the tuple. Unmatched traffic uses defaultAction. A later deny cannot undo an earlier allow. Permit the complete address and port ranges for every approved request and reversed reply, preserve guest isolation in both directions, and admit no other TCP/UDP tuple. The checks assess whole CIDR match ranges and complete inclusive port ranges, not a few test hosts. You may use narrow permits, split ranges into equivalent rules, or guard a broader permit with earlier exceptions. Reply rules must match the service source port and the client's destination range; this stateless worksheet never infers an established connection. Run the independent service and isolation checks after edits, inspect the first-match counterexample, and repair the policy without Reset.

What the checks verify

Your work is graded on 9 independent properties, not on matching one reference answer.

  • Policy records have canonical bounded address, port, identity and action fields.
  • The policy explicitly denies unmatched traffic.
  • Every staff portal request tuple is permitted.
  • Every guest partner-web request tuple is permitted.
  • Staff and guest resolver requests work over both declared transports.
  • Every approved administrator SSH request tuple is permitted.
  • Reversed reply tuples are permitted for every approved request contract.
  • No unapproved tuple involving a guest source or destination is effectively permitted.
  • The complete effective TCP/UDP allow space contains no unapproved tuple.

Where this sits in the N10-009 blueprint

Domain
Network Security
Objective
Security Defenses
Skill
Effective Network Controls

Part of N10-009 preparation

Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.