Exercise 1: Why a Compromised Support Workstation Is a "Pivot Point" — Possible Solution ==================================================================== WHAT A REGULAR EMPLOYEE WORKSTATION EXPOSES ------------------------------ Per this chapter's table, a regular employee workstation's typical reach if compromised is "that one person's own accounts and files" - the blast radius is contained to whatever that single individual can personally access. WHAT A SUPPORT WORKSTATION EXPOSES INSTEAD ------------------------------ Per this chapter, a support workstation "often has active sessions into ticketing systems, remote-access tools ... and sometimes elevated or admin-capable credentials - reaching many other accounts and systems at once." Its typical reach isn't the technician's own accounts alone - it's every account and system the technician's own tools are able to touch on behalf of other people. WHY "PIVOT POINT" IS THE RIGHT TERM, NOT JUST "MORE ACCESS" ------------------------------ A pivot point isn't simply a device with a larger personal footprint - it's a device that functions as a stepping stone into systems that otherwise belong to entirely different people. Compromising it doesn't just expose the technician's own identity; per this chapter, it "hands an attacker the exact tools this course has spent eight chapters teaching how to recognize being misused against someone else." The attacker inherits the technician's own reach, not just their personal data. WHY THIS MAKES IT QUALITATIVELY DIFFERENT, NOT JUST QUANTITATIVELY WORSE ------------------------------ A regular workstation compromise is bad for one person. A support workstation compromise is bad for every account and system reachable through it - potentially the entire organization's user base, if the ticketing and remote-access tools reach that far. This is a difference in kind (one victim vs. many, through a single point of failure), not merely a matter of degree. WHY THIS WORKS AS AN ANSWER ------------------------------ It contrasts what each workstation type exposes per the chapter's own table, explains specifically why "pivot point" captures something more than "more access," and explains why that makes the difference qualitative rather than just a bigger version of the same risk.