[POSSIBLE INCIDENT] Marketing intern PC seeing prod servers in ARP
- From
- Senior Security Analyst <soc-l2@acme-corp.com>
- To
- netops@acme-corp.com
- Date
- 2026-04-19 09:55 UTC
On a routine onboarding check, a new marketing intern reported that their laptop is "showing weird hostnames" — they ran arp on their first day and saw production server names (db-prod-01, web-prod-02) on their local subnet.
Their PC is plugged into ACCESS-SW-12 port Gi1/0/24 in the marketing area. Marketing should be on VLAN 200 (office), not VLAN 100 (prod-servers). The switch port log says the wrong access-VLAN was applied on Apr 18 18:12 UTC, so the port has been bridged into the prod-servers segment for roughly 16 hours by the time we noticed — please bound the exposure window before doing anything destructive.
Please confirm and remediate. Treat as access-control / segmentation violation while you investigate, not just a typo. Critically, before you remediate: did the intern's workstation actually reach any production resource (db-prod-01 / web-prod-02 SSH / SMB / HTTP), or is this only L2 visibility? We need that answered from logs, not assumed.
A plea from the on-call: do not "fix" this by converting the marketing access ports to trunk, do not delete VLAN 100 to "make the leak go away", and do not clear the switch's MAC address-table before evidence is preserved. Move the port, scope the exposure, then harden.
— SOC L2