Skip to main content

Interview questions · Book 11

Networking interview questions

156 questions from 39 pages, each with a short answer. Say your answer first, then open the question to check it.

p. 1 · 4 questions

ARP

Full page
  1. 1

    What is ARP?

    ARP is a network protocol that finds the MAC address belonging to an IPv4 address on the local network, so a device knows where to deliver each Ethernet frame.

  2. 2

    What is the difference between ARP and DNS?

    DNS translates domain names such as example.com into IP addresses and works across the internet. ARP translates IPv4 addresses into MAC addresses and works only within a single local network.

  3. 3

    What is ARP spoofing?

    ARP spoofing is an attack in which a device on the local network sends fake ARP replies, so other devices link the attacker's MAC address to someone else's IP address, often the router's. Traffic then flows through the attacker, who can read or change anything that isn't encrypted.

  4. 4

    Does IPv6 use ARP?

    No. IPv6 replaces ARP with the Neighbor Discovery Protocol, which uses ICMPv6 messages sent to multicast addresses instead of broadcasts to find neighbors' MAC addresses.

p. 2 · 4 questions

Bandwidth

Full page
  1. 1

    What is bandwidth?

    Bandwidth is the maximum amount of data a network connection can carry per second, usually measured in megabits or gigabits per second (Mbps or Gbps).

  2. 2

    What is the difference between bandwidth and speed?

    People often use them interchangeably, but bandwidth is the maximum capacity of a connection, while the speed you actually see is throughput. Throughput can be lower because of congestion, distance, and other traffic on the network.

  3. 3

    What is the difference between Mbps and MB/s?

    Mbps means megabits per second and is used for network speeds, while MB/s means megabytes per second and is used for file transfers. Since one byte is eight bits, divide Mbps by eight to get MB/s.

  4. 4

    How much bandwidth do I need?

    It depends on usage. Browsing and email need very little, a single HD video stream typically needs around 5 Mbps, and 4K streaming usually needs about 15 to 25 Mbps, multiplied by the number of people using the connection at the same time.

p. 3 · 4 questions

BGP

Full page
  1. 1

    What is BGP?

    BGP (Border Gateway Protocol) is the routing protocol that links the internet's autonomous systems by letting them announce which IP ranges they can reach.

  2. 2

    What is an autonomous system?

    A network or group of networks under one organization's control with a single routing policy, identified by an autonomous system number (ASN). Internet providers, cloud companies and large enterprises each run one or more.

  3. 3

    What is a BGP hijack?

    When a network announces IP prefixes that belong to someone else, by mistake or on purpose, so that traffic for those addresses is routed to it. RPKI route origin validation helps networks reject such announcements.

  4. 4

    What is the difference between BGP and OSPF?

    OSPF is an interior gateway protocol that finds the best paths inside one organization's network. BGP is an exterior gateway protocol that exchanges routes between different organizations' networks according to their policies.

p. 4 · 4 questions

CIDR

Full page
  1. 1

    What is CIDR notation?

    CIDR (Classless Inter-Domain Routing) writes an IP range as an address and prefix length, like 10.0.0.0/16; the prefix counts the leading network bits.

  2. 2

    What does /24 mean in an IP address?

    That the first 24 bits are the network prefix, the same as the subnet mask 255.255.255.0. The remaining 8 bits give 256 addresses in the block.

  3. 3

    How many addresses are in a CIDR block?

    Two to the power of the bits left over. For IPv4 that is 2^(32 − prefix): a /24 has 256, a /20 has 4,096 and a /16 has 65,536.

  4. 4

    What is the difference between CIDR and a subnet mask?

    They express the same thing differently. The subnet mask 255.255.255.0 and the prefix /24 both say the first 24 bits are the network. CIDR notation is shorter and also used for IPv6.

p. 5 · 4 questions

Default Gateway

Full page
  1. 1

    What is a default gateway?

    A default gateway is the router a device sends traffic to whenever the destination lies outside its own subnet, acting as the network's exit to other networks.

  2. 2

    How do I find my default gateway?

    On Linux, run ip route show default; on macOS, route -n get default; and on Windows, ipconfig, which lists it as Default Gateway. On most home networks it is an address such as 192.168.1.1 or 192.168.0.1.

  3. 3

    What happens if the default gateway is wrong?

    The device can still communicate with other devices in its own subnet, but traffic to anywhere else is sent to the wrong place or nowhere. Websites and other networks become unreachable even though the local network seems fine.

  4. 4

    Is the default gateway the same as the router?

    Usually, yes: the default gateway is the IP address of the router's interface on your local subnet. The term describes the router's role from the device's point of view, as the next hop for all non-local traffic.

p. 6 · 4 questions

DHCP

Full page
  1. 1

    What is DHCP?

    DHCP is a network protocol that automatically gives devices an IP address and other settings, such as the router and DNS server, when they join a network.

  2. 2

    What is the difference between DHCP and DNS?

    DHCP gives a device its IP address and network settings when it joins a network. DNS translates domain names into IP addresses, and DHCP is usually what tells a device which DNS server to use.

  3. 3

    What is a DHCP lease?

    A lease is the period of time a device is allowed to use the IP address it was given, such as 8 or 24 hours. The device renews the lease automatically before it expires and usually keeps the same address.

  4. 4

    What happens if a DHCP server is unavailable?

    A device may keep using an address whose lease hasn't expired yet, or it falls back to a self-assigned link-local address in the 169.254.0.0/16 range. That address only works on the local network segment, so the device typically has no internet access.

p. 7 · 4 questions

DNS Record

Full page
  1. 1

    What is a DNS record?

    A DNS record is an entry in a domain's DNS zone that maps a name to information, such as an IP address (A, AAAA), another name (CNAME) or mail servers (MX).

  2. 2

    What is the difference between an A record and a CNAME?

    An A record points a name directly to an IPv4 address. A CNAME points a name to another name, which is then resolved to an address. CNAMEs are useful when the target's address may change, such as a hosting provider's hostname.

  3. 3

    How long do DNS changes take?

    Up to the record's previous TTL, since resolvers may keep the old answer until it expires. With a TTL of 300 seconds, most users see a change within five minutes; with a day-long TTL it can take a day.

  4. 4

    What is a TXT record used for?

    Storing text that other systems read, most often to prove you own a domain for services like Google Search Console, and for email authentication records such as SPF, DKIM and DMARC.

p. 8 · 4 questions

Firewall

Full page
  1. 1

    What is a firewall?

    A firewall is a security system that checks network traffic and allows or blocks it based on rules, acting as a barrier between trusted and untrusted networks.

  2. 2

    What is the difference between a firewall and antivirus software?

    A firewall controls which network traffic can reach or leave a device, while antivirus software scans files and programs on the device for malware. They protect against different threats and are usually used together.

  3. 3

    What is a web application firewall (WAF)?

    A WAF is a firewall that inspects HTTP requests to a web application and blocks ones that look like attacks, such as SQL injection or cross-site scripting. It works at the application level, while a traditional firewall mostly looks at IP addresses and ports.

  4. 4

    Do I need a firewall on a cloud server?

    Yes. Cloud platforms usually provide network-level rules, often called security groups, and you should allow only the ports your service needs, such as 443 for HTTPS and 22 for SSH from trusted addresses.

More

Settings