Ravindra BagaleCourses & study guides Track your progress

Guides

50 Network Security Interview Questions and Answers

This pack delivers 50 network security interview Q&As covering segmentation, firewalls, TLS, VPN/ZTNA, cloud SG/NACL themes, east-west traffic and defender-safe visibility — suited to India NOC/SOC hybrids and US network security roles. Concepts and architecture only.

Friends! Network security interview = a diagram in your head. Segmentation, SG vs NACL, TLS validation, egress control. 50 Q&A — Wireshark/nmap only on own lab scope. No attack recipes.

How to use this pack

Sketch a three-tier diagram before answering design questions. Always state assume-breach / east-west risk. Contrast stateful vs stateless clearly. Mention authorisation before any scanning talk. Tie controls to ransomware blast-radius reduction. Capture packets only where you are allowed.

Educational / lab-only

Network tools (scanners, sniffers, firewall changes) only on networks you own or with written authorisation. No MITM practise on cafe Wi-Fi, no DDoS generation, no exploit PoCs.

Network security interview pack Segmentation, firewall policy and TLS protect east-west and north-south paths. Zones DMZ · private micro-seg Controls firewall TLS · VPN Visibility flow logs SOC Q&A

Network security interviews stress segmentation, TLS, firewall policy and east-west visibility — authorised labs only.

Questions 1–50

Q1. What is network segmentation and why? (Beginner)

Dividing networks into zones so a breach cannot freely reach crown jewels. Use VLANs, firewalls, cloud VPCs/subnets and identity-aware proxies. Flat networks help ransomware spread — interviewers expect that link.

Q2. Firewall vs router vs switch (security view)? (Beginner)

Switch forwards at Layer 2 inside a LAN. Router routes at Layer 3 between networks. Firewall enforces allow/deny policy, often with state and logging. Modern devices blend features — speak to function.

Q3. Stateful vs stateless firewall? (Beginner)

Stateful tracks connection state so return traffic for established flows is allowed. Stateless filters each packet alone (basic ACL/NACL themes). AWS analogy: Security Groups are stateful; NACLs are stateless.

Q4. What is a DMZ for web apps? (Beginner)

Place the public web tier in a restricted zone; keep app and database private. Only required ports flow between tiers. Same idea in AWS three-tier VPC designs.

Q5. Explain TLS at a high level. (Beginner)

TLS authenticates the server via certificates and encrypts the session so path eavesdroppers cannot easily read payloads. Clients must validate cert chains and hostnames. HTTPS is HTTP over TLS.

Q6. HTTP vs HTTPS? (Beginner)

HTTP is cleartext on port 80; HTTPS wraps TLS on 443. Prefer HTTPS everywhere; use HSTS where appropriate. Mixed content can still leak or break trust.

Q7. What is DNS and why secure it? (Beginner)

DNS maps names to IPs. Abuse includes phishing domains and tunnelling themes. Defences: recursive filtering, DNS logs for SOC, DNSSEC where used, and MFA on registrar accounts.

Q8. ARP and ARP spoofing awareness? (Intermediate)

ARP maps IP to MAC on a LAN. Spoofing can enable local MITM themes on flat networks. Defences: dynamic ARP inspection themes, segmentation, and not relying on LAN trust alone.

Q9. MITM — defender view? (Beginner)

Attacker position to intercept or modify traffic. Defences: TLS with validation, careful pinning in special apps, secure Wi-Fi, and not installing random root CAs. No attack recipes needed in interviews.

Q10. What is a VPN concentrator used for? (Beginner)

Terminates remote-access or site-to-site VPNs, authenticates users/devices and enforces access policy. Combine with MFA and posture checks. Split versus full tunnel is a security/performance trade-off.

Q11. IDS/IPS placement? (Intermediate)

IDS often uses taps for visibility; IPS sits inline on chokepoints. Cloud equivalents need cost care. False positives on IPS can outage systems — change control matters.

Q12. What is NAC? (Intermediate)

Network Access Control admits devices based on identity/posture (802.1X themes). Guests get restricted VLANs. Helps stop unmanaged devices on corp SSIDs.

Q13. Wireless security basics? (Beginner)

Prefer WPA2/WPA3-Enterprise with 802.1X; avoid open or weak shared PSKs for corporate. Separate guest Wi-Fi. Do not expose AP admin interfaces to the internet casually.

Q14. East-west vs north-south traffic? (Intermediate)

North-south crosses the perimeter. East-west is lateral inside. Modern breaches move east-west — micro-segmentation and identity controls matter more than only the edge firewall.

Q15. What is micro-segmentation? (Intermediate)

Fine-grained allow-lists between workloads (SG/NSG, service mesh policies). Assume one VM compromise and limit next hops. Start with critical app maps.

Q16. DDoS — defender high level? (Beginner)

Overwhelm availability with volume or application-layer floods. Mitigations: upstream scrubbing/CDN, rate limits, anycast, sane autoscaling and ISP/cloud playbooks. Do not practise generating floods.

Q17. BGP briefly for security folks? (Intermediate)

Internet routing between ASNs. Incidents include route leaks/hijacks. Operator defences include RPKI/filtering themes. Enterprises should understand dependency and monitoring — not attacks.

Q18. NAT security implications? (Beginner)

NAT hides internal IPs but is not a firewall by itself. Outbound NAT still needs egress control. Hairpinning and logging complexity appear in troubleshooting questions.

Q19. Egress filtering — why? (Intermediate)

Control what internal hosts may reach on the internet — reduces malware C2 and exfil paths. Allow-list destinations where feasible; log denies for SOC.

Q20. Security Group vs NACL (AWS-style)? (Beginner)

SG: stateful, ENI level, allow rules only with implicit deny. NACL: subnet level, stateless, allow and deny. Interviews love this cloud comparison.

Q21. Public vs private subnet? (Beginner)

Public has a route to an Internet Gateway. Private has no IGW route and uses NAT for outbound if needed. Databases belong in private subnets.

Q22. What is a bastion / jump host? (Beginner)

Hardened admin entry host to reach private instances. Prefer MFA, short-lived access, session recording and modern alternatives like SSM Session Manager. Avoid SSH open to 0.0.0.0/0.

Q23. Port scanning ethics? (Beginner)

Only scan systems you own or have written authorisation to test. Unauthorised scanning can be illegal and career-ending. Discuss nmap as an admin inventory/lab tool with scope.

Q24. Common ports to know? (Beginner)

22 SSH, 25/587 mail, 53 DNS, 80/443 web, 3389 RDP, 3306 MySQL, 5432 Postgres. Helps read firewall policies. Close unused listeners.

Q25. NetFlow/IPFIX use in SOC? (Intermediate)

Conversation summaries (who talked to whom, bytes, ports) for anomaly detection when full PCAP is too heavy. Retention and sampling trade-offs matter.

Q26. PCAP analysis safety? (Beginner)

Capture only on authorised networks; respect privacy; handle malware-bearing captures carefully. Use Wireshark filters; do not email captures with secrets to personal accounts.

Q27. TLS interception trade-offs? (Intermediate)

Corporate proxies may decrypt TLS for DLP/malware scanning with an enterprise CA on managed devices. Trade-offs: privacy, breakage, and protecting the interception CA as a crown jewel.

Q28. Certificate expiry — prevent? (Beginner)

Inventory certs, monitor expiry, automate renewal where fit, alert at 30/14/7 days. Expired-cert outages are classic interview war stories.

Q29. What is 802.1X? (Intermediate)

Port-based network access control: authenticate before full LAN access, often with RADIUS. Improves wired/wireless admission versus open wall jacks.

Q30. VLAN hopping awareness only. (Intermediate)

Misconfigured trunks historically allowed cross-VLAN tricks. Defence: disable unused ports, set native VLAN carefully, avoid user ports as trunks — follow switch hardening guides.

Q31. IPv6 security — why care? (Intermediate)

Dual-stack networks may leave IPv6 unmanaged while IPv4 is locked. Ensure firewalls and logging cover IPv6, or disable if unused per policy. Attackers go where you are blind.

Q32. What is a WAF? (Beginner)

Web Application Firewall filters HTTP(S) for common web attacks and bots at Layer 7. Complements secure coding — not a replacement. Tune to limit false blocks.

Q33. API gateway security network angle? (Intermediate)

Centralise authn, rate limits, TLS and logging; restrict origins; privately integrate backends. Inventory shadow APIs that bypass the gateway.

Q34. ZTNA vs VPN? (Intermediate)

Zero Trust Network Access brokers per-app access with identity/device checks instead of placing users on a flat network. Many orgs run hybrid during migration.

Q35. Lateral movement — network signs? (Intermediate)

Unusual internal SMB/RDP/WinRM patterns, odd admin-share access and beaconing — thematic. Detect with east-west visibility and identity logs. Contain with segmentation and account disable.

Q36. How do you secure RDP/SSH exposure? (Beginner)

Avoid publishing to the whole internet; use VPN/ZTNA/bastion/SSM; enforce MFA; restrict source IPs; patch; monitor failed logons. Credential hygiene matters as much as ports.

Q37. Load balancer security basics? (Beginner)

Terminate TLS correctly, modern ciphers, careful client-IP forwarding, WAF integration, health checks that do not leak admin panels. Restrict SG from LB to app only.

Q38. DNS tunnelling — defender idea? (Intermediate)

Abnormal DNS query volumes or lengths to odd domains can signal covert channels. Detect with DNS logging and analytics; block risky categories. Stay within authorised data.

Q39. Network ACLs vs host firewalls? (Beginner)

Defence in depth: coarse subnet ACLs plus per-OS host firewalls. Cloud SGs are distributed host-adjacent controls. Document overlapping rules.

Q40. Document network architecture for audits? (Beginner)

Current diagrams, data flows, trust boundaries, firewall rule owners and change tickets. Stale diagrams are findings. Include cloud and on-prem.

Q41. NTP and time sync security why? (Intermediate)

Correct time keeps logs correlated and Kerberos/TLS happy. Prefer authenticated or internal NTP hierarchy themes.

Q42. Email security network controls? (Beginner)

Mail gateways, TLS for transport, SPF/DKIM/DMARC, URL rewriting and attachment sandboxing. SOC needs message traces. User reporting is part of the control.

Q43. OT/ICS network rule of thumb? (Intermediate)

Segment OT from IT, allow-list conduits, jump hosts with MFA, never freestyle scan live plants. Safety first. Mention Colonial/Oldsmar lessons thematically only.

Q44. Hairpin NAT / U-turn — when asked? (Intermediate)

Internal clients reaching a public VIP that reflects back inside. Confuses firewall logs. Prefer private endpoints or split DNS when possible.

Q45. Capacity vs security for inline devices? (Intermediate)

IPS/firewalls can bottleneck or fail open/closed with different risk. Know vendor fail mode and size for peak traffic plus inspection overhead.

Check recent policy pushes, IPS signatures, asymmetric routing after firewall inserts and cert problems. Collaborate with netops inside change windows.

Captures may include personal data — need authorisation and retention limits. Never capture cafe Wi-Fi for practice. Lab or employer-approved spans only.

Q48. Defence for credential theft on the wire (themes). (Intermediate)

Prefer encrypted protocols, disable legacy cleartext where policy allows, enforce SMB signing when required, monitor downgrades. Identity controls remain critical.

Q49. Cloud networking shared responsibility? (Beginner)

Provider runs the fabric; you design VPC/VNet, routes, SGs/NSGs, peering and exposure. Misopened 0.0.0.0/0 on admin ports is on you.

Q50. Favourite network control in interviews? (Beginner)

Pick one and justify — for example deny-by-default segmentation plus identity-aware access — because it limits ransomware blast radius and supports Zero Trust. Show business impact fluency.

Ravindra Bagale's Tip

💡 Students stop at "we have a firewall so we are safe". Interviewers ask about east-west. Talk segmentation + identity + egress logs. A flat VLAN is a ransomware highway. Keep that in mind!

Got it? Network security = zones, least ports, TLS, visibility, ethics. Revise 50 Q. Next: cloud AWS and IAM Zero Trust packs.

Frequently asked questions

What diagram should I draw cold?

Internet → edge firewall/WAF → web tier → app tier → database, with admin path via bastion/ZTNA.

Is a firewall enough?

No. Flat networks and identity gaps still allow lateral movement — add segmentation and MFA.

May I demo nmap in an interview?

Discuss ethical inventory on labs you own; do not scan employer or third-party networks without written leave.

What cloud network topics appear?

Public vs private subnets, Security Groups vs NACLs, bastion vs SSM, egress control.

How do OT questions differ?

Safety first, IT/OT segmentation, no live plant scanning — simulation only.

Related guides on this site?

Firewall beginner, SG vs NACL, VPN and Wireshark beginner guides.