Networking Fundamentals
Networking Fundamentals
Beginner
Q1: What is a computer network?
A computer network is a collection of connected devices that can communicate with each other and share resources.
Q2: Why do networks matter?
Networks allow computers to share data, applications, printers, storage, and internet access efficiently.
Q3: What is a node in a network?
A node is any device connected to the network, such as a computer, router, switch, server, or mobile device.
Q4: What is a protocol?
A protocol is a set of rules that defines how devices communicate over a network.
Q5: What is the Internet?
The Internet is a global network of interconnected networks using standard protocols such as TCP/IP.
Q6: What is a LAN?
A LAN (Local Area Network) is a network confined to a small geographic area such as a home, office, or campus.
Q7: What is a WAN?
A WAN (Wide Area Network) connects networks over a large geographical area, such as cities, countries, or continents.
Q8: What is a MAN?
A MAN (Metropolitan Area Network) covers a metropolitan area, usually larger than a LAN but smaller than a WAN.
Q9: What is a PAN?
A PAN (Personal Area Network) is a small network used around an individual, such as Bluetooth devices.
Q10: What is the difference between a switch and a router?
A switch connects devices within the same network segment. A router connects different networks and directs traffic between them.
Q11: What is an IP address?
An IP address is a unique identifier assigned to a network device so it can be located and reached.
Q12: What is IPv4?
IPv4 is the fourth version of the Internet Protocol and uses 32-bit addresses.
Q13: What is IPv6?
IPv6 is the next-generation IP protocol using 128-bit addresses to provide a much larger address space.
Q14: How many addresses can IPv4 support?
IPv4 supports about 4.3 billion unique addresses, which is no longer enough for the modern internet.
Q15: Why is IPv6 needed?
IPv6 addresses the exhaustion of IPv4 addresses and adds improvements like simpler configuration and better security design.
Q16: What does a MAC address do?
A MAC address uniquely identifies a network interface card (NIC) on the local network.
Q17: What is the difference between IP and MAC addresses?
An IP address identifies a device on a network layer. A MAC address identifies the hardware interface on the local link.
Q18: What is a subnet?
A subnet is a smaller network created by dividing a larger IP network into segments.
Q19: What is subnetting?
Subnetting is the process of splitting a larger network into smaller sub-networks for better organization and efficiency.
Q20: What is a subnet mask?
A subnet mask is used with an IP address to determine the network and host portions of the address.
Q21: What is a default gateway?
A default gateway is the device that forwards traffic from a local network to other networks, such as the internet.
Q22: What is DNS?
DNS (Domain Name System) translates human-readable domain names like example.com into IP addresses.
Q23: What is DHCP?
DHCP (Dynamic Host Configuration Protocol) automatically assigns IP addresses and network settings to devices.
Q24: What is NAT?
NAT (Network Address Translation) allows multiple devices on a private network to share one public IP address.
Q25: What is a private IP address range?
Private IP addresses are ranges reserved for internal networks and are not routable on the public internet.
Q26: What are the private IPv4 ranges?
- 10.0.0.0/8
- 172.16.0.0/12
- 192.168.0.0/16
Q27: What is a public IP address?
A public IP address is reachable from the internet and is assigned to a device or network router.
Q28: What is a loopback address?
A loopback address is used by a device to send traffic to itself, commonly 127.0.0.1 for IPv4 and ::1 for IPv6.
Q29: What is a port?
A port is a numbered endpoint used by transport layer protocols to identify specific services or applications.
Q30: What is a socket?
A socket is an endpoint for communication, identified by IP address and port number.
Q31: What is TCP?
TCP (Transmission Control Protocol) is a connection-oriented protocol that provides reliable, ordered delivery.
Q32: What is UDP?
UDP (User Datagram Protocol) is a connectionless protocol designed for speed, often used in streaming or DNS.
Q33: What is the difference between TCP and UDP?
TCP provides reliability and ordering. UDP is faster and simpler but does not guarantee delivery or ordering.
Q34: What is the OSI model?
The OSI model is a 7-layer reference model for understanding how network communication works.
Q35: What are the OSI layers?
- Physical
- Data Link
- Network
- Transport
- Session
- Presentation
- Application
Q36: What is the TCP/IP model?
The TCP/IP model is the practical networking model used on the internet, usually simplified into 4 or 5 layers.
Q37: What are the main TCP/IP layers?
- Link
- Internet
- Transport
- Application
Q38: What does the physical layer do?
The physical layer deals with the actual transmission of bits over a cable, radio signal, or optical fiber.
Q39: What does the data link layer do?
It handles local delivery between devices on the same network segment, often using MAC addresses.
Q40: What does the network layer do?
The network layer handles routing and delivery between networks using IP addresses.
Q41: What does the transport layer do?
The transport layer provides data delivery services such as connection setup, reliability, and segmentation.
Q42: What does the application layer do?
The application layer contains protocols used by programs, such as HTTP, DNS, SMTP, and SSH.
Q43: What is a packet?
A packet is a formatted unit of data transmitted over a network.
Q44: What is a frame?
A frame is the Data Link layer unit of data, containing a header, payload, and trailer.
Q45: What is a segment?
A segment is the Transport layer PDU for TCP or UDP.
Q46: What is a datagram?
A datagram is a self-contained packet, often associated with UDP.
Q47: What is a router?
A router forwards packets between networks based on IP routing information.
Q48: What is a switch?
A switch forwards frames within a local area network using MAC addresses.
Q49: What is a hub?
A hub is a basic device that repeats signals to all connected devices, unlike a switch.
Q50: What is a firewall?
A firewall filters traffic based on security rules to control what enters or leaves a network.
Q51: What is a network interface?
A network interface is the hardware or software component that connects a device to a network.
Q52: What is bandwidth?
Bandwidth is the maximum rate at which data can be transferred over a network link.
Q53: What is latency?
Latency is the time delay between sending a packet and receiving it.
Q54: What is throughput?
Throughput is the actual data rate achieved at application level, often lower than theoretical bandwidth.
Q55: What is RTT?
RTT (Round Trip Time) is the time for a packet to travel to a destination and back.
Q56: What is packet loss?
Packet loss occurs when packets are dropped during transmission, often due to congestion or errors.
Q57: What is jitter?
Jitter is variation in packet delay, which can affect real-time traffic like VoIP and video.
Q58: What is a connectionless protocol?
A connectionless protocol does not establish a dedicated session before sending data.
Q59: What is a connection-oriented protocol?
A connection-oriented protocol establishes a session before sending data and verifies delivery.
Q60: What is a network topology?
A network topology describes the physical or logical arrangement of devices and links in a network.
Q61: What is bus topology?
In bus topology, all devices share a single communication medium.
Q62: What is star topology?
In star topology, all devices connect to a central device such as a switch or hub.
Q63: What is ring topology?
In ring topology, devices are connected in a circular path.
Q64: What is mesh topology?
In mesh topology, devices have multiple redundant links to others for resilience.
Q65: What is a NIC?
A NIC (Network Interface Card) is the physical or virtual interface used to connect a device to a network.
Q66: What is Ethernet?
Ethernet is the dominant LAN technology used for wired networking.
Q67: What is Wi-Fi?
Wi-Fi is a wireless local network technology based on IEEE 802.11 standards.
Q68: What is CSMA/CD?
CSMA/CD (Carrier Sense Multiple Access with Collision Detection) was used in Ethernet hubs before switches dominated.
Q69: What is CSMA/CA?
CSMA/CA is used in Wi-Fi to avoid collisions by sensing the carrier before transmitting.
Q70: What is ARP?
ARP (Address Resolution Protocol) resolves an IP address to a MAC address on the same local network.
Q71: What is ICMP?
ICMP (Internet Control Message Protocol) is used for error reporting and diagnostics, such as ping.
Q72: What is ping?
Ping uses ICMP Echo Request and Echo Reply to test connectivity between devices.
Q73: What is traceroute?
Traceroute shows the path packets take through intermediate routers to a destination.
Q74: What is a hostname?
A hostname is a human-readable label for a device or server, such as web01.
Q75: What is a domain name?
A domain name is a name used for websites and services, such as example.com.
Q76: What is DNS resolution?
DNS resolution is the process of converting a domain name into an IP address.
Q77: What is a recursive DNS query?
A recursive DNS query asks a resolver to fully resolve a name on behalf of the client.
Q78: What is a DNS resolver?
A DNS resolver is the server that answers DNS queries from clients.
Q79: What is caching in DNS?
Caching stores previously resolved DNS answers to speed up future lookups.
Q80: What is a DNS record?
A DNS record stores information such as A, AAAA, MX, CNAME, and TXT records.
Q81: What is an A record?
An A record maps a hostname to an IPv4 address.
Q82: What is an AAAA record?
An AAAA record maps a hostname to an IPv6 address.
Q83: What is a CNAME record?
A CNAME record aliases one hostname to another hostname.
Q84: What is an MX record?
An MX record specifies the mail server responsible for a domain.
Q85: What is a TXT record?
A TXT record stores arbitrary text, often used for SPF, DKIM, or verification data.
Q86: What is HTTP?
HTTP (Hypertext Transfer Protocol) is the protocol used for transferring web pages and resources.
Q87: What is HTTPS?
HTTPS is HTTP over TLS/SSL, providing encryption and identity verification.
Q88: What is TLS?
TLS (Transport Layer Security) encrypts communications and authenticates endpoints.
Q89: What is SSL?
SSL (Secure Sockets Layer) is the older predecessor to TLS.
Q90: What is a TCP handshake?
The TCP handshake is the sequence of SYN, SYN-ACK, and ACK used to establish a connection.
Q91: What is a three-way handshake?
A three-way handshake is the standard process used by TCP to connect two endpoints.
Q92: What is session establishment?
Session establishment is the process of creating a communication state before data transfer begins.
Q93: What is the purpose of sequence numbers?
Sequence numbers help TCP track the order of bytes and detect missing or duplicated data.
Q94: What is acknowledgement?
Acknowledgement is the confirmation that data has been received successfully.
Q95: What is flow control?
Flow control prevents a sender from overwhelming a receiver with too much data at once.
Q96: What is congestion control?
Congestion control helps prevent network overload by reducing transmission rates when congestion is detected.
Q97: What is window size?
Window size is the amount of data a receiver is willing to accept at once.
Q98: What is connection teardown?
Connection teardown is the process of closing a TCP connection cleanly.
Q99: What is a FIN packet?
A FIN packet indicates the sender has no more data to send.
Q100: What is a SYN flood?
A SYN flood is a denial-of-service attack that overwhelms a server with half-open TCP connections.
Q101: What is a port scan?
A port scan probes multiple ports to discover which services are exposed.
Q102: What is a firewall rule?
A firewall rule defines which traffic is allowed or denied based on source, destination, port, and protocol.
Q103: What is a VPN?
A VPN (Virtual Private Network) creates an encrypted tunnel over a public network.
Q104: What is tunneling?
Tunneling wraps one protocol inside another, often for private communication over a public network.
Q105: What is a proxy?
A proxy is an intermediary server that forwards requests between clients and servers.
Q106: What is a forward proxy?
A forward proxy acts on behalf of a client requesting resources from the internet.
Q107: What is a reverse proxy?
A reverse proxy sits in front of servers and handles requests on their behalf.
Q108: What is load balancing?
Load balancing distributes traffic across multiple servers to improve performance and availability.
Q109: What is a web server?
A web server serves web resources such as HTML, CSS, images, and APIs over HTTP or HTTPS.
Q110: What is an application server?
An application server runs application logic and often serves business functions behind a web layer.
Q111: What is a database server?
A database server stores and serves structured data used by applications.
Q112: What is a DNS server?
A DNS server resolves domain names to IP addresses.
Q113: What is DHCP lease?
A DHCP lease is the temporary assignment of an IP address to a device.
Q114: What is APIPA?
APIPA (Automatic Private IP Addressing) assigns a self-contained private IP when DHCP fails, usually in the 169.254.0.0/16 range.
Q115: What is a broadcast address?
A broadcast address sends traffic to all devices in a network.
Q116: What is multicast?
Multicast sends data to a selected group of hosts rather than all hosts or a single host.
Q117: What is anycast?
Anycast sends packets to the nearest or best destination among multiple servers with the same address.
Q118: What is a route?
A route is a path or rule describing how packets should be forwarded to a destination.
Q119: What is a routing table?
A routing table contains destination networks and the next hop used to reach them.
Q120: What is a next hop?
A next hop is the next router or network device to which a packet should be forwarded.
Intermediate
Q121: What is subnet mask notation?
Subnet masks are often written as CIDR notation like /24 or dotted decimal like 255.255.255.0.
Q122: What is CIDR?
CIDR (Classless Inter-Domain Routing) is a method for allocating IP addresses and routing more flexibly than the old class-based system.
Q123: What is VLSM?
VLSM (Variable Length Subnet Masking) allows different subnet sizes within the same address block.
Q124: How do you calculate subnet size?
Subnet size depends on the number of host bits. More host bits means more addresses per subnet, fewer subnets.
Q125: What is a network address?
A network address is the first address in a subnet and is not usually assigned to hosts.
Q126: What is a broadcast address?
A broadcast address is the last address in a subnet used to reach all hosts inside it.
Q127: Why do subnets exist?
Subnets reduce broadcast domains, improve routing efficiency, and help organize networks by function or geography.
Q128: What is a broadcast domain?
A broadcast domain is a network segment where broadcast traffic reaches all devices.
Q129: What is a collision domain?
A collision domain is a network segment where multiple devices contend for the same medium.
Q130: Why are switches preferred over hubs?
Switches reduce collisions and allow simultaneous communication per port.
Q131: What is a VLAN?
A VLAN (Virtual LAN) logically segments a network without changing physical topology.
Q132: Why use VLANs?
VLANs improve network segmentation, performance, and security.
Q133: What is trunking?
Trunking carries multiple VLANs across a link between switches.
Q134: What is IEEE 802.1Q?
IEEE 802.1Q is the VLAN tagging standard used on Ethernet networks.
Q135: What is static routing?
Static routing uses manually configured routes.
Q136: What is dynamic routing?
Dynamic routing uses protocols such as OSPF and BGP to automatically learn routes.
Q137: What is OSPF?
OSPF (Open Shortest Path First) is a link-state routing protocol widely used inside enterprise networks.
Q138: What is BGP?
BGP (Border Gateway Protocol) is used to exchange routing information between autonomous systems on the internet.
Q139: What is an autonomous system?
An autonomous system is a collection of IP networks under a single administrative control.
Q140: What is RIP?
RIP (Routing Information Protocol) is a legacy distance-vector protocol used in smaller networks.
Q141: What is a routing loop?
A routing loop occurs when packets circle between routers without reaching their destination.
Q142: How do routers avoid loops?
They use metrics, route aging, split horizon, and link-state information.
Q143: What is a default route?
A default route is the route used when there is no specific route for a destination.
Q144: What is a metric?
A metric is a value used to choose between multiple possible routes.
Q145: What is a hop count?
A hop count is the number of routers a packet passes through.
Q146: What is path MTU discovery?
MTU discovery finds the largest packet size that can pass without fragmentation.
Q147: What is fragmentation?
Fragmentation splits a packet into smaller parts when it exceeds the MTU of a link.
Q148: Why is fragmentation sometimes bad?
It adds overhead, complexity, and may hurt performance or reliability.
Q149: What is DNS forwarder?
A DNS forwarder sends unresolved queries to another DNS server.
Q150: What is a DNS zone?
A DNS zone is a portion of the DNS namespace managed by a specific authority.
Q151: What is recursive resolver?
A recursive resolver performs the work of resolving a domain name by querying other servers.
Q152: What is authoritative DNS?
Authoritative DNS servers provide the final answer for a domain’s records.
Q153: What is TTL?
TTL (Time To Live) is the time a DNS record is cached before refresh.
Q154: What is the difference between TCP and HTTP?
TCP is the transport protocol responsible for connection and reliability. HTTP is an application protocol that defines resource requests and responses.
Q155: What is the HTTP request lifecycle?
A client sends a request, the server processes it, and returns a response.
Q156: What is an HTTP status code?
A status code tells the client the result of the request, such as 200, 404, or 500.
Q157: What is HTTP keep-alive?
HTTP keep-alive reuses a TCP connection for multiple HTTP requests.
Q158: What is HTTP/1.1?
HTTP/1.1 is a widely used HTTP version with persistent connections and pipelining support.
Q159: What is HTTP/2?
HTTP/2 introduces multiplexing, header compression, and binary framing for improved performance.
Q160: What is HTTP/3?
HTTP/3 runs over QUIC instead of TCP, reducing latency and improving multiplexing.
Q161: What is QUIC?
QUIC is a transport protocol designed for low-latency, secure, multiplexed network communication.
Q162: What is TLS handshake?
The TLS handshake negotiates protocol version, certificates, and session keys before secure communication.
Q163: Why is TLS needed?
TLS protects data in transit from eavesdropping, tampering, and impersonation.
Q164: What is certificate validation?
Certificate validation ensures the server identity presented is trusted and matches the expected hostname.
Q165: What is a certificate authority?
A certificate authority signs digital certificates used to establish trust in TLS.
Q166: What is mTLS?
mTLS (mutual TLS) requires both client and server to authenticate using certificates.
Q167: What is a socket pair?
A socket pair is the pair of local and remote endpoints used for a TCP or UDP connection.
Q168: What is a half-open connection?
A half-open connection exists when one side has accepted or sent data while the other side is not fully established.
Q169: What is connection pooling?
Connection pooling reuses existing network connections instead of creating new ones repeatedly.
Q170: What is a reverse DNS lookup?
A reverse DNS lookup resolves an IP address back to a hostname.
Q171: What is a packet sniffer?
A packet sniffer captures network traffic for analysis and troubleshooting.
Q172: What is Wireshark?
Wireshark is a widely used packet analysis tool for inspecting network traffic.
Q173: What is netstat?
netstat displays active network connections and listening ports on a device.
Q174: What is ss?
ss is a modern Linux socket inspection tool similar to netstat.
Q175: What is iptables?
iptables is a Linux firewall utility that filters and forwards network traffic.
Q176: What is nftables?
nftables is a modern Linux firewall framework replacing older iptables-based filtering.
Q177: What is a NAT table?
A NAT table maps internal addresses to external addresses and ports for internet access.
Q178: What is port forwarding?
Port forwarding redirects traffic arriving on a port to another device or port.
Q179: What is a DMZ?
A DMZ (Demilitarized Zone) is a network segment hosting public-facing services separate from internal networks.
Q180: What is segmentation?
Segmentation divides networks into smaller logical or physical areas to isolate traffic and improve security.
Q181: What is a VPN concentrator?
A VPN concentrator handles many IPSec or SSL VPN connections from clients.
Q182: What is network address planning?
Network address planning assigns subnets and IP ranges logically to reduce conflict, support growth, and maintain security.
Q183: What is the role of NAT in IPv4?
NAT allows private IPv4 networks to share a smaller set of public addresses.
Q184: What is a private/public split in routing?
Private addresses are not routable on the public internet; public addresses are.
Q185: Why do networks need DNS and DHCP together?
DNS resolves names; DHCP provides addresses and network config. Together they make devices usable without manual configuration.
Q186: What is host discovery?
Host discovery identifies active devices on a network, often using ping or ARP.
Q187: What is network scanning?
Network scanning explores a range of hosts, ports, or services to understand the network.
Q188: What is a network edge?
The network edge is where local networks meet external networks or the internet.
Q189: What is a local route?
A local route is used to send traffic directly to devices within the same network.
Q190: What is a remote route?
A remote route forwards traffic to a different network or destination.
Q191: What is a routing protocol?
A routing protocol is a set of rules for routers to exchange and compute routes.
Q192: What is a link-state protocol?
A link-state protocol shares network topology information so routers can compute shortest paths.
Q193: What is a distance-vector protocol?
A distance-vector protocol exchanges routing tables and chooses routes based on distance metrics.
Q194: What is packet encapsulation?
Packet encapsulation wraps a packet with protocol headers as it moves down the stack.
Q195: What is decapsulation?
Decapsulation removes protocol headers as data moves up the network stack toward the application.
Q196: Why is understanding layering important?
Layering helps explain how protocols interact and why debugging network issues requires checking multiple layers.
Q197: What is network troubleshooting?
Network troubleshooting is the process of identifying and fixing connectivity, performance, and configuration problems.
Q198: What is end-to-end connectivity?
End-to-end connectivity means a packet can travel from one host to another across all required network layers.
Q199: What is network reliability?
Network reliability is the ability to provide consistent connectivity and service despite failures or congestion.
Q200: What is the main goal of networking fundamentals?
The goal is to understand how data moves, how devices identify each other, and how networks remain reliable, scalable, and secure.
Advanced / Expert
Q201: What is the OSI model from a practical viewpoint?
It is a conceptual tool for understanding where a network problem may exist, such as physical media, addressing, routing, or application protocol errors.
Q202: What is the role of link-layer addressing?
Link-layer addressing such as MAC addresses is used only within a local segment and is not routed across the internet.
Q203: How does IP routing work?
Routers use destination IP addresses, routing tables, and longest-prefix matching to forward packets.
Q204: What is longest-prefix matching?
Longest-prefix matching selects the most specific route for a destination among multiple routing table entries.
Q205: Why is route aggregation useful?
Route aggregation reduces routing table size and improves scalability in large networks.
Q206: What is BGP route propagation?
BGP routers exchange network reachability information across autonomous systems, allowing internet-scale routing.
Q207: What is policy routing?
Policy routing forwards traffic based on rules beyond destination prefix, such as source, protocol, or application-specific criteria.
Q208: What is ECMP?
Equal-Cost Multi-Path routing sends traffic across multiple equal-cost paths for load balancing and redundancy.
Q209: What is MPLS?
MPLS (Multiprotocol Label Switching) uses labels for faster forwarding in service provider and enterprise networks.
Q210: What is QoS?
QoS (Quality of Service) prioritizes traffic classes to improve latency, reliability, or throughput for critical applications.
Q211: What is traffic shaping?
Traffic shaping controls the rate or pattern of transmitted traffic to enforce policy or avoid congestion.
Q212: What is traffic policing?
Traffic policing enforces limits by dropping or marking packets that exceed configured thresholds.
Q213: What is network congestion?
Congestion occurs when demand exceeds available network capacity, causing queue growth and packet loss.
Q214: What is AIMD?
AIMD (Additive Increase / Multiplicative Decrease) is a standard congestion control strategy in TCP.
Q215: How does TCP congestion control work?
TCP increases data flow gradually and reduces it sharply when packet loss or delay indicates congestion.
Q216: What is slow start?
Slow start is the initial phase of TCP congestion control where the sender starts conservatively and ramps up quickly.
Q217: What is fast retransmit?
Fast retransmit detects missing packets and retransmits them before the retransmission timeout expires.
Q218: What is fast recovery?
Fast recovery speeds normal transmission after a packet loss, instead of waiting for a full timeout cycle.
Q219: What is additive increase?
Additive increase means the sender gradually increases the congestion window as network conditions allow.
Q220: What is multiplicative decrease?
Multiplicative decrease reduces the congestion window sharply when congestion is detected.
Q221: What is dual-stack networking?
Dual-stack networking supports both IPv4 and IPv6 simultaneously on the same device or network.
Q222: What is NAT64?
NAT64 allows IPv6-only clients to communicate with IPv4 servers through translation.
Q223: What is DNS64?
DNS64 synthesizes AAAA records for IPv6 clients so they can access IPv4-only services via NAT64.
Q224: What is anycast DNS?
Anycast DNS sends queries to the nearest DNS server replica, improving resilience and latency.
Q225: What is HTTP connection reuse?
HTTP connection reuse reduces overhead by keeping existing TCP connections open for multiple requests.
Q226: What is connection coalescing?
Connection coalescing merges multiple logical network connections into fewer physical connections for efficiency.
Q227: What is multiplexing?
Multiplexing allows multiple independent streams or requests to share a single connection efficiently.
Q228: What is head-of-line blocking?
Head-of-line blocking occurs when one delayed packet blocks the delivery of others in the same flow.
Q229: Why did HTTP/2 and QUIC address HOL blocking?
Because older TCP-based architectures have issues with blocking, especially under loss conditions.
Q230: What is QUIC 0-RTT?
0-RTT allows reconnection without full handshake when connection context is already known.
Q231: Why is TLS important for HTTP/3?
HTTP/3 runs over QUIC, which integrates encryption at the transport layer.
Q232: What is a SYN cookie?
A SYN cookie is a technique used to protect servers from SYN flood attacks without storing many half-open connections.
Q233: What is a DDoS attack?
A DDoS attack overwhelms a target with a flood of traffic from many sources, often distributed across botnets.
Q234: How do networks mitigate DDoS?
By rate limiting, filtering, CDN use, scrubbing centers, and distributed defense systems.
Q235: What is a CDN?
A CDN (Content Delivery Network) caches content near users to improve performance and reduce origin load.
Q236: What is load balancer health checking?
Health checks verify that backend servers are available before sending traffic to them.
Q237: What is session affinity?
Session affinity keeps a client connected to the same backend for repeated requests, often for stateful workloads.
Q238: What is a network intrusion?
A network intrusion is unauthorized access or malicious activity on a network.
Q239: What is packet filtering?
Packet filtering allows or denies traffic based on network attributes such as IP, port, and protocol.
Q240: What is deep packet inspection?
Deep packet inspection examines packet payloads to identify patterns, protocols, or malicious content.
Q241: What is a transparent proxy?
A transparent proxy intercepts traffic without requiring client configuration.
Q242: What is an explicit proxy?
An explicit proxy requires clients to configure proxy settings.
Q243: What is an ingress controller?
An ingress controller manages inbound traffic into a Kubernetes or application environment.
Q244: What is egress filtering?
Egress filtering restricts outbound traffic to approved destinations and services.
Q245: What is ACL?
An ACL (Access Control List) defines which traffic is allowed or denied based on matching rules.
Q246: What is network segmentation for security?
It isolates critical systems from general user traffic to reduce lateral movement and blast radius.
Q247: What is lateral movement?
Lateral movement is the movement of an attacker across internal systems after initial access.
Q248: What is network forensic analysis?
Network forensic analysis inspects network data to understand what happened during a security event.
Q249: What is packet capture retention?
Packet capture retention is the storage policy for captured traffic used for troubleshooting or investigations.
Q250: What is network telemetry?
Network telemetry is observations from network devices such as flows, counters, and packet statistics.
Q251: What is NetFlow?
NetFlow is a protocol for collecting IP traffic metadata for analysis and capacity planning.
Q252: What is sFlow?
sFlow samples network traffic and exports metadata for monitoring and analytics.
Q253: What is SNMP?
SNMP (Simple Network Management Protocol) is used to monitor and manage network devices.
Q254: What is RMON?
RMON (Remote Monitoring) provides remote monitoring of network traffic and device health.
Q255: What is a management plane?
The management plane handles device configuration, monitoring, and operational control.
Q256: What is a control plane?
The control plane decides how packets are routed and how network state is computed.
Q257: What is a data plane?
The data plane forwards actual user traffic based on the decisions of the control plane.
Q258: Why is separation of control and data planes important?
It improves scalability, manageability, and operational clarity in modern networks.
Q259: What is SDN?
SDN (Software-Defined Networking) decouples the control plane from the data plane for centralized management and automation.
Q260: What is NFV?
NFV (Network Functions Virtualization) runs network functions such as routers and firewalls as software instead of dedicated hardware.
Q261: What is overlay networking?
Overlay networking creates a virtual network on top of an underlying physical network.
Q262: What is VXLAN?
VXLAN is a tunneling protocol used for overlay networking in data centers and cloud environments.
Q263: What is underlay networking?
Underlay networking is the physical or infrastructure network that carries overlay traffic.
Q264: What is network virtualization?
Network virtualization abstracts physical networking resources into logical networks and services.
Q265: What is hardware offload?
Hardware offload moves tasks such as packet filtering or encryption into optimized hardware for performance gains.
Q266: What is NIC teaming?
NIC teaming combines multiple network interfaces to provide redundancy or higher throughput.
Q267: What is a network sensor?
A network sensor monitors traffic for anomalies, inspection, or security detection.
Q268: What is network forensics?
Network forensics reconstructs events using captured data, packet traces, and traffic logs.
Q269: What is a packet capture timestamp?
Packet timestamps are used to reconstruct timing and ordering across network events.
Q270: What is a handshake timeout?
A handshake timeout occurs when a TCP connection cannot be established within an expected time window.
Q271: What is a retransmission timeout?
A retransmission timeout occurs when a sender waits too long without acknowledgment and re-sends the data.
Q272: What is slow path forwarding?
Slow path forwarding is packet handling by software or control logic rather than hardware acceleration.
Q273: What is fast path forwarding?
Fast path forwarding is optimized hardware-level forwarding of traffic.
Q274: What is packet classification?
Packet classification identifies traffic type or policy group based on fields like IP, port, and protocol.
Q275: What is a service chain?
A service chain is a sequence of network functions applied to a packet, such as firewall, NAT, and load balancing.
Q276: What is zero-trust networking?
Zero-trust networking assumes no trust by default and requires verification for every access request.
Q277: What is identity-based networking?
Identity-based networking authorizes traffic or access based on identity rather than just network location.
Q278: Why is network automation important?
Automation reduces human errors, speeds changes, and enables consistent deployment at scale.
Q279: What is intent-based networking?
Intent-based networking allows administrators to define desired outcomes, and the system translates them into configuration.
Q280: What is network observability?
Network observability is the ability to infer full behavior of a network from telemetry, logs, and traces.
Q281: What is the relationship between networking and cloud?
Cloud networking abstracts physical infrastructure into virtual networks, load balancers, VPCs, and service discovery.
Q282: What is VPC?
A VPC (Virtual Private Cloud) is a private, isolated network environment in the cloud.
Q283: What is a subnet in cloud networking?
A cloud subnet is a segment of a VPC used to isolate workloads and manage routing.
Q284: What is a security group?
A security group is a cloud firewall rule set applied to instances or workloads.
Q285: What is an availability zone?
An availability zone is an isolated data center location used in cloud platforms for resilience.
Q286: What is an edge network?
An edge network is the boundary between end users and backend services, often involving CDNs and regional gateways.
Q287: What is network latency budget design?
Latency budget design assigns acceptable delay targets to services, dependencies, and network hops.
Q288: Why is network design about trade-offs?
Because performance, security, cost, and complexity often pull in different directions.
Q289: What is the hardest part of networking?
The hardest part is often understanding interactions between protocols, topology, policy, and real-world failures.
Q290: What is the long-term value of understanding networking?
It helps engineers diagnose system behavior, design scalable systems, and build secure, reliable communication paths.