Networking Fundamentals

Networking Fundamentals


Beginner

Q1: What is a computer network?

A computer network is a collection of connected devices that can communicate with each other and share resources.

Q2: Why do networks matter?

Networks allow computers to share data, applications, printers, storage, and internet access efficiently.

Q3: What is a node in a network?

A node is any device connected to the network, such as a computer, router, switch, server, or mobile device.

Q4: What is a protocol?

A protocol is a set of rules that defines how devices communicate over a network.

Q5: What is the Internet?

The Internet is a global network of interconnected networks using standard protocols such as TCP/IP.

Q6: What is a LAN?

A LAN (Local Area Network) is a network confined to a small geographic area such as a home, office, or campus.

Q7: What is a WAN?

A WAN (Wide Area Network) connects networks over a large geographical area, such as cities, countries, or continents.

Q8: What is a MAN?

A MAN (Metropolitan Area Network) covers a metropolitan area, usually larger than a LAN but smaller than a WAN.

Q9: What is a PAN?

A PAN (Personal Area Network) is a small network used around an individual, such as Bluetooth devices.

Q10: What is the difference between a switch and a router?

A switch connects devices within the same network segment. A router connects different networks and directs traffic between them.

Q11: What is an IP address?

An IP address is a unique identifier assigned to a network device so it can be located and reached.

Q12: What is IPv4?

IPv4 is the fourth version of the Internet Protocol and uses 32-bit addresses.

Q13: What is IPv6?

IPv6 is the next-generation IP protocol using 128-bit addresses to provide a much larger address space.

Q14: How many addresses can IPv4 support?

IPv4 supports about 4.3 billion unique addresses, which is no longer enough for the modern internet.

Q15: Why is IPv6 needed?

IPv6 addresses the exhaustion of IPv4 addresses and adds improvements like simpler configuration and better security design.

Q16: What does a MAC address do?

A MAC address uniquely identifies a network interface card (NIC) on the local network.

Q17: What is the difference between IP and MAC addresses?

An IP address identifies a device on a network layer. A MAC address identifies the hardware interface on the local link.

Q18: What is a subnet?

A subnet is a smaller network created by dividing a larger IP network into segments.

Q19: What is subnetting?

Subnetting is the process of splitting a larger network into smaller sub-networks for better organization and efficiency.

Q20: What is a subnet mask?

A subnet mask is used with an IP address to determine the network and host portions of the address.

Q21: What is a default gateway?

A default gateway is the device that forwards traffic from a local network to other networks, such as the internet.

Q22: What is DNS?

DNS (Domain Name System) translates human-readable domain names like example.com into IP addresses.

Q23: What is DHCP?

DHCP (Dynamic Host Configuration Protocol) automatically assigns IP addresses and network settings to devices.

Q24: What is NAT?

NAT (Network Address Translation) allows multiple devices on a private network to share one public IP address.

Q25: What is a private IP address range?

Private IP addresses are ranges reserved for internal networks and are not routable on the public internet.

Q26: What are the private IPv4 ranges?

  • 10.0.0.0/8
  • 172.16.0.0/12
  • 192.168.0.0/16

Q27: What is a public IP address?

A public IP address is reachable from the internet and is assigned to a device or network router.

Q28: What is a loopback address?

A loopback address is used by a device to send traffic to itself, commonly 127.0.0.1 for IPv4 and ::1 for IPv6.

Q29: What is a port?

A port is a numbered endpoint used by transport layer protocols to identify specific services or applications.

Q30: What is a socket?

A socket is an endpoint for communication, identified by IP address and port number.

Q31: What is TCP?

TCP (Transmission Control Protocol) is a connection-oriented protocol that provides reliable, ordered delivery.

Q32: What is UDP?

UDP (User Datagram Protocol) is a connectionless protocol designed for speed, often used in streaming or DNS.

Q33: What is the difference between TCP and UDP?

TCP provides reliability and ordering. UDP is faster and simpler but does not guarantee delivery or ordering.

Q34: What is the OSI model?

The OSI model is a 7-layer reference model for understanding how network communication works.

Q35: What are the OSI layers?

  1. Physical
  2. Data Link
  3. Network
  4. Transport
  5. Session
  6. Presentation
  7. Application

Q36: What is the TCP/IP model?

The TCP/IP model is the practical networking model used on the internet, usually simplified into 4 or 5 layers.

Q37: What are the main TCP/IP layers?

  • Link
  • Internet
  • Transport
  • Application

Q38: What does the physical layer do?

The physical layer deals with the actual transmission of bits over a cable, radio signal, or optical fiber.

Q39: What does the data link layer do?

It handles local delivery between devices on the same network segment, often using MAC addresses.

Q40: What does the network layer do?

The network layer handles routing and delivery between networks using IP addresses.

Q41: What does the transport layer do?

The transport layer provides data delivery services such as connection setup, reliability, and segmentation.

Q42: What does the application layer do?

The application layer contains protocols used by programs, such as HTTP, DNS, SMTP, and SSH.

Q43: What is a packet?

A packet is a formatted unit of data transmitted over a network.

Q44: What is a frame?

A frame is the Data Link layer unit of data, containing a header, payload, and trailer.

Q45: What is a segment?

A segment is the Transport layer PDU for TCP or UDP.

Q46: What is a datagram?

A datagram is a self-contained packet, often associated with UDP.

Q47: What is a router?

A router forwards packets between networks based on IP routing information.

Q48: What is a switch?

A switch forwards frames within a local area network using MAC addresses.

Q49: What is a hub?

A hub is a basic device that repeats signals to all connected devices, unlike a switch.

Q50: What is a firewall?

A firewall filters traffic based on security rules to control what enters or leaves a network.

Q51: What is a network interface?

A network interface is the hardware or software component that connects a device to a network.

Q52: What is bandwidth?

Bandwidth is the maximum rate at which data can be transferred over a network link.

Q53: What is latency?

Latency is the time delay between sending a packet and receiving it.

Q54: What is throughput?

Throughput is the actual data rate achieved at application level, often lower than theoretical bandwidth.

Q55: What is RTT?

RTT (Round Trip Time) is the time for a packet to travel to a destination and back.

Q56: What is packet loss?

Packet loss occurs when packets are dropped during transmission, often due to congestion or errors.

Q57: What is jitter?

Jitter is variation in packet delay, which can affect real-time traffic like VoIP and video.

Q58: What is a connectionless protocol?

A connectionless protocol does not establish a dedicated session before sending data.

Q59: What is a connection-oriented protocol?

A connection-oriented protocol establishes a session before sending data and verifies delivery.

Q60: What is a network topology?

A network topology describes the physical or logical arrangement of devices and links in a network.

Q61: What is bus topology?

In bus topology, all devices share a single communication medium.

Q62: What is star topology?

In star topology, all devices connect to a central device such as a switch or hub.

Q63: What is ring topology?

In ring topology, devices are connected in a circular path.

Q64: What is mesh topology?

In mesh topology, devices have multiple redundant links to others for resilience.

Q65: What is a NIC?

A NIC (Network Interface Card) is the physical or virtual interface used to connect a device to a network.

Q66: What is Ethernet?

Ethernet is the dominant LAN technology used for wired networking.

Q67: What is Wi-Fi?

Wi-Fi is a wireless local network technology based on IEEE 802.11 standards.

Q68: What is CSMA/CD?

CSMA/CD (Carrier Sense Multiple Access with Collision Detection) was used in Ethernet hubs before switches dominated.

Q69: What is CSMA/CA?

CSMA/CA is used in Wi-Fi to avoid collisions by sensing the carrier before transmitting.

Q70: What is ARP?

ARP (Address Resolution Protocol) resolves an IP address to a MAC address on the same local network.

Q71: What is ICMP?

ICMP (Internet Control Message Protocol) is used for error reporting and diagnostics, such as ping.

Q72: What is ping?

Ping uses ICMP Echo Request and Echo Reply to test connectivity between devices.

Q73: What is traceroute?

Traceroute shows the path packets take through intermediate routers to a destination.

Q74: What is a hostname?

A hostname is a human-readable label for a device or server, such as web01.

Q75: What is a domain name?

A domain name is a name used for websites and services, such as example.com.

Q76: What is DNS resolution?

DNS resolution is the process of converting a domain name into an IP address.

Q77: What is a recursive DNS query?

A recursive DNS query asks a resolver to fully resolve a name on behalf of the client.

Q78: What is a DNS resolver?

A DNS resolver is the server that answers DNS queries from clients.

Q79: What is caching in DNS?

Caching stores previously resolved DNS answers to speed up future lookups.

Q80: What is a DNS record?

A DNS record stores information such as A, AAAA, MX, CNAME, and TXT records.

Q81: What is an A record?

An A record maps a hostname to an IPv4 address.

Q82: What is an AAAA record?

An AAAA record maps a hostname to an IPv6 address.

Q83: What is a CNAME record?

A CNAME record aliases one hostname to another hostname.

Q84: What is an MX record?

An MX record specifies the mail server responsible for a domain.

Q85: What is a TXT record?

A TXT record stores arbitrary text, often used for SPF, DKIM, or verification data.

Q86: What is HTTP?

HTTP (Hypertext Transfer Protocol) is the protocol used for transferring web pages and resources.

Q87: What is HTTPS?

HTTPS is HTTP over TLS/SSL, providing encryption and identity verification.

Q88: What is TLS?

TLS (Transport Layer Security) encrypts communications and authenticates endpoints.

Q89: What is SSL?

SSL (Secure Sockets Layer) is the older predecessor to TLS.

Q90: What is a TCP handshake?

The TCP handshake is the sequence of SYN, SYN-ACK, and ACK used to establish a connection.

Q91: What is a three-way handshake?

A three-way handshake is the standard process used by TCP to connect two endpoints.

Q92: What is session establishment?

Session establishment is the process of creating a communication state before data transfer begins.

Q93: What is the purpose of sequence numbers?

Sequence numbers help TCP track the order of bytes and detect missing or duplicated data.

Q94: What is acknowledgement?

Acknowledgement is the confirmation that data has been received successfully.

Q95: What is flow control?

Flow control prevents a sender from overwhelming a receiver with too much data at once.

Q96: What is congestion control?

Congestion control helps prevent network overload by reducing transmission rates when congestion is detected.

Q97: What is window size?

Window size is the amount of data a receiver is willing to accept at once.

Q98: What is connection teardown?

Connection teardown is the process of closing a TCP connection cleanly.

Q99: What is a FIN packet?

A FIN packet indicates the sender has no more data to send.

Q100: What is a SYN flood?

A SYN flood is a denial-of-service attack that overwhelms a server with half-open TCP connections.

Q101: What is a port scan?

A port scan probes multiple ports to discover which services are exposed.

Q102: What is a firewall rule?

A firewall rule defines which traffic is allowed or denied based on source, destination, port, and protocol.

Q103: What is a VPN?

A VPN (Virtual Private Network) creates an encrypted tunnel over a public network.

Q104: What is tunneling?

Tunneling wraps one protocol inside another, often for private communication over a public network.

Q105: What is a proxy?

A proxy is an intermediary server that forwards requests between clients and servers.

Q106: What is a forward proxy?

A forward proxy acts on behalf of a client requesting resources from the internet.

Q107: What is a reverse proxy?

A reverse proxy sits in front of servers and handles requests on their behalf.

Q108: What is load balancing?

Load balancing distributes traffic across multiple servers to improve performance and availability.

Q109: What is a web server?

A web server serves web resources such as HTML, CSS, images, and APIs over HTTP or HTTPS.

Q110: What is an application server?

An application server runs application logic and often serves business functions behind a web layer.

Q111: What is a database server?

A database server stores and serves structured data used by applications.

Q112: What is a DNS server?

A DNS server resolves domain names to IP addresses.

Q113: What is DHCP lease?

A DHCP lease is the temporary assignment of an IP address to a device.

Q114: What is APIPA?

APIPA (Automatic Private IP Addressing) assigns a self-contained private IP when DHCP fails, usually in the 169.254.0.0/16 range.

Q115: What is a broadcast address?

A broadcast address sends traffic to all devices in a network.

Q116: What is multicast?

Multicast sends data to a selected group of hosts rather than all hosts or a single host.

Q117: What is anycast?

Anycast sends packets to the nearest or best destination among multiple servers with the same address.

Q118: What is a route?

A route is a path or rule describing how packets should be forwarded to a destination.

Q119: What is a routing table?

A routing table contains destination networks and the next hop used to reach them.

Q120: What is a next hop?

A next hop is the next router or network device to which a packet should be forwarded.

Intermediate

Q121: What is subnet mask notation?

Subnet masks are often written as CIDR notation like /24 or dotted decimal like 255.255.255.0.

Q122: What is CIDR?

CIDR (Classless Inter-Domain Routing) is a method for allocating IP addresses and routing more flexibly than the old class-based system.

Q123: What is VLSM?

VLSM (Variable Length Subnet Masking) allows different subnet sizes within the same address block.

Q124: How do you calculate subnet size?

Subnet size depends on the number of host bits. More host bits means more addresses per subnet, fewer subnets.

Q125: What is a network address?

A network address is the first address in a subnet and is not usually assigned to hosts.

Q126: What is a broadcast address?

A broadcast address is the last address in a subnet used to reach all hosts inside it.

Q127: Why do subnets exist?

Subnets reduce broadcast domains, improve routing efficiency, and help organize networks by function or geography.

Q128: What is a broadcast domain?

A broadcast domain is a network segment where broadcast traffic reaches all devices.

Q129: What is a collision domain?

A collision domain is a network segment where multiple devices contend for the same medium.

Q130: Why are switches preferred over hubs?

Switches reduce collisions and allow simultaneous communication per port.

Q131: What is a VLAN?

A VLAN (Virtual LAN) logically segments a network without changing physical topology.

Q132: Why use VLANs?

VLANs improve network segmentation, performance, and security.

Q133: What is trunking?

Trunking carries multiple VLANs across a link between switches.

Q134: What is IEEE 802.1Q?

IEEE 802.1Q is the VLAN tagging standard used on Ethernet networks.

Q135: What is static routing?

Static routing uses manually configured routes.

Q136: What is dynamic routing?

Dynamic routing uses protocols such as OSPF and BGP to automatically learn routes.

Q137: What is OSPF?

OSPF (Open Shortest Path First) is a link-state routing protocol widely used inside enterprise networks.

Q138: What is BGP?

BGP (Border Gateway Protocol) is used to exchange routing information between autonomous systems on the internet.

Q139: What is an autonomous system?

An autonomous system is a collection of IP networks under a single administrative control.

Q140: What is RIP?

RIP (Routing Information Protocol) is a legacy distance-vector protocol used in smaller networks.

Q141: What is a routing loop?

A routing loop occurs when packets circle between routers without reaching their destination.

Q142: How do routers avoid loops?

They use metrics, route aging, split horizon, and link-state information.

Q143: What is a default route?

A default route is the route used when there is no specific route for a destination.

Q144: What is a metric?

A metric is a value used to choose between multiple possible routes.

Q145: What is a hop count?

A hop count is the number of routers a packet passes through.

Q146: What is path MTU discovery?

MTU discovery finds the largest packet size that can pass without fragmentation.

Q147: What is fragmentation?

Fragmentation splits a packet into smaller parts when it exceeds the MTU of a link.

Q148: Why is fragmentation sometimes bad?

It adds overhead, complexity, and may hurt performance or reliability.

Q149: What is DNS forwarder?

A DNS forwarder sends unresolved queries to another DNS server.

Q150: What is a DNS zone?

A DNS zone is a portion of the DNS namespace managed by a specific authority.

Q151: What is recursive resolver?

A recursive resolver performs the work of resolving a domain name by querying other servers.

Q152: What is authoritative DNS?

Authoritative DNS servers provide the final answer for a domain’s records.

Q153: What is TTL?

TTL (Time To Live) is the time a DNS record is cached before refresh.

Q154: What is the difference between TCP and HTTP?

TCP is the transport protocol responsible for connection and reliability. HTTP is an application protocol that defines resource requests and responses.

Q155: What is the HTTP request lifecycle?

A client sends a request, the server processes it, and returns a response.

Q156: What is an HTTP status code?

A status code tells the client the result of the request, such as 200, 404, or 500.

Q157: What is HTTP keep-alive?

HTTP keep-alive reuses a TCP connection for multiple HTTP requests.

Q158: What is HTTP/1.1?

HTTP/1.1 is a widely used HTTP version with persistent connections and pipelining support.

Q159: What is HTTP/2?

HTTP/2 introduces multiplexing, header compression, and binary framing for improved performance.

Q160: What is HTTP/3?

HTTP/3 runs over QUIC instead of TCP, reducing latency and improving multiplexing.

Q161: What is QUIC?

QUIC is a transport protocol designed for low-latency, secure, multiplexed network communication.

Q162: What is TLS handshake?

The TLS handshake negotiates protocol version, certificates, and session keys before secure communication.

Q163: Why is TLS needed?

TLS protects data in transit from eavesdropping, tampering, and impersonation.

Q164: What is certificate validation?

Certificate validation ensures the server identity presented is trusted and matches the expected hostname.

Q165: What is a certificate authority?

A certificate authority signs digital certificates used to establish trust in TLS.

Q166: What is mTLS?

mTLS (mutual TLS) requires both client and server to authenticate using certificates.

Q167: What is a socket pair?

A socket pair is the pair of local and remote endpoints used for a TCP or UDP connection.

Q168: What is a half-open connection?

A half-open connection exists when one side has accepted or sent data while the other side is not fully established.

Q169: What is connection pooling?

Connection pooling reuses existing network connections instead of creating new ones repeatedly.

Q170: What is a reverse DNS lookup?

A reverse DNS lookup resolves an IP address back to a hostname.

Q171: What is a packet sniffer?

A packet sniffer captures network traffic for analysis and troubleshooting.

Q172: What is Wireshark?

Wireshark is a widely used packet analysis tool for inspecting network traffic.

Q173: What is netstat?

netstat displays active network connections and listening ports on a device.

Q174: What is ss?

ss is a modern Linux socket inspection tool similar to netstat.

Q175: What is iptables?

iptables is a Linux firewall utility that filters and forwards network traffic.

Q176: What is nftables?

nftables is a modern Linux firewall framework replacing older iptables-based filtering.

Q177: What is a NAT table?

A NAT table maps internal addresses to external addresses and ports for internet access.

Q178: What is port forwarding?

Port forwarding redirects traffic arriving on a port to another device or port.

Q179: What is a DMZ?

A DMZ (Demilitarized Zone) is a network segment hosting public-facing services separate from internal networks.

Q180: What is segmentation?

Segmentation divides networks into smaller logical or physical areas to isolate traffic and improve security.

Q181: What is a VPN concentrator?

A VPN concentrator handles many IPSec or SSL VPN connections from clients.

Q182: What is network address planning?

Network address planning assigns subnets and IP ranges logically to reduce conflict, support growth, and maintain security.

Q183: What is the role of NAT in IPv4?

NAT allows private IPv4 networks to share a smaller set of public addresses.

Q184: What is a private/public split in routing?

Private addresses are not routable on the public internet; public addresses are.

Q185: Why do networks need DNS and DHCP together?

DNS resolves names; DHCP provides addresses and network config. Together they make devices usable without manual configuration.

Q186: What is host discovery?

Host discovery identifies active devices on a network, often using ping or ARP.

Q187: What is network scanning?

Network scanning explores a range of hosts, ports, or services to understand the network.

Q188: What is a network edge?

The network edge is where local networks meet external networks or the internet.

Q189: What is a local route?

A local route is used to send traffic directly to devices within the same network.

Q190: What is a remote route?

A remote route forwards traffic to a different network or destination.

Q191: What is a routing protocol?

A routing protocol is a set of rules for routers to exchange and compute routes.

Q192: What is a link-state protocol?

A link-state protocol shares network topology information so routers can compute shortest paths.

Q193: What is a distance-vector protocol?

A distance-vector protocol exchanges routing tables and chooses routes based on distance metrics.

Q194: What is packet encapsulation?

Packet encapsulation wraps a packet with protocol headers as it moves down the stack.

Q195: What is decapsulation?

Decapsulation removes protocol headers as data moves up the network stack toward the application.

Q196: Why is understanding layering important?

Layering helps explain how protocols interact and why debugging network issues requires checking multiple layers.

Q197: What is network troubleshooting?

Network troubleshooting is the process of identifying and fixing connectivity, performance, and configuration problems.

Q198: What is end-to-end connectivity?

End-to-end connectivity means a packet can travel from one host to another across all required network layers.

Q199: What is network reliability?

Network reliability is the ability to provide consistent connectivity and service despite failures or congestion.

Q200: What is the main goal of networking fundamentals?

The goal is to understand how data moves, how devices identify each other, and how networks remain reliable, scalable, and secure.

Advanced / Expert

Q201: What is the OSI model from a practical viewpoint?

It is a conceptual tool for understanding where a network problem may exist, such as physical media, addressing, routing, or application protocol errors.

Q202: What is the role of link-layer addressing?

Link-layer addressing such as MAC addresses is used only within a local segment and is not routed across the internet.

Q203: How does IP routing work?

Routers use destination IP addresses, routing tables, and longest-prefix matching to forward packets.

Q204: What is longest-prefix matching?

Longest-prefix matching selects the most specific route for a destination among multiple routing table entries.

Q205: Why is route aggregation useful?

Route aggregation reduces routing table size and improves scalability in large networks.

Q206: What is BGP route propagation?

BGP routers exchange network reachability information across autonomous systems, allowing internet-scale routing.

Q207: What is policy routing?

Policy routing forwards traffic based on rules beyond destination prefix, such as source, protocol, or application-specific criteria.

Q208: What is ECMP?

Equal-Cost Multi-Path routing sends traffic across multiple equal-cost paths for load balancing and redundancy.

Q209: What is MPLS?

MPLS (Multiprotocol Label Switching) uses labels for faster forwarding in service provider and enterprise networks.

Q210: What is QoS?

QoS (Quality of Service) prioritizes traffic classes to improve latency, reliability, or throughput for critical applications.

Q211: What is traffic shaping?

Traffic shaping controls the rate or pattern of transmitted traffic to enforce policy or avoid congestion.

Q212: What is traffic policing?

Traffic policing enforces limits by dropping or marking packets that exceed configured thresholds.

Q213: What is network congestion?

Congestion occurs when demand exceeds available network capacity, causing queue growth and packet loss.

Q214: What is AIMD?

AIMD (Additive Increase / Multiplicative Decrease) is a standard congestion control strategy in TCP.

Q215: How does TCP congestion control work?

TCP increases data flow gradually and reduces it sharply when packet loss or delay indicates congestion.

Q216: What is slow start?

Slow start is the initial phase of TCP congestion control where the sender starts conservatively and ramps up quickly.

Q217: What is fast retransmit?

Fast retransmit detects missing packets and retransmits them before the retransmission timeout expires.

Q218: What is fast recovery?

Fast recovery speeds normal transmission after a packet loss, instead of waiting for a full timeout cycle.

Q219: What is additive increase?

Additive increase means the sender gradually increases the congestion window as network conditions allow.

Q220: What is multiplicative decrease?

Multiplicative decrease reduces the congestion window sharply when congestion is detected.

Q221: What is dual-stack networking?

Dual-stack networking supports both IPv4 and IPv6 simultaneously on the same device or network.

Q222: What is NAT64?

NAT64 allows IPv6-only clients to communicate with IPv4 servers through translation.

Q223: What is DNS64?

DNS64 synthesizes AAAA records for IPv6 clients so they can access IPv4-only services via NAT64.

Q224: What is anycast DNS?

Anycast DNS sends queries to the nearest DNS server replica, improving resilience and latency.

Q225: What is HTTP connection reuse?

HTTP connection reuse reduces overhead by keeping existing TCP connections open for multiple requests.

Q226: What is connection coalescing?

Connection coalescing merges multiple logical network connections into fewer physical connections for efficiency.

Q227: What is multiplexing?

Multiplexing allows multiple independent streams or requests to share a single connection efficiently.

Q228: What is head-of-line blocking?

Head-of-line blocking occurs when one delayed packet blocks the delivery of others in the same flow.

Q229: Why did HTTP/2 and QUIC address HOL blocking?

Because older TCP-based architectures have issues with blocking, especially under loss conditions.

Q230: What is QUIC 0-RTT?

0-RTT allows reconnection without full handshake when connection context is already known.

Q231: Why is TLS important for HTTP/3?

HTTP/3 runs over QUIC, which integrates encryption at the transport layer.

Q232: What is a SYN cookie?

A SYN cookie is a technique used to protect servers from SYN flood attacks without storing many half-open connections.

Q233: What is a DDoS attack?

A DDoS attack overwhelms a target with a flood of traffic from many sources, often distributed across botnets.

Q234: How do networks mitigate DDoS?

By rate limiting, filtering, CDN use, scrubbing centers, and distributed defense systems.

Q235: What is a CDN?

A CDN (Content Delivery Network) caches content near users to improve performance and reduce origin load.

Q236: What is load balancer health checking?

Health checks verify that backend servers are available before sending traffic to them.

Q237: What is session affinity?

Session affinity keeps a client connected to the same backend for repeated requests, often for stateful workloads.

Q238: What is a network intrusion?

A network intrusion is unauthorized access or malicious activity on a network.

Q239: What is packet filtering?

Packet filtering allows or denies traffic based on network attributes such as IP, port, and protocol.

Q240: What is deep packet inspection?

Deep packet inspection examines packet payloads to identify patterns, protocols, or malicious content.

Q241: What is a transparent proxy?

A transparent proxy intercepts traffic without requiring client configuration.

Q242: What is an explicit proxy?

An explicit proxy requires clients to configure proxy settings.

Q243: What is an ingress controller?

An ingress controller manages inbound traffic into a Kubernetes or application environment.

Q244: What is egress filtering?

Egress filtering restricts outbound traffic to approved destinations and services.

Q245: What is ACL?

An ACL (Access Control List) defines which traffic is allowed or denied based on matching rules.

Q246: What is network segmentation for security?

It isolates critical systems from general user traffic to reduce lateral movement and blast radius.

Q247: What is lateral movement?

Lateral movement is the movement of an attacker across internal systems after initial access.

Q248: What is network forensic analysis?

Network forensic analysis inspects network data to understand what happened during a security event.

Q249: What is packet capture retention?

Packet capture retention is the storage policy for captured traffic used for troubleshooting or investigations.

Q250: What is network telemetry?

Network telemetry is observations from network devices such as flows, counters, and packet statistics.

Q251: What is NetFlow?

NetFlow is a protocol for collecting IP traffic metadata for analysis and capacity planning.

Q252: What is sFlow?

sFlow samples network traffic and exports metadata for monitoring and analytics.

Q253: What is SNMP?

SNMP (Simple Network Management Protocol) is used to monitor and manage network devices.

Q254: What is RMON?

RMON (Remote Monitoring) provides remote monitoring of network traffic and device health.

Q255: What is a management plane?

The management plane handles device configuration, monitoring, and operational control.

Q256: What is a control plane?

The control plane decides how packets are routed and how network state is computed.

Q257: What is a data plane?

The data plane forwards actual user traffic based on the decisions of the control plane.

Q258: Why is separation of control and data planes important?

It improves scalability, manageability, and operational clarity in modern networks.

Q259: What is SDN?

SDN (Software-Defined Networking) decouples the control plane from the data plane for centralized management and automation.

Q260: What is NFV?

NFV (Network Functions Virtualization) runs network functions such as routers and firewalls as software instead of dedicated hardware.

Q261: What is overlay networking?

Overlay networking creates a virtual network on top of an underlying physical network.

Q262: What is VXLAN?

VXLAN is a tunneling protocol used for overlay networking in data centers and cloud environments.

Q263: What is underlay networking?

Underlay networking is the physical or infrastructure network that carries overlay traffic.

Q264: What is network virtualization?

Network virtualization abstracts physical networking resources into logical networks and services.

Q265: What is hardware offload?

Hardware offload moves tasks such as packet filtering or encryption into optimized hardware for performance gains.

Q266: What is NIC teaming?

NIC teaming combines multiple network interfaces to provide redundancy or higher throughput.

Q267: What is a network sensor?

A network sensor monitors traffic for anomalies, inspection, or security detection.

Q268: What is network forensics?

Network forensics reconstructs events using captured data, packet traces, and traffic logs.

Q269: What is a packet capture timestamp?

Packet timestamps are used to reconstruct timing and ordering across network events.

Q270: What is a handshake timeout?

A handshake timeout occurs when a TCP connection cannot be established within an expected time window.

Q271: What is a retransmission timeout?

A retransmission timeout occurs when a sender waits too long without acknowledgment and re-sends the data.

Q272: What is slow path forwarding?

Slow path forwarding is packet handling by software or control logic rather than hardware acceleration.

Q273: What is fast path forwarding?

Fast path forwarding is optimized hardware-level forwarding of traffic.

Q274: What is packet classification?

Packet classification identifies traffic type or policy group based on fields like IP, port, and protocol.

Q275: What is a service chain?

A service chain is a sequence of network functions applied to a packet, such as firewall, NAT, and load balancing.

Q276: What is zero-trust networking?

Zero-trust networking assumes no trust by default and requires verification for every access request.

Q277: What is identity-based networking?

Identity-based networking authorizes traffic or access based on identity rather than just network location.

Q278: Why is network automation important?

Automation reduces human errors, speeds changes, and enables consistent deployment at scale.

Q279: What is intent-based networking?

Intent-based networking allows administrators to define desired outcomes, and the system translates them into configuration.

Q280: What is network observability?

Network observability is the ability to infer full behavior of a network from telemetry, logs, and traces.

Q281: What is the relationship between networking and cloud?

Cloud networking abstracts physical infrastructure into virtual networks, load balancers, VPCs, and service discovery.

Q282: What is VPC?

A VPC (Virtual Private Cloud) is a private, isolated network environment in the cloud.

Q283: What is a subnet in cloud networking?

A cloud subnet is a segment of a VPC used to isolate workloads and manage routing.

Q284: What is a security group?

A security group is a cloud firewall rule set applied to instances or workloads.

Q285: What is an availability zone?

An availability zone is an isolated data center location used in cloud platforms for resilience.

Q286: What is an edge network?

An edge network is the boundary between end users and backend services, often involving CDNs and regional gateways.

Q287: What is network latency budget design?

Latency budget design assigns acceptable delay targets to services, dependencies, and network hops.

Q288: Why is network design about trade-offs?

Because performance, security, cost, and complexity often pull in different directions.

Q289: What is the hardest part of networking?

The hardest part is often understanding interactions between protocols, topology, policy, and real-world failures.

Q290: What is the long-term value of understanding networking?

It helps engineers diagnose system behavior, design scalable systems, and build secure, reliable communication paths.