Skip to content
Tech Interview Prep home
Technical interview guide

Cloud Networking Fundamentals

VPCs, subnets, and security groups — the building blocks every other cloud topic assumes.

Read
22 min
Practice MCQs
25
Interview QA
25
Edition
v3
Editorial status
Reviewed

Scope: Vendor-neutral fundamentals with AWS VPC terminology and official references accessed 2026-08-30..

Interview QA

Treat each question like a live interview question: answer out loud first (structure, assumptions, tradeoffs), then open the model answer to spot gaps and rehearse a tighter follow-up.

Curated: · Written: · Reviewed:

QA-1

Design the address plan for a new production VPC that must later connect to on-premises and several other cloud networks.

QA-2

What makes a cloud subnet public, and what else does an IPv4 workload need before it is actually internet reachable?

QA-3

Design outbound internet access for private IPv4 workloads across three availability zones.

QA-4

Explain CIDR longest-prefix matching using a broad transit route and a narrower peering route.

QA-5

Compare security groups and network ACLs, including how each handles response traffic.

QA-6

Walk through diagnosing a TCP timeout between a private application and an on-premises database.

QA-7

Design the subnet and routing layout for a highly available three-tier service across multiple zones.

QA-8

What changes when an existing IPv4 VPC becomes dual stack with IPv6?

QA-9

How would you isolate a database network while still supporting application, backup, and operations traffic?

QA-10

When should an organization use VPC peering versus a transit hub?

QA-11

What problem does a private service endpoint solve, and what security problems does it not solve?

QA-12

Design DNS for services that need different private and public answers.

QA-13

How would you design and validate hybrid connectivity between a VPC and an on-premises network?

QA-14

Design secure administrative access to private workloads without opening SSH or RDP to the world.

QA-15

How would you organize route tables so that subnet intent remains explicit as the environment grows?

QA-16

What network telemetry would you enable for a production VPC, and what can it fail to tell you?

QA-17

How do you prevent subnet address exhaustion from becoming an autoscaling outage?

QA-18

How does an egress proxy or next-generation firewall differ from a standard cloud NAT gateway when restricting outbound traffic to third-party APIs?

QA-19

Explain how ordered network ACL rules can create a production incident and how you would test them.

QA-20

Why place a public load balancer in front of private application targets, and what controls still remain necessary?

QA-21

Define a meaningful availability test for redundant site-to-site VPN tunnels.

QA-22

A private DNS name resolves correctly in one VPC but not another. How would you diagnose and fix it?

QA-23

How do you verify and enforce that a managed database subnet has no direct route or ingress from the public internet?

QA-24

How does a centralized transit hub route inter-VPC traffic to ensure network isolation and mandate firewall inspection?

QA-25

An acquired company uses the same private CIDR as your production VPC. Propose a safe integration plan.