Skip to content
Tech Interview Prep home
Technical interview guide

Network Security Basics

Firewalls, VPNs, and network segmentation — the perimeter and internal controls that limit blast radius.

Read
27 min
Practice MCQs
25
Interview QA
25
Edition
v3
Editorial status
Reviewed

Scope: NIST SP 800-41 Rev. 1, SP 800-77 Rev. 1, SP 800-207/207A, CISA ZTMM 2.0, and RFC 8446 guidance accessed 2026-08-31..

Interview QA

Treat each question like a live interview question: answer out loud first (structure, assumptions, tradeoffs), then open the model answer to spot gaps and rehearse a tighter follow-up.

Curated: · Written: · Reviewed:

QA-1

Design firewall policy for a three-tier internet application.

QA-2

Design segmentation to limit lateral movement after endpoint compromise.

QA-3

Design outbound egress controls for application and build workloads.

QA-4

How do stateful and stateless firewalls differ, and how do state tables track connections?

QA-5

How do you govern the lifecycle of a firewall rule?

QA-6

Design a site-to-site IPsec VPN between two organizations.

QA-7

Choose between full-tunnel and split-tunnel remote access.

QA-8

Govern enterprise TLS inspection safely.

QA-9

Design secure enterprise DNS resolution and monitoring.

QA-10

Explain zero trust and its relationship to segmentation and application authorization.

QA-11

What is the primary difference in deployment and traffic handling between an IDS and an IPS?

QA-12

How does a Denial of Service (DoS) attack differ from a Distributed Denial of Service (DDoS) attack, and what are standard network mitigation techniques?

QA-13

Use device posture as an access-policy input without creating unsafe certainty.

QA-14

Secure service-to-service communication with a service mesh.

QA-15

Design privacy-conscious network telemetry and flow logging.

QA-16

Detect and respond to lateral movement using network evidence.

QA-17

Design DDoS resilience for network security enforcement points.

QA-18

Define safe network-policy behavior during identity or policy-service outage.

QA-19

Troubleshoot a legitimate request blocked after a network-policy change.

QA-20

Contain a compromised workload without causing a wider outage.

QA-21

Operate network policy as code safely.

QA-22

Secure connectivity during a merger or hybrid-cloud integration.

QA-23

Plan IPv6 adoption without creating an unmonitored bypass path.

QA-24

Build an end-to-end test strategy for network security controls.

QA-25

Design network security for a multi-tenant cloud platform.