Have questions? Speak to our experts at 8447712333 Connect With Us
18 Networking Interview Questions That Keep Coming Up (OSI, TCP/UDP, Subnetting, and More)

18 Networking Interview Questions That Keep Coming Up (OSI, TCP/UDP, Subnetting, and More)

innovativeacademy

innovativeacademy

October 3, 2026
9 min read

18 Networking Interview Questions That Keep Coming Up (OSI, TCP/UDP, Subnetting, and More)

Table of Contents

  1. Introduction
  2. The OSI and TCP/IP Models
  3. IP Addressing and Subnetting
  4. TCP vs. UDP and the Transport Layer
  5. Devices: Hubs, Switches, and Routers
  6. DNS, DHCP, and Name Resolution
  7. Security Basics: Firewalls and HTTPS
  8. Why These Questions Keep Showing Up Across So Many Different Roles
  9. Learning Networking Fundamentals at Innovative Academy
  10. FAQs
  11. Final Thoughts

1. Introduction

Networking interview questions have a longer shelf life than almost anything else in IT. The OSI model was formalized in the 1980s, and a version of "explain the difference between TCP and UDP" has been asked in technical interviews for just as long, because the underlying concepts haven't changed even as the specific tools built on top of them have.

These eighteen questions are the ones that recur across network engineering, system administration, support, and even general software roles, organized by what they're actually testing rather than dumped alphabetically.

2. The OSI and TCP/IP Models

Q1. What are the seven layers of the OSI model, and what does each one actually do?

From the bottom up:

  1. Physical – raw bits over a physical medium (cables, radio signals)
  2. Data Link – frames and MAC addressing within a local network segment
  3. Network – routing packets between networks using IP addresses
  4. Transport – end-to-end delivery via TCP or UDP
  5. Session – establishing and maintaining a connection's state
  6. Presentation – formatting, encryption, and compression of data
  7. Application – the layer user-facing protocols like HTTP and DNS actually operate at

Interviewers often ask this question not to test memorization of the list but to see whether a candidate can place a specific real-world problem, such as "this device isn't getting an IP address", at the correct layer.

Q2. How does the TCP/IP model differ from the OSI model?

TCP/IP is the four-layer model (Network Access, Internet, Transport, Application) that the modern internet is actually built on. It predates the seven-layer OSI model, which was designed later as a more detailed theoretical reference.

In practice, several OSI layers collapse into single TCP/IP layers. OSI's Application, Presentation, and Session layers all map roughly onto TCP/IP's single Application layer. Most real troubleshooting conversations use OSI's terminology because it's more granular, even though TCP/IP is the model actually implemented.

Q3. What layer does a VPN typically operate at, and why does that matter?

Most VPN technologies either operate at the network layer (like IPsec) or create a tunnel that encapsulates traffic from multiple layers above it.

What matters practically is that a VPN extends a private network's addressing and security policies across a public network by wrapping original packets inside new ones. Understanding that encapsulation is what lets someone reason correctly about why a VPN connection can carry traffic that looks, to applications running on it, like it's on the local private network even when the user is physically elsewhere.

3. IP Addressing and Subnetting

Q4. What is subnetting, and why bother dividing a network into subnets at all?

Subnetting divides one larger IP network into multiple smaller ones by borrowing bits from the host portion of an address for additional network identification. The practical reasons:

  • Less broadcast traffic – a broadcast only needs to reach devices within its subnet, not the entire organization.
  • Better security – different subnets can have different access policies.
  • More efficient address allocation – each subnet can be sized closer to how many hosts it actually needs, rather than wasting addresses on one flat network.

Q5. What's a subnet mask, and what does /24 mean?

A subnet mask indicates which bits of an IP address identify the network and which bits identify the specific host on that network.

"/24" is CIDR (Classless Inter-Domain Routing) notation shorthand for a subnet mask of 255.255.255.0. It means the first 24 bits are the network portion, leaving the remaining 8 bits (256 possible values, 254 usable after reserving the network and broadcast addresses) for host addresses within that subnet.

Q6. What's the difference between a public and a private IP address?

Private IP addresses are reserved for use inside private networks and aren't routable on the public internet. The private ranges are:

  • 10.0.0.0 – 10.255.255.255
  • 172.16.0.0 – 172.31.255.255
  • 192.168.0.0 – 192.168.255.255

A router performing NAT (Network Address Translation) translates between a device's private address and the network's public address when traffic needs to leave the local network.

A public IP address is globally unique and routable. Private addresses only need to be unique within their own network, which is why two different home networks can both safely use 192.168.1.1 for their router without any conflict.

Q7. What is NAT, and why does almost every home network use it?

Network Address Translation lets many devices on a private network share one public IP address when communicating with the internet. It rewrites the source address (and tracks port mappings) on outbound traffic and reverses the process on the way back in.

It offers a security benefit, since internal devices aren't directly addressable from the internet, but it exists mainly as a practical necessity: there are far more private devices in the world than there are available public IPv4 addresses to give each one its own.

4. TCP vs. UDP and the Transport Layer

Q8. What's the core difference between TCP and UDP?

TCP is connection-oriented. It establishes a connection through a three-way handshake before sending data, guarantees delivery through acknowledgments and retransmission, and preserves the order in which data arrives.

UDP is connectionless. It sends data without establishing a connection first and doesn't guarantee delivery or order, but in exchange it has far less overhead and lower latency.

TCP fits applications where correctness matters more than speed (web pages, file transfers, email). UDP fits scenarios where speed matters more than guaranteed delivery (video streaming, VoIP calls, DNS lookups, online gaming).

Q9. Walk through the TCP three-way handshake.

  1. The client sends a SYN (synchronize) packet to request a connection.
  2. The server responds with a SYN-ACK, acknowledging the request and sending its own synchronization request back.
  3. The client responds with an ACK, confirming receipt. The connection is now established and data transfer can begin.

This handshake is also exactly why TCP connections have measurable setup latency that UDP doesn't: there's a real round-trip cost paid before any actual application data moves.

Q10. What's a port number, and why do both TCP and UDP use them?

A port number identifies a specific process or service running on a device, letting a single IP address support many simultaneous network conversations at once. For example, port 80 is used for unencrypted HTTP, port 443 for HTTPS, and port 53 for DNS.

Both TCP and UDP use port numbers because the question of "which application on this machine is this data headed for" is relevant regardless of which transport protocol is carrying it.

5. Devices: Hubs, Switches, and Routers

Q11. What's the practical difference between a hub, a switch, and a router?

A hub is a simple physical-layer device that repeats every incoming signal out to all connected ports, with no awareness of which device is where. This behavior creates unnecessary traffic and collisions, which is why hubs have largely disappeared from modern networks.

A switch operates at the Data Link layer, learns which MAC address is reachable through which port, and forwards traffic only to the specific port that device is connected to, which is far more efficient.

A router operates at the Network layer and connects separate networks to each other, making forwarding decisions based on IP addresses rather than MAC addresses.

In short: a switch connects devices within one network, and a router connects networks to other networks.

Q12. What is a VLAN, and why would a network be split into them?

A virtual LAN logically segments a single physical switch (or set of switches) into multiple separate broadcast domains, as if they were separate physical networks, without needing separate hardware for each segment.

This lets an organization isolate traffic, such as keeping a finance department's data separate from a guest Wi-Fi network, purely through configuration. The result is better security and more efficient broadcast traffic on infrastructure that's physically shared.

Q13. What does Spanning Tree Protocol (STP) actually prevent?

STP prevents switching loops in networks that have redundant physical connections between switches. Without it, a loop between switches would cause broadcast traffic to circulate endlessly, consuming bandwidth and eventually overwhelming the network, a failure mode known as a broadcast storm.

STP calculates a loop-free logical topology by selectively blocking redundant paths while keeping them available as automatic backups if the active path fails.

6. DNS, DHCP, and Name Resolution

Q14. What does DNS actually do, step by step, when you type a website address?

DNS translates human-readable domain names into the IP addresses computers actually use to route traffic. When a browser requests a domain:

  1. The request typically goes to a recursive resolver (often run by the ISP), which first checks its cache.
  2. If the answer isn't cached, the resolver queries a root server.
  3. It then queries the top-level domain server (like .com).
  4. Finally, it queries the domain's own authoritative nameserver, which returns the actual IP address.

The IP address is then returned to the browser so the connection can be made.

Q15. What is DHCP, and what happens if a device doesn't get a response from a DHCP server?

DHCP (Dynamic Host Configuration Protocol) automatically assigns IP addresses and related network configuration (subnet mask, default gateway, DNS servers) to devices joining a network. It uses a four-step process commonly abbreviated DORA: Discover, Offer, Request, Acknowledge.

If a device doesn't receive a response, many operating systems fall back to self-assigning an address in the 169.254.x.x range (APIPA). Seeing one of these addresses is a strong diagnostic signal that the device couldn't reach a DHCP server at all.

7. Security Basics: Firewalls and HTTPS

Q16. What does a firewall actually do, and where does it sit?

A firewall inspects incoming and outgoing network traffic and allows or blocks it based on a defined set of security rules. Simpler packet-filtering firewalls match on source/destination IP, port, or protocol, while more advanced ones perform deeper application-level inspection.

It typically sits at the boundary between a trusted internal network and an untrusted external one (most commonly the internet), acting as the first checkpoint traffic has to pass before reaching internal systems.

Q17. What's the actual difference between HTTP and HTTPS?

HTTP transmits data in plain text over port 80, meaning anyone intercepting the traffic between client and server can read it directly.

HTTPS adds a TLS/SSL encryption layer on top, typically over port 443. It encrypts data in transit and verifies the server's identity through a certificate. A user connecting to a bank's HTTPS site therefore gets both confidentiality (the data can't be read in transit) and authentication (reasonable confidence the server is who it claims to be).

Q18. What's the difference between a stateless and a stateful firewall?

A stateless firewall evaluates each packet independently against its rule set, with no memory of previous packets in the same conversation.

A stateful firewall tracks the state of active connections, so it can make smarter decisions. For example, it can automatically allow return traffic for a connection that was legitimately initiated from inside the network, without needing an explicit rule for every possible response packet.

Stateful inspection is the more common approach in modern firewalls because it closes gaps that purely rule-based stateless filtering tends to leave open.

8. Why These Questions Keep Showing Up Across So Many Different Roles

What makes this set of questions durable isn't that networking itself has stayed simple. Cloud architecture, software-defined networking, and zero-trust security models have all added real complexity on top. But none of that added complexity replaces the fundamentals; it's built on them.

A cloud engineer troubleshooting why a container can't reach another service is still, underneath several layers of abstraction, reasoning about ports, routing, and DNS resolution. That's why these questions show up not just in networking-specific roles but in general IT support, DevOps, and even some backend development interviews. They test a foundation that every more specialized role eventually has to stand on.

9. Learning Networking Fundamentals at Innovative Academy

Innovative Academy's Networking Fundamentals program in Bangalore covers exactly this layer of material: OSI and TCP/IP models, IP addressing and subnetting, DNS and DHCP, and the devices that move traffic between them. The program uses real equipment rather than slides alone, which is what makes the difference between recognizing these concepts on a page and being able to explain them confidently when an interviewer asks a follow-up question.

Students who want to go deeper typically move on to the institute's CCNA training in Bangalore, which builds directly on this same foundation toward Cisco's own certification.

10. FAQs

1. Do I need to memorize subnet math to answer these questions well?

Being able to calculate a subnet quickly, such as how many usable hosts a /27 supports, comes up often enough in both interviews and real troubleshooting that it's worth practicing until it's fast and automatic, rather than something you have to work out slowly under interview pressure.

2. Are these questions specific to Cisco equipment, or do they apply more broadly?

The concepts themselves (OSI layers, TCP vs UDP, subnetting, DNS) are vendor-neutral and apply regardless of whether the equipment in a given job is Cisco, Juniper, or something else. Cisco's CCNA certification is built around testing this same foundational knowledge, which is part of why it's so widely recognized as a baseline credential.

3. Out of this entire list, where should limited prep time go first?

TCP vs UDP and the hub/switch/router distinction are close to universal across networking and IT support interviews at any level. Subnetting questions are more common when the role has hands-on configuration responsibilities rather than purely support or helpdesk duties.

4. Is it a problem if I can explain these concepts but haven't configured real equipment?

It's a real gap worth closing before an interview if possible. Explaining subnetting conceptually and actually configuring VLANs or static routes on a real switch are different skills, and interviewers for hands-on roles will often probe for the second one specifically.

5. How does this list relate to CCNA exam prep specifically?

Every topic here (OSI/TCP-IP models, subnetting, VLANs, STP, routing concepts) appears directly on Cisco's CCNA 200-301 exam blueprint. This list doubles as a reasonable diagnostic for how exam-ready your foundational knowledge already is, whether the immediate goal is an interview or the certification exam itself.

11. Final Thoughts

These eighteen questions have stayed relevant for decades for the same reason they're worth preparing thoroughly rather than skimming: they're not testing trivia about a specific product or vendor. They're testing whether a candidate actually understands how data gets from one point to another across a network, a foundation that nothing newer in networking has made optional.

Share this article: