Cloud Networking and VPC Design Questions

Designing networks inside a cloud provider: VPC/VNet topology, subnets, route tables, gateways, NAT, and peering, plus private connectivity through VPC endpoints and cloud load balancers. Covers segmentation, security groups and network ACLs, hybrid connectivity to on-premises data centers over VPN or dedicated links like Direct Connect and ExpressRoute, IP address planning across many VPCs and accounts, and how cloud network design differs from traditional data-center networking.

EasyTechnical
31 practiced

Explain AWS VPC endpoints and the differences between Interface Endpoints (PrivateLink) and Gateway Endpoints. Provide concrete examples: how would you grant private access to S3 and to a private API in your VPC without exposing traffic to the public internet?

EasyTechnical
30 practiced

Explain what a Virtual Private Cloud (VPC) is across AWS, Azure, and GCP. Describe the core components (subnets, route tables, internet gateway or equivalent, NAT, security groups, and network ACLs) and explain the differences between public and private subnets. Provide a simple example layout for a 3-tier web application (web, app, db), indicating which tiers belong in public vs private subnets and why.

EasyTechnical
26 practiced

Explain how TLS (encryption in transit) is typically implemented in cloud architectures. Discuss end-to-end TLS versus terminating TLS at a load balancer, certificate management (rotation and trust), SNI considerations, and where you might decrypt traffic for inspection while minimizing the attack surface.

EasyTechnical
32 practiced

Describe the public/private subnet pattern for a multi-tier application (web, application, database) in a VPC. For each tier specify whether it belongs in a public or private subnet, where NAT/IGW is required, typical routing and ACL/security-group configuration, and how this pattern improves security and manageability.

MediumTechnical
28 practiced

You have an EC2 instance deployed with a public IP and Security Group allowing SSH and HTTP, but you cannot reach the instance from the internet. Provide a prioritized troubleshooting checklist covering control plane and data plane checks: route tables, Internet Gateway attachment, Elastic IP association, source/destination check, NACLs, VPC endpoint interactions, OS firewall, and instance health.

Unlock Full Question Bank

Get access to all 7 Cloud Networking and VPC Design interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.