Cloud Networking and VPC Design Questions

Designing networks inside a cloud provider: VPC/VNet topology, subnets, route tables, gateways, NAT, and peering, plus private connectivity through VPC endpoints and cloud load balancers. Covers segmentation, security groups and network ACLs, hybrid connectivity to on-premises data centers over VPN or dedicated links like Direct Connect and ExpressRoute, IP address planning across many VPCs and accounts, and how cloud network design differs from traditional data-center networking.

MediumTechnical
32 practiced

Describe operational uses for VPC Flow Logs. Explain how you'd configure destinations (CloudWatch Logs vs S3), sampling vs full logs, retention policies, parsing challenges, and integration with SIEM or analytics pipelines for use cases like security detections and cost analysis.

HardTechnical
28 practiced

Your NAT Gateway costs have grown dramatically due to large volumes of container image pulls and OS updates across many accounts. Propose a combination of architecture and operational changes to reduce NAT and egress costs while maintaining security isolation and reliability for development and production workloads.

MediumTechnical
30 practiced

For a compliance-heavy environment, describe how you would restrict and monitor outbound egress traffic from private subnets, including the use of NAT gateway, centralized proxy, firewall rules, and logging. Explain pros/cons of forcing egress through a single inspection point.

EasyTechnical
26 practiced

Explain how TLS (encryption in transit) is typically implemented in cloud architectures. Discuss end-to-end TLS versus terminating TLS at a load balancer, certificate management (rotation and trust), SNI considerations, and where you might decrypt traffic for inspection while minimizing the attack surface.

HardTechnical
34 practiced

Explain how private hosted zones (Route 53 Private Hosted Zones, or the Azure/GCP private DNS zone equivalent) enable split-horizon DNS for hybrid applications. Describe cross-account private hosted zone sharing, conditional forwarding to on-prem DNS via resolver rules, resolving internal names from serverless and container compute (e.g. Lambda/EKS), and common pitfalls such as overlapping domain names.

Unlock Full Question Bank

Get access to all 49 Cloud Networking and VPC Design interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.