Cloud Networking and VPC Design Questions

Designing networks inside a cloud provider: VPC/VNet topology, subnets, route tables, gateways, NAT, and peering, plus private connectivity through VPC endpoints and cloud load balancers. Covers segmentation, security groups and network ACLs, hybrid connectivity to on-premises data centers over VPN or dedicated links like Direct Connect and ExpressRoute, IP address planning across many VPCs and accounts, and how cloud network design differs from traditional data-center networking.

MediumTechnical
27 practiced

Explain how route tables work inside a VPC: how route tables are associated to subnets, the concept of local routes, longest-prefix-match (route precedence), propagating routes from virtual gateways (BGP), and how you would handle overlapping routes or conflicting routes when connecting to multiple external networks.

MediumTechnical
30 practiced

Recommend an approach for organizing Security Groups at scale: per-application, per-tier, or per-environment. For each approach, explain pros/cons regarding manageability, least privilege, rule explosion, automation, and operational impacts in a large organization.

MediumTechnical
30 practiced

For a compliance-heavy environment, describe how you would restrict and monitor outbound egress traffic from private subnets, including the use of NAT gateway, centralized proxy, firewall rules, and logging. Explain pros/cons of forcing egress through a single inspection point.

EasyTechnical
32 practiced

You need to explain the core components of a VPC to a junior admin: subnets, route tables, the internet gateway, the NAT gateway, security groups, and network ACLs. For each one, give a one-sentence description and a simple rule of thumb for when they'd need to change it.

MediumTechnical
35 practiced

Given a three-tier application (web, app, database) inside one VPC, propose the specific security group and network ACL rules that implement least privilege between the tiers. For each tier, specify the ports and traffic direction, and say whether you'd enforce it with a stateful security group or a stateless NACL and why.

Unlock Full Question Bank

Get access to all 36 Cloud Networking and VPC Design interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.