Cloud Networking and VPC Design Questions

Designing networks inside a cloud provider: VPC/VNet topology, subnets, route tables, gateways, NAT, and peering, plus private connectivity through VPC endpoints and cloud load balancers. Covers segmentation, security groups and network ACLs, hybrid connectivity to on-premises data centers over VPN or dedicated links like Direct Connect and ExpressRoute, IP address planning across many VPCs and accounts, and how cloud network design differs from traditional data-center networking.

HardTechnical
36 practiced

Design a hardened bastion/access solution that eliminates inbound SSH from the internet, supports audit and session recording, and allows emergency access for on-call engineers. Compare options: AWS Systems Manager Session Manager, Azure Bastion, traditional bastion hosts with just-in-time (JIT) access, and third-party jump hosts. Describe IAM policies, ephemeral credentials, MFA, session logging, and a migration plan to roll out the safest option.

HardTechnical
34 practiced

Design the network connectivity for a PCI DSS scoped workload in AWS that must connect to external payment processors. Explain segmentation to minimize scope, options between Direct Connect and VPN for payment traffic, PrivateLink usage, ensuring encryption in transit, centralized logging and monitoring, and practical steps to keep non-PCI systems out of scope.

MediumTechnical
36 practiced

Explain how to set up packet capture in AWS for debugging intermittent network issues using VPC Traffic Mirroring. Include selecting mirror sources, creating mirror sessions and filters, choosing mirror targets (appliances or capture instances), expected performance impacts, and how to pipeline stored PCAPs to analysis tools without overloading storage.

EasyTechnical
42 practiced

Compare and contrast instance-level security groups and subnet-level Network ACLs (NACLs) in cloud providers. Explain evaluation order, stateful vs stateless behavior, default rules and limits, and give examples of when to use each for a multi-tier application. Include an example where both are required and explain why.

HardTechnical
32 practiced

A fintech customer requires microsegmentation to limit lateral movement between services. Describe how you would implement microsegmentation in a cloud environment using a combination of security groups, NACLs, host-based firewalls, service mesh policies, and cloud firewall appliances. Explain enforcement points, policy lifecycle (authoring, testing, rollout), performance impact, and a migration strategy from a flat network.

Unlock Full Question Bank

Get access to all 14 Cloud Networking and VPC Design interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.