Network Security and Defense Questions

Securing networks at the infrastructure layer. Covers firewalls, ACLs and rule design, network device hardening and secure configuration, intrusion detection and prevention systems, VPN and remote-access encryption, network protocols and their security properties, and packet-level traffic analysis. The hands-on network-defense layer, distinct from zero-trust architecture strategy.

MediumTechnical
23 practiced

You must restrict east-west traffic so developer workstations cannot access the production database subnet in a campus network. Outline a set of router/switch ACLs or firewall rules (include 3-5 example lines), describe where to apply them (source-side/segmentation point), and explain how to allow legitimate admin flows (backups, monitoring) without opening a broad hole.

EasySystem Design
22 practiced

You are deploying a network-based IDS for a medium-sized office that has a public DMZ, an internal LAN, and a concentration of remote VPN users. Describe where you would place sensors (tap/span/inline) for maximum visibility, what traffic each sensor should capture (north-south/east-west), how to handle encrypted links, and any network changes (VLANs, mirror ports, taps) required to support reliable packet capture and minimal loss.

EasyTechnical
26 practiced

Explain the differences between AWS Security Groups and Network ACLs. Include differences in statefulness, rule evaluation order, directionality, use cases, and limitations. Provide an example where you would use both together for layered protection.

MediumTechnical
39 practiced

Write a Suricata or Snort rule that triggers on DNS TXT responses larger than 512 bytes and containing base64-like characters (indicative of tunnel/exfil). Include the exact rule syntax, explain each part (header, options, content modifiers), and discuss potential evasion techniques and strategies to reduce false positives.

EasyTechnical
38 practiced

Describe man-in-the-middle (MITM) attacks including passive interception and active manipulation techniques (e.g., ARP spoofing, TLS stripping). Explain which network and application-layer logs and telemetry you would examine to detect MITM activity and provide two immediate mitigations for a corporate network.

Unlock Full Question Bank

Get access to all Network Security and Defense interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.