Switching, VLANs, and Layer 2 Segmentation Questions

Layer 2 switching and segmentation: MAC learning, aging and forwarding (including unknown-unicast flooding and cut-through versus store-and-forward), VLAN design and 802.1Q trunking (tag format, native VLAN, DTP trunk negotiation, VTP, voice VLAN, private VLANs, Q-in-Q), spanning tree (STP, RSTP, MST and edge protection such as PortFast, BPDU guard and root guard), EtherChannel/LACP and MLAG, multicast handling with IGMP snooping, and the hand-off between layer 2 and layer 3 (SVIs, router-on-a-stick, routed ports). Covers access and trunk port configuration and verification, switch-level fault diagnosis (trunk and native VLAN mismatches, MAC flapping, broadcast storms, bundles that will not form), campus, small-office and data-centre VLAN plans, and migrating or renumbering VLANs with minimal downtime. Boundary: attack and defense mechanics (MAC flooding, DHCP snooping, ARP inspection, VLAN hopping), routing protocol configuration, VXLAN/EVPN overlays, fabric and whole-campus topology choice, device automation, and the generic layered troubleshooting method are covered elsewhere.

No published Switching, VLANs, and Layer 2 Segmentation questions for Cybersecurity Engineer yet

This topic is part of the Cybersecurity Engineer interview scope, but we have not published questions for it under this role yet. Browse the other topics in this category, or start a practice session to work through it interactively.