Network Security and Defense Questions

Securing networks at the infrastructure layer. Covers firewalls, ACLs and rule design, network device hardening and secure configuration, intrusion detection and prevention systems, VPN and remote-access encryption, network protocols and their security properties, and packet-level traffic analysis. The hands-on network-defense layer, distinct from zero-trust architecture strategy.

MediumTechnical
25 practiced

Write a Snort rule (Snort v2 or v3 syntax acceptable) that alerts on HTTP requests where the URI contains the SQL injection token 'UNION SELECT' (case-insensitive). The rule should match the HTTP URI, be reasonably efficient, and include a comment describing any potential false positives and performance considerations.

EasyTechnical
21 practiced

Briefly compare Snort, Suricata, and Zeek (formerly Bro) as IDS/network-monitoring tools. For each tool explain its primary detection approach (signature vs script-based), key strengths (performance, multi-threading, protocol parsing, scripting), typical output formats (e.g., EVE JSON, conn.log), and one common real-world use case where the tool is the preferred choice.

HardTechnical
24 practiced

Describe an approach to tune an IDS/IPS to reduce false positives while still detecting novel or zero-day attacks. Include steps for baseline profiling, whitelist/blacklist strategies, signature vs anomaly detection trade-offs, use of threat intelligence, feedback loops with SOC analysts, and metrics to evaluate tuning success.

MediumTechnical
20 practiced

Discuss how TLS 1.3 changes the visible information in passive network monitoring compared to TLS 1.2. Which handshake elements remain observable, which are encrypted earlier in the exchange, and how would you adapt existing detection rules that relied on TLS 1.2 cleartext fields?

MediumTechnical
22 practiced

Write a Python script or clear pseudocode that processes Suricata EVE JSON alert logs (one JSON object per line) and prints the top 10 source IP addresses by alert count, excluding RFC1918 private addresses. The solution should handle very large files via streaming and avoid loading the entire file into memory.

Unlock Full Question Bank

Get access to all Network Security and Defense interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.