Network Monitoring and Performance Questions

Network telemetry and performance operations: SNMP polling and traps (including counter wraparound and SNMPv3 access), NetFlow, sFlow and IPFIX flow export, sampling and its accuracy, streaming telemetry (gNMI), and eBPF or packet-capture telemetry; interface-level metrics (utilization, errors, discards, queue depth, microbursts), active synthetic probing alongside passive counters, link-flap detection, baselining and anomaly detection on network signals including elephant-flow spotting, network SLIs and SLOs, alerting, alert-storm suppression and NOC dashboards, telemetry pipeline design, storage, retention, downsampling and cardinality for network data (including securing the collection path and handling bursty remote sites), BGP and link-state monitoring including prefix hijack and route-leak detection, and network capacity monitoring, percentile utilization and bandwidth headroom planning. Also covers measuring and tuning network-level latency, jitter, packet loss and throughput (bufferbloat, queueing, TCP tuning for long paths). Excludes the generic metrics, logs and traces stack and alert design, the layered fault-isolation method and packet-capture troubleshooting, TCP and protocol fundamentals, application and CDN latency engineering, cloud VPC design and security detection.

MediumSystem Design
54 practiced

Design a pipeline to collect, enrich and analyze network flow records arriving at hundreds of thousands per second, including flow logs from cloud environments, with real-time dashboards and hourly rollups. Cover collectors, buffering, processing, storage and failure behavior.

HardSystem Design
31 practiced

Telemetry from remote cellular-managed sites drops out and then arrives in bursts. How would you design collection so you lose little data, avoid false alerts when a site goes quiet, and avoid overwhelming collectors on reconnect?

MediumSystem Design
33 practiced

Passive counters say the network is fine but users report slowness. How would you set up synthetic active checks to complement them: what to probe, how often, from where, and how to use the results?

HardSystem Design
29 practiced

Architect network observability across cloud, on-prem and edge covering about 50,000 devices, with sub-second alerting for critical failures and long-term trend retention. Where do you standardize, what do you collect, and how do you keep alert volume under control?

EasyTechnical
27 practiced

Network telemetry arrives at very different rates: interface counters, flow aggregates and routing events. What granularity and retention plan would you set for each, what do you keep at full resolution, what do you roll up, and why?

Unlock Full Question Bank

Get access to all Network Monitoring and Performance interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.