Cloud Networking and VPC Design Questions

Designing networks inside a cloud provider: VPC/VNet topology, subnets, route tables, gateways, NAT, and peering, plus private connectivity through VPC endpoints and cloud load balancers. Covers segmentation, security groups and network ACLs, hybrid connectivity to on-premises data centers over VPN or dedicated links like Direct Connect and ExpressRoute, IP address planning across many VPCs and accounts, and how cloud network design differs from traditional data-center networking.

EasyTechnical
42 practiced

Compare and contrast instance-level security groups and subnet-level Network ACLs (NACLs) in cloud providers. Explain evaluation order, stateful vs stateless behavior, default rules and limits, and give examples of when to use each for a multi-tier application. Include an example where both are required and explain why.

HardTechnical
34 practiced

Design the network connectivity for a PCI DSS scoped workload in AWS that must connect to external payment processors. Explain segmentation to minimize scope, options between Direct Connect and VPN for payment traffic, PrivateLink usage, ensuring encryption in transit, centralized logging and monitoring, and practical steps to keep non-PCI systems out of scope.

HardTechnical
36 practiced

Design a hardened bastion/access solution that eliminates inbound SSH from the internet, supports audit and session recording, and allows emergency access for on-call engineers. Compare options: AWS Systems Manager Session Manager, Azure Bastion, traditional bastion hosts with just-in-time (JIT) access, and third-party jump hosts. Describe IAM policies, ephemeral credentials, MFA, session logging, and a migration plan to roll out the safest option.

HardTechnical
31 practiced

You need to capture packet-level data for a short window to debug a production high-throughput network problem without impacting performance or incurring excessive storage cost. Propose an architecture using sampling, BPF-based filtering, traffic mirroring, ephemeral capture targets, and automation to trigger captures on detected anomalies. Explain how to secure captured data and automate lifecycle (start, stop, store, purge).

MediumTechnical
35 practiced

Given a three-tier application (web, app, database) inside one VPC, propose the specific security group and network ACL rules that implement least privilege between the tiers. For each tier, specify the ports and traffic direction, and say whether you'd enforce it with a stateful security group or a stateless NACL and why.

Unlock Full Question Bank

Get access to all 16 Cloud Networking and VPC Design interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.