20 of 20 questions shown
Role and technical questions
Explain the OSI model and say at which layers switches, routers and firewalls work.
What they’re checking: Whether you understand the layered model well enough to use it for troubleshooting, not just recite the seven layer names.
Sample answer
The seven layers are physical, data link, network, transport, session, presentation and application. Physical covers cables, optics and signals. Data link handles framing and MAC addresses, which is where a normal switch works, forwarding frames using its MAC address table. The network layer handles IP addressing and routing, which is where routers and layer 3 switches work. Transport covers TCP and UDP ports. A traditional firewall filters at layers 3 and 4 using IPs and ports, while next-generation firewalls inspect up to layer 7 to identify applications. I use the model when troubleshooting: check the link light and cable first, then VLAN and MAC learning, then IP and routing.
- Where does ARP fit in the model?
- How does the TCP/IP model map to OSI?
Which traffic on a corporate network uses TCP and which uses UDP, and why?
What they’re checking: Whether you understand transport protocols in terms of real applications and why the choice affects troubleshooting and firewall rules.
Sample answer
TCP is connection-oriented, with a three-way handshake, acknowledgements, retransmission and ordering, so it suits traffic where every byte must arrive correctly: web browsing over HTTPS on port 443, email, file transfers, SSH on 22 and database connections. UDP has no handshake or retransmission, so it is lighter and faster but unreliable, which suits real-time or simple query traffic: voice and video calls using RTP, DNS queries on port 53, DHCP and SNMP. For voice, a late packet is useless, so retransmitting it would only add delay. When I open firewall rules, I need to know which protocol an application uses, because allowing TCP 53 alone would break most DNS lookups.
- When does DNS use TCP instead of UDP?
- What is the purpose of the TCP window size?
How many usable hosts does a /26 subnet have, and what are the subnets of 192.168.10.0/24 at /26?
What they’re checking: Whether you can subnet quickly and accurately in your head, a basic skill tested in almost every network interview.
Sample answer
A /26 leaves 6 host bits, so each subnet has 2 to the power 6, which is 64 addresses. Two are reserved, the network address and the broadcast address, which leaves 62 usable hosts. The subnet mask is 255.255.255.192. Splitting 192.168.10.0/24 into /26 gives four subnets. The first is 192.168.10.0 to .63, with hosts .1 to .62. The second is .64 to .127, with hosts .65 to .126. The third is .128 to .191, and the fourth is .192 to .255, with hosts .193 to .254. I usually give the first usable address of each subnet to the gateway, for consistency across sites.
- What prefix would you use for a point-to-point link?
- Which subnet would you use for 100 hosts?
What is a VLAN, and how do devices in different VLANs communicate?
What they’re checking: Whether you understand layer 2 segmentation and how inter-VLAN routing is actually configured in an office network.
Sample answer
A VLAN splits one physical switch network into separate broadcast domains, for example staff, guests, voice phones and CCTV, which improves security and reduces broadcast traffic. Access ports belong to one VLAN and connect end devices. Trunk ports carry several VLANs between switches, tagging frames with 802.1Q, with one native VLAN untagged. Devices in different VLANs cannot talk directly. They need a layer 3 device. The common design is a layer 3 core switch with a switched virtual interface, an SVI, for each VLAN acting as the gateway. In smaller sites, a router with subinterfaces on one trunk link does this, called router on a stick. Access control lists then limit which VLANs can reach which.
- What is VLAN hopping and how do you prevent it?
- Why should the native VLAN not be VLAN 1?
Two OSPF routers are stuck in the EXSTART state. What is the likely cause and how do you fix it?
What they’re checking: Whether you know OSPF neighbour states deeply enough to troubleshoot from symptoms, which separates real experience from textbook knowledge.
Sample answer
EXSTART is where the two routers negotiate master and slave and start exchanging database descriptor packets. When neighbours stay stuck in EXSTART or EXCHANGE, the most common cause is an MTU mismatch on the link, because the router with the smaller MTU rejects the larger database descriptor packets. I check with show ip ospf neighbor and show interface on both sides, and debug if needed. The proper fix is to make the interface MTU match on both ends. Ignoring the MTU check with a command is possible, but it hides the problem. Other neighbour issues show at different states, for example mismatched hello timers, area or authentication stop adjacency forming at all.
- Why is it normal for two DROTHER routers to stay in 2-WAY?
- What is the difference between OSPF area types?
Users in one office say they cannot reach the internet. How do you troubleshoot?
What they’re checking: Whether you troubleshoot methodically by scope and by layer, gathering facts and test results before changing any configuration on live devices.
Sample answer
First I find the scope: one user, one VLAN, the whole office, or only some websites. That narrows it quickly. If it is one user, I check their IP settings, whether they got a DHCP address or a 169.254 address, then ping their gateway. If the whole office is affected, I check the edge: the ISP link status, the router or firewall interface, and whether the default route is present. Then I ping a public IP like 8.8.8.8 and a domain name separately. If IP works but names do not, it is DNS. If nothing leaves the site, I check NAT and the firewall logs, then raise a ticket with the ISP with my test results.
- What does traceroute tell you here?
- What if only one website fails?
What problem does Spanning Tree Protocol solve, and how is the root bridge chosen?
What they’re checking: Whether you understand layer 2 loops and how to control spanning tree in a real campus design rather than leaving defaults.
Sample answer
Redundant links between switches create layer 2 loops, and because Ethernet frames have no time-to-live, broadcasts circulate endlessly, causing a broadcast storm and MAC table instability that can bring down the network. STP blocks redundant paths and keeps one loop-free tree, unblocking a path if the active one fails. The root bridge is the switch with the lowest bridge ID, which is the priority, 32768 by default, followed by the MAC address. Left on defaults, an old access switch could become root. So I set the core switches’ priority lower deliberately, use Rapid PVST+ for faster convergence, and enable PortFast and BPDU guard on access ports to users.
- What does root guard do?
- How does RSTP converge faster than classic STP?
What is the difference between static NAT, pool-based NAT and PAT?
What they’re checking: Whether you understand the different address translation types and when each one is actually used at the internet edge of an office network.
Sample answer
Static NAT maps one private IP to one public IP permanently, used when an internal server, like a mail server, must be reachable from the internet at a fixed address. NAT with a pool maps private addresses to a range of public addresses on a first-come basis, and when the pool runs out, new users cannot connect, so it is rarely used now. PAT, also called NAT overload, maps many private addresses to one public IP using different source port numbers to keep sessions apart. Almost every office uses PAT for general internet access. For published services, I usually combine static NAT or port forwarding with tight firewall rules.
- How do you check active NAT translations?
- Why can NAT cause problems for some VPN traffic?
A site-to-site IPsec VPN with a branch office will not come up. How do you troubleshoot it?
What they’re checking: Whether you understand IPsec phases well enough to isolate mismatches quickly, a common real task for enterprise network engineers.
Sample answer
I check the two phases separately. Phase 1, IKE, builds a secure channel between peers. If it fails, I check reachability between public IPs, that UDP 500 and 4500 are allowed, and that both sides match on IKE version, encryption, hashing, Diffie-Hellman group, authentication method and pre-shared key. If phase 1 is up but phase 2 fails, I check the transform set and, most often, the interesting traffic: the local and remote subnets must mirror each other exactly on both ends. Then I check that VPN traffic is exempted from NAT and that routes point to the tunnel. Logs and debug output on the firewall usually name the mismatch.
- What is the difference between policy-based and route-based VPNs?
- What is perfect forward secrecy?
How do HSRP and VRRP provide gateway redundancy?
What they’re checking: Whether you can design first-hop redundancy so that a single router or core switch failure does not cut off users.
Sample answer
Hosts usually have one default gateway configured, so if that router fails, they lose connectivity. HSRP, which is Cisco proprietary, and VRRP, an open standard, let two or more routers share a virtual IP and virtual MAC address that hosts use as their gateway. One router is active, or master in VRRP, and the other stands by. If the active one fails, the standby takes over the virtual IP within seconds, and hosts notice nothing. I set priority so the intended router is active, enable preemption so it takes back the role after recovering, and use interface or object tracking so the router gives up the role if its uplink fails.
- How does GLBP differ from HSRP?
- How would you load balance VLANs across two core switches?
How do standard and extended access control lists differ, and where should each be placed?
What they’re checking: Whether you write traffic filters correctly and understand placement and the implicit deny, which prevents both outages and security gaps.
Sample answer
A standard ACL filters only on source IP address. Because it cannot tell where traffic is going, I place it as close to the destination as possible, otherwise it may block that source from reaching everything else. An extended ACL filters on source and destination IP, protocol and port, so I place it close to the source to drop unwanted traffic early. Every ACL ends with an implicit deny, so if I forget a permit for something like DHCP or routing protocol traffic, it gets blocked. Rules are checked top down, so specific entries go first. Before applying an ACL to a live interface, I review it and plan a rollback.
- What is the difference between inbound and outbound ACLs?
- How do you safely change an ACL on a remote router?
Behavioural questions
Tell me about a network outage at a branch or office that you resolved.
What they’re checking: How you handle pressure, use evidence and communicate with users and the business during a network outage.
Sample answer
A branch of a retail chain lost access to the billing server in our data centre on a busy Saturday, so stores could not bill. The internet worked, which ruled out the ISP link. I checked the firewall and saw the site-to-site VPN was down after the branch firewall rebooted following a power cut. Phase 1 was failing because the firewall had come up with an older configuration whose pre-shared key had been changed months earlier. I restored the latest backup, the tunnel came up and billing worked within forty minutes. Afterwards we set up automatic configuration backups and saving checks for all branch devices.
- How did you keep the store manager informed?
- Why was the running config not saved?
Describe a change you made that caused an unexpected outage. How did you handle it?
What they’re checking: Honesty, and whether you follow change discipline on live networks, with reviewed commands, rollback plans and lessons applied afterwards.
Sample answer
During a planned change window, I added a new VLAN to the trunk between two core switches. I used the trunk allowed VLAN command without the add keyword, which replaced the whole allowed list with just the new VLAN. Several floors lost connectivity. Because I had a console session and a pre-written rollback, I restored the original allowed list within five minutes. I informed the change manager right away and wrote it up honestly. Since then, every change I make includes the exact commands reviewed by a second engineer, a pre-change backup, and verification steps. I also use configuration templates for routine changes.
- How long was the outage?
- What does your change plan template include?
Tell me about a time you had to escalate a problem with an ISP or vendor.
What they’re checking: Whether you can work with external providers firmly and with evidence to get problems fixed quickly.
Sample answer
Our MPLS link to a plant had packet loss every afternoon for a week, and the ISP kept closing tickets saying the link was fine. I set up continuous ping and SNMP monitoring and found loss of around eight percent between 2 and 5 pm, only on their side of the handoff. I sent graphs, timestamps and traceroutes to the ISP’s escalation manager and asked for a joint test during the problem window. They found a congested aggregation port at their exchange and moved our circuit. I also used the data to push for a service credit as per the SLA.
- What is in a good escalation email?
- How did you keep the plant running in the meantime?
Tell me about a network migration you planned and carried out.
What they’re checking: Your planning and execution skills on larger changes, including testing, cutover planning and minimising downtime.
Sample answer
I led the replacement of the core switches at a hospital campus, where downtime had to be minimal. I documented every existing VLAN, SVI, routing setting and connection, then pre-configured the new switches and tested them in a lab with the same configuration. We planned the cutover for a Sunday night in stages, floor by floor, with a rollback for each stage, and agreed with the clinical teams which systems could be offline and for how long. Each stage was checked with a test list, including phones and patient monitors. The whole cutover finished in five hours with no unplanned outage.
- How did you handle devices with hard-coded settings?
- What would you do differently next time?
How did you explain a network limitation to a manager who wanted something done immediately?
What they’re checking: Whether you can communicate technical constraints in plain language and offer alternatives, rather than just saying no.
Sample answer
As a junior engineer at an IT services company, a sales manager wanted a client’s new office connected to our network the same afternoon. That needed a VPN, firewall rules and an approved change. I explained in plain words that connecting an unchecked network directly would expose our systems, and that the approval was there to protect the client too. I offered an alternative: the client team could use our secure remote access for their urgent work that day, which I set up within an hour. The proper site connection went in two days later after approval. The manager was satisfied because the client could still work.
- What if the manager had escalated?
- How long does a normal change approval take?
Tell me about a time you improved network documentation or monitoring.
What they’re checking: Whether you value documentation and visibility, which make troubleshooting faster and show maturity even in a junior engineer.
Sample answer
When I joined my first role, the network diagrams were years out of date, and every fault meant tracing cables physically. Over a month, using CDP and LLDP neighbour information, switch configurations and some floor visits, I rebuilt the diagrams for our main office and listed every switch port, VLAN and IP range in a shared sheet. I also added all switches to our monitoring tool with alerts for interface down and high utilisation. A few weeks later, when an uplink failed, the alert and the updated diagram let a colleague find the faulty port within minutes. My manager made the documentation update part of every change.
- Which monitoring tool did you use?
- How do you keep documentation current?
HR round questions
Are you comfortable with 24x7 shifts and being on call for network incidents?
What they’re checking: Whether you accept the shift and on-call reality of network operations roles and can work reliably in them.
Sample answer
Yes. I have worked rotating shifts in a network operations centre for two years, including nights, so I know what it involves. I keep a regular sleep pattern during night weeks and do proper handovers with open tickets and anything to watch. I would like to understand the rotation pattern, how many engineers share it, and whether there is a shift allowance or comp-off. I am also comfortable being called for major incidents outside my shift, as long as escalations are genuine, and I would contribute to improving alerts so on-call stays manageable.
- How do you hand over an ongoing incident at shift change?
- What is the hardest part of night shifts for you?
Which networking certifications do you hold or plan to take, and why?
What they’re checking: Whether you are investing in structured learning that fits the role and the company’s equipment and career path.
Sample answer
I completed CCNA while finishing my diploma. It gave me a solid base in subnetting, switching, routing and basic security, and I practised the labs in Packet Tracer and on used switches in our college lab. Since your company works mostly with Cisco and Fortinet equipment, my next goal is the Fortinet NSE certification for firewalls, and later CCNP Enterprise once I have real experience on production networks. I know certifications are only part of it, so I am also building a home lab with GNS3 to practise OSPF, BGP and VPN scenarios.
- Which CCNA topic did you find hardest?
- What have you built in your home lab?
What salary do you expect as a network engineer, and what is your notice period?
What they’re checking: Whether your expectation is reasonable and explained by your experience, and whether your joining date fits their needs.
Sample answer
I currently earn ₹8 lakh CTC as an L2 network engineer with four years of experience on Cisco routing and switching, Fortinet firewalls and SD-WAN at a managed services company. This is an L3 role with design and project ownership, so I am looking for ₹11 to 12 lakh fixed, plus shift allowance. I am open to discussing the structure. My notice period is 60 days. I am currently in the middle of a branch migration, so I would like to complete that phase, but I can ask for early release after it.
- What will you do if your company counter-offers?
- Would you accept a lower fixed for a better title?
Practise these questions
Answer them aloud against a timer, then compare with the sample answers.
How to prepare for a network engineer interview
- Practise subnetting until you can work out network, broadcast and host ranges for any prefix in under a minute without a calculator.
- Know the show and debug commands you would use for VLANs, spanning tree, OSPF, BGP, NAT and VPNs on the platforms listed on your resume.
- Build a small lab in Packet Tracer, GNS3 or EVE-NG and break things on purpose, so you can describe real symptoms and fixes.
- Prepare one outage story and one migration or change story, with timeline, root cause and what you changed in your process afterwards.
- Revise the basics of the firewall and SD-WAN products the company uses, since many roles now combine routing, switching and security.