Basic Networking Interview Questions for Cybersecurity Freshers, With Answers

Prepare for cybersecurity interviews with this 2025 guide on basic and important networking questions. Covers OSI model, ports, firewalls, TCP/IP, DNS, VPNs, and real-world scenarios.

Jun 27, 2025 - 17:52
Updated: 8 days ago
103.3k
Basic Networking Interview Questions for Cybersecurity Freshers, With Answers

Quick answer: Cybersecurity interviews test networking because attacks travel over networks. Expect questions on the OSI model, TCP versus UDP, the three-way handshake, common ports, IP and MAC addresses, subnetting, DNS, DHCP, ARP, NAT, firewalls, VPNs and TLS. Answer in two parts: define the idea, then say why a defender cares.

Key takeaways

  • Know the OSI layers and which protocol and attack lives at each layer.
  • Learn about 15 common ports by heart and what each is used for.
  • Be able to explain the TCP three-way handshake and why SYN floods work.
  • Always add the security angle: how an attacker abuses it and how you detect or block it.
  • Practise a quick subnet calculation, ping and traceroute output, and DNS lookups in a home lab.

How to answer a networking question in a security interview

Use two sentences. First define the thing plainly. Then say why it matters for defence. For example: "ARP maps an IP address to a MAC address on a local network. Because it has no authentication, attackers can poison it, so I would watch for duplicate MAC mappings." That second sentence is what separates a security candidate from a general networking one.

These questions are common topics, not a record of what any company asked. Use them to practise, and adapt to the job description.

Fundamentals

What is the OSI model?

A seven-layer reference model: Physical, Data Link, Network, Transport, Session, Presentation, Application. It helps you locate a problem or an attack. Security angle: a switch issue sits at layer 2 (MAC flooding, ARP spoofing), a routing issue at layer 3, a port-based attack at layer 4 and a web attack at layer 7.

What is the difference between an IP address and a MAC address?

An IP address is a logical address that can change and is used to route traffic between networks. A MAC address is a hardware address of the network card, used on the local link. Security angle: MAC addresses can be spoofed, so MAC filtering alone is weak.

TCP versus UDP?

TCP is connection-oriented and reliable, with a handshake, ordering and retransmission. UDP is connectionless and faster with no delivery guarantee. Web, email and SSH use TCP. DNS queries, streaming and VoIP often use UDP. Security angle: UDP is easier to spoof, which is why it is used in reflection and amplification attacks.

Explain the TCP three-way handshake.

The client sends SYN, the server replies SYN-ACK, the client sends ACK, and the connection is established. Security angle: a SYN flood sends many SYNs and never completes the handshake, filling the server's connection table. SYN cookies and rate limits help.

What is subnetting, and how many usable hosts are in a /24?

Subnetting splits a network into smaller ones using a mask. A /24 has 256 addresses, of which 254 are usable because the network and broadcast addresses are reserved. Security angle: subnets support segmentation, so a compromised machine cannot reach everything.

Ports and protocols

PortProtocolUseSecurity note
20/21FTPFile transferClear text; prefer SFTP
22SSHRemote loginUse keys, limit exposure
23TelnetRemote loginClear text; avoid
25SMTPMail sendingSpam and relay abuse
53DNSName lookupTunnelling, cache poisoning
67/68DHCPAddress assignmentRogue DHCP servers
80/443HTTP/HTTPSWeb443 uses TLS
110/143POP3/IMAPMail retrievalUse encrypted variants
445SMBFile sharingNever expose to the internet
3389RDPRemote desktopCommon brute-force target

For a longer list, read our networking interview questions and answers.

What does DNS do, and how is it attacked?

DNS turns names into IP addresses. Attackers abuse it through cache poisoning, hijacking, and tunnelling data inside queries. Defences include DNSSEC, restricting recursion and monitoring unusual query volume or long random subdomains.

What does DHCP do?

It automatically gives devices an IP address, mask, gateway and DNS server. A rogue DHCP server can send clients a malicious gateway. Switch features such as DHCP snooping block this.

What is ARP and ARP spoofing?

ARP resolves an IP address to a MAC address on the local network. In ARP spoofing an attacker sends fake replies so traffic flows through them. Dynamic ARP inspection and static entries for critical hosts reduce the risk.

What is NAT?

Network Address Translation lets many private addresses share one public address. It hides internal addressing, but it is not a firewall. Do not call NAT a security control in an interview.

Security devices and encryption

Firewall versus IDS versus IPS?

A firewall allows or blocks traffic by rules. An IDS watches and alerts. An IPS sits in line and can block. A stateful firewall tracks connection state, and a next-generation firewall adds application awareness.

What is a VPN?

A VPN creates an encrypted tunnel across an untrusted network. Site-to-site links connect offices, and remote-access VPNs connect users. Security angle: VPN credentials are a target, so use MFA.

What happens when you open an HTTPS website?

The browser resolves the domain by DNS, opens a TCP connection, completes a TLS handshake where the server proves its identity with a certificate, keys are agreed, and then encrypted HTTP requests flow. Certificate validation is what stops a simple man-in-the-middle.

What is a DMZ?

A separate network zone for public-facing servers, so a compromise there does not give direct access to the internal network.

What is the difference between symmetric and asymmetric encryption?

Symmetric uses one shared key and is fast. Asymmetric uses a public and private key pair and is used for key exchange and signatures. TLS uses both.

Troubleshooting questions

  • ping tests reachability with ICMP. A blocked ping does not prove a host is down.
  • traceroute (tracert on Windows) shows the path and where it stops.
  • nslookup or dig tests DNS. netstat or ss lists connections and listening ports.
  • Wireshark shows the actual packets. See the Wireshark documentation.

Common mistakes in interviews

  • Reciting definitions with no security angle.
  • Saying "port 80 is HTTP" and forgetting the encrypted alternative.
  • Claiming NAT or a hidden SSID is security.
  • Guessing. Say "I would check the packet capture" instead of inventing an answer.

More practice: CCNA interview questions for freshers and CCNA questions with detailed answers.

Next steps

Next steps: to build networking depth for security, look at our Computer Network course or the CCNA 200-301 course.

Related reading

Frequently Asked Questions

Expect the OSI model, TCP versus UDP, the three-way handshake, ports, IP and MAC addresses, subnetting, DNS, DHCP, ARP, NAT, firewalls, VPNs and TLS. Interviewers want the security angle on each, not only the definition.

Know the 15 or so common ones: 20/21 FTP, 22 SSH, 23 Telnet, 25 SMTP, 53 DNS, 67/68 DHCP, 80 HTTP, 110 POP3, 143 IMAP, 443 HTTPS, 445 SMB and 3389 RDP, plus what attackers do with each.

The client sends SYN, the server answers SYN-ACK, and the client sends ACK, which opens the connection. Add that a SYN flood abuses this by sending many SYNs without finishing, exhausting the server.

For most SOC analyst work, yes. Reading packet captures, firewall and DNS logs and understanding traffic flows matters daily. Basic scripting helps, but weak networking makes alerts hard to interpret.

A firewall allows or blocks traffic using rules about addresses, ports and state. An IPS inspects traffic for attack patterns and can block it in line. An IDS only alerts. Many products combine these features.

Build a small lab with two or three virtual machines, capture traffic with Wireshark, run ping, traceroute and DNS lookups, and watch a TCP handshake. Subnet a few networks by hand each day.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.