Basic Networking Interview Questions for Cybersecurity Freshers, With Answers
Prepare for cybersecurity interviews with this 2025 guide on basic and important networking questions. Covers OSI model, ports, firewalls, TCP/IP, DNS, VPNs, and real-world scenarios.
Quick answer: Cybersecurity interviews test networking because attacks travel over networks. Expect questions on the OSI model, TCP versus UDP, the three-way handshake, common ports, IP and MAC addresses, subnetting, DNS, DHCP, ARP, NAT, firewalls, VPNs and TLS. Answer in two parts: define the idea, then say why a defender cares.
Key takeaways
- Know the OSI layers and which protocol and attack lives at each layer.
- Learn about 15 common ports by heart and what each is used for.
- Be able to explain the TCP three-way handshake and why SYN floods work.
- Always add the security angle: how an attacker abuses it and how you detect or block it.
- Practise a quick subnet calculation, ping and traceroute output, and DNS lookups in a home lab.
How to answer a networking question in a security interview
Use two sentences. First define the thing plainly. Then say why it matters for defence. For example: "ARP maps an IP address to a MAC address on a local network. Because it has no authentication, attackers can poison it, so I would watch for duplicate MAC mappings." That second sentence is what separates a security candidate from a general networking one.
These questions are common topics, not a record of what any company asked. Use them to practise, and adapt to the job description.
Fundamentals
What is the OSI model?
A seven-layer reference model: Physical, Data Link, Network, Transport, Session, Presentation, Application. It helps you locate a problem or an attack. Security angle: a switch issue sits at layer 2 (MAC flooding, ARP spoofing), a routing issue at layer 3, a port-based attack at layer 4 and a web attack at layer 7.
What is the difference between an IP address and a MAC address?
An IP address is a logical address that can change and is used to route traffic between networks. A MAC address is a hardware address of the network card, used on the local link. Security angle: MAC addresses can be spoofed, so MAC filtering alone is weak.
TCP versus UDP?
TCP is connection-oriented and reliable, with a handshake, ordering and retransmission. UDP is connectionless and faster with no delivery guarantee. Web, email and SSH use TCP. DNS queries, streaming and VoIP often use UDP. Security angle: UDP is easier to spoof, which is why it is used in reflection and amplification attacks.
Explain the TCP three-way handshake.
The client sends SYN, the server replies SYN-ACK, the client sends ACK, and the connection is established. Security angle: a SYN flood sends many SYNs and never completes the handshake, filling the server's connection table. SYN cookies and rate limits help.
What is subnetting, and how many usable hosts are in a /24?
Subnetting splits a network into smaller ones using a mask. A /24 has 256 addresses, of which 254 are usable because the network and broadcast addresses are reserved. Security angle: subnets support segmentation, so a compromised machine cannot reach everything.
Ports and protocols
| Port | Protocol | Use | Security note |
|---|---|---|---|
| 20/21 | FTP | File transfer | Clear text; prefer SFTP |
| 22 | SSH | Remote login | Use keys, limit exposure |
| 23 | Telnet | Remote login | Clear text; avoid |
| 25 | SMTP | Mail sending | Spam and relay abuse |
| 53 | DNS | Name lookup | Tunnelling, cache poisoning |
| 67/68 | DHCP | Address assignment | Rogue DHCP servers |
| 80/443 | HTTP/HTTPS | Web | 443 uses TLS |
| 110/143 | POP3/IMAP | Mail retrieval | Use encrypted variants |
| 445 | SMB | File sharing | Never expose to the internet |
| 3389 | RDP | Remote desktop | Common brute-force target |
For a longer list, read our networking interview questions and answers.
What does DNS do, and how is it attacked?
DNS turns names into IP addresses. Attackers abuse it through cache poisoning, hijacking, and tunnelling data inside queries. Defences include DNSSEC, restricting recursion and monitoring unusual query volume or long random subdomains.
What does DHCP do?
It automatically gives devices an IP address, mask, gateway and DNS server. A rogue DHCP server can send clients a malicious gateway. Switch features such as DHCP snooping block this.
What is ARP and ARP spoofing?
ARP resolves an IP address to a MAC address on the local network. In ARP spoofing an attacker sends fake replies so traffic flows through them. Dynamic ARP inspection and static entries for critical hosts reduce the risk.
What is NAT?
Network Address Translation lets many private addresses share one public address. It hides internal addressing, but it is not a firewall. Do not call NAT a security control in an interview.
Security devices and encryption
Firewall versus IDS versus IPS?
A firewall allows or blocks traffic by rules. An IDS watches and alerts. An IPS sits in line and can block. A stateful firewall tracks connection state, and a next-generation firewall adds application awareness.
What is a VPN?
A VPN creates an encrypted tunnel across an untrusted network. Site-to-site links connect offices, and remote-access VPNs connect users. Security angle: VPN credentials are a target, so use MFA.
What happens when you open an HTTPS website?
The browser resolves the domain by DNS, opens a TCP connection, completes a TLS handshake where the server proves its identity with a certificate, keys are agreed, and then encrypted HTTP requests flow. Certificate validation is what stops a simple man-in-the-middle.
What is a DMZ?
A separate network zone for public-facing servers, so a compromise there does not give direct access to the internal network.
What is the difference between symmetric and asymmetric encryption?
Symmetric uses one shared key and is fast. Asymmetric uses a public and private key pair and is used for key exchange and signatures. TLS uses both.
Troubleshooting questions
- ping tests reachability with ICMP. A blocked ping does not prove a host is down.
- traceroute (
tracerton Windows) shows the path and where it stops. - nslookup or dig tests DNS. netstat or ss lists connections and listening ports.
- Wireshark shows the actual packets. See the Wireshark documentation.
Common mistakes in interviews
- Reciting definitions with no security angle.
- Saying "port 80 is HTTP" and forgetting the encrypted alternative.
- Claiming NAT or a hidden SSID is security.
- Guessing. Say "I would check the packet capture" instead of inventing an answer.
More practice: CCNA interview questions for freshers and CCNA questions with detailed answers.
Next steps
Next steps: to build networking depth for security, look at our Computer Network course or the CCNA 200-301 course.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0