---
tags:
- networking
- l1
- flashcard-deck
- linux-networking
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [Linux Networking Tools](../../../../library/portal/topics.md) | **Domain:** Networking
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
linux-networking/08e08dc8e94a	linux-networking	easy	interfaces, iptables, linux, ss, system	You typing `CTRL + C` but your script still running. How do you stop it?	In most cases, you can stop a running script by using the `CTRL + C` keyboard combination. This sends an interrupt signal (SIGINT) to the script, which terminates its execution. If this does not work and the script is still running, you can try using the `CTRL + \` combination, which sends a quit signal (SIGQUIT) to the script, which may terminate it immediately.\n\n\nRemember: ping = ICMP Echo. No reply ≠ host down — firewalls block ICMP.	projects/knowledge/interview/linux/016-you-typing-codectrl-ccode-but-your-script-still-ru.txt
linux-networking/0f59e4dd6ea7	linux-networking	medium	iptables, linux, ss	What are you using for troubleshooting and debugging network issues?	`dstat -t` is great for identifying network and disk issues.\n`netstat -tnlaup` can be used to see which processes are running on which ports.\n`lsof -i -P` can be used for the same purpose as netstat.\n`ngrep -d any metafilter` for matching regex against payloads of packets.\n`tcpdump` for capturing packets\n`wireshark` same concept as tcpdump but with GUI (optional).\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/178-what-are-you-using-for-troubleshooting-and-debuggi.txt
linux-networking/1145c6d245ad	linux-networking	medium	dns, iptables, linux, networking, services, ss	What can you find in /etc/services?	/etc/services maps service names to port numbers.\n\nFormat:\nservice-name  port/protocol  [aliases]\n\nExamples:\nssh     22/tcp\nhttp    80/tcp    www\nhttps   443/tcp\ndns     53/udp\n\nPurpose:\n- Human-readable service names\n- Used by netstat, ss, lsof for display\n- getservbyname() library function\n\nNot a firewall:\n- Doesn't control access\n- Just name-to-port mapping\n- Informational only\n\nStandard file across Unix systems (IANA assignments).\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/linux/386-what-can-you-find-in-etcservices.txt
linux-networking/166829a6b981	linux-networking	hard	linux, performance, interrupts, networking, troubleshooting	Server shows high interrupt CPU usage (irq% in top). How do you troubleshoot?	High interrupt CPU indicates hardware generating excessive interrupts, often network-related.\n\nDiagnostic steps:\n1. Identify the IRQ source: `cat /proc/interrupts` - look for rapidly increasing counters\n2. Per-CPU breakdown: `mpstat -P ALL 1` - see which CPUs handle interrupts\n3. Check for interrupt storms on specific device (e.g.\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/linux/519-high-interrupt-cpu-troubleshooting.txt
linux-networking/16d93b952364	linux-networking	easy	linux, ntp, time, networking	What is NTP? What is it used for?	NTP (Network Time Protocol) synchronizes system clocks over network.\n\nPurpose:\n- Accurate timekeeping\n- Synchronized time across servers\n- Critical for: logs, certificates, distributed systems, auth\n\nComponents:\n- ntpd or chronyd - NTP daemons\n- NTP servers - Time sources (stratum levels)\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/linux/362-what-is-ntp-what-is-it-used-for.txt
linux-networking/1774b5603200	linux-networking	medium	linux, ss, ssh, system	You must run command that will be performed for a very long time. How to prevent killing this process after the ssh session drops?	Use `nohup` to make your process ignore the hangup signal:\n\n```bash\nnohup long-running-process &\nexit\n```\n\nor you want to be using **GNU Screen**:\n\n```bash\nscreen -d -m long-running-process\nexit\n```\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/073-you-must-run-command-that-will-be-performed-for-a-.txt
linux-networking/1b041e66e15b	linux-networking	hard	bridge, interfaces, linux, routing	True or False? By default, when creating two separate network namespaces, a ping from one namespace to another will work fine	False. Network namespace has its own interfaces and routing table. There is no way (without creating a bridge for example) for one network namespace to reach another.\n\nRemember: ping = ICMP Echo. No reply ≠ host down — firewalls block ICMP.	projects/knowledge/interview/linux/283-true-or-false-by-default-when-creating-two-separat.txt
linux-networking/1d1c10231228	linux-networking	easy	linux, ssh	What is stored in ~/.ssh/known_hosts?	The file stores the key fingerprints for the clients connecting to the SSH server. This fingerprint creates a trust between the client and the server for future SSH connections.\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/199-what-is-stored-in-sshknownhosts.txt
linux-networking/1e69fa35eb84	linux-networking	easy	interfaces, linux, troubleshooting	What is the loopback (lo) interface?	The loopback interface is a special, virtual network interface that your computer uses to communicate with itself. It is used mainly for diagnostics and troubleshooting, and to connect to servers running on the local machine.\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/linux/250-what-is-the-loopback-lo-interface.txt
linux-networking/22dbd34cc837	linux-networking	hard	linux, boot, control-flow, kernel	You would like to enable IPv4 forwarding in the kernel, how would you do it?	`sudo sysctl net.ipv4.ip_forward=1`\n\nTo make it persistent (applied after reboot for example): insert `net.ipv4.ip_forward = 1` into `/etc/sysctl.conf`\n\nAnother way to is to run `echo 1 | sudo tee /proc/sys/net/ipv4/ip_forward`\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/linux/193-you-would-like-to-enable-ipv4-forwarding-in-the-ke.txt
linux-networking/2677b7d668b0	linux-networking	easy	linux, ssh, networking, tunneling	What is SSH port forwarding?	SSH tunneling routes traffic through encrypted SSH connection.\n\nTypes:\n1. Local (-L): ssh -L 8080:db:5432 bastion\n   - localhost:8080 reaches db:5432\n\n2. Remote (-R): ssh -R 8080:localhost:3000 server\n   - server:8080 reaches your localhost:3000\n\n3. Dynamic (-D): ssh -D 1080 bastion\n   - Creates SOCKS proxy\n\nUse: Access internal services, bypass firewalls, encrypt protocols.\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/337-what-is-ssh-port-forwarding.txt
linux-networking/2aa3e698ddfe	linux-networking	medium	iptables, linux, ss	What happens when you press ctrl + c?	When you press "Ctrl+C," it sends the SIGINT signal to the foreground process, asking it to terminate gracefully.\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/232-what-happens-when-you-press-ctrl-c.txt
linux-networking/31bf71914549	linux-networking	medium	linux, routing	What does the traceroute command do? How does it work?	Another common way to ask this question is "what part of the tcp header does traceroute modify?"\n\nRemember: traceroute = each hop (TTL). mtr = traceroute+continuous ping. Better diagnosis.	projects/knowledge/interview/linux/312-what-the-traceroute-command-does-how-does-it-works.txt
linux-networking/3b904ad32d88	linux-networking	hard	bonding, linux	What network bonding modes are there?	There a couple of modes:\n\n  * balance-rr: round robing bonding\n  * active-backup: a fault tolerance mode where only one is active\n  * balance-tlb: Adaptive transmit load balancing\n  * balance-alb: Adaptive load balancing\n\nRemember: Modes: 0=rr, 1=active-backup, 4=802.3ad(LACP). Mode 1 and 4 most common.	projects/knowledge/interview/linux/258-what-network-bonding-modes-are-there.txt
linux-networking/3f5cc15d8c17	linux-networking	medium	linux, processes, ss	How do you check per-process CPU, memory, and I/O usage on Linux?	`pidstat` from the sysstat package. Use `pidstat -u 1` for per-process CPU every second, `pidstat -r 1` for memory, `pidstat -d 1` for disk I/O. Combine flags: `pidstat -urd 1` for all three. Add `-p <PID>` to monitor a specific process.\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/220-how-to-check-process-usage.txt
linux-networking/404199b2a73e	linux-networking	medium	linux, processes, ss, troubleshooting	What are you using for troubleshooting and debugging process issues?	`strace` is great for understanding what your program does. It prints every system call your program executed.\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/180-what-are-you-using-for-troubleshooting-and-debuggi.txt
linux-networking/42d838b30ece	linux-networking	easy	linux, encryption, text-processing	What is telnet and why is it a bad idea to use it in production? (or at all)	Telnet is a type of client-server protocol that can be used to open a command line on a remote computer, typically a server.\nBy default, all the data sent and received via telnet is transmitted in clear/plain text, therefore it should not be used as it does not encrypt any data between the client and the server.\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/linux/254-what-is-telnet-and-why-is-it-a-bad-idea-to-use-it-.txt
linux-networking/4490aae3552e	linux-networking	easy	interfaces, ip-command, linux, loopback, networking, ss	When you run 'ip a' you see there is a device called 'lo'. What is it?	'lo' is the loopback interface - a virtual network interface.\n\nPurpose:\n- Internal communication within the host\n- Testing network applications locally\n- Inter-process communication via network stack\n\nCharacteristics:\n- IP address: 127.0.0.1 (IPv4), ::1 (IPv6)\n- Always up, always present\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/linux/413-when-you-run-ip-a-you-see-there-is-a-device-called.txt
linux-networking/4860f6c4f025	linux-networking	medium	bonding, interfaces, linux, networking	What is network interface bonding and do you know how to configure it?	Bonding combines multiple NICs into one logical interface.\n\nModes:\n- mode=0 (balance-rr): Round-robin load balancing\n- mode=1 (active-backup): Failover only\n- mode=2 (balance-xor): XOR-based load balancing\n- mode=4 (802.3ad): LACP, requires switch support\n- mode=5 (balance-tlb): Adaptive transmit load balancing\n\nRemember: Modes: 0=rr, 1=active-backup, 4=802.3ad(LACP). Mode 1 and 4 most common.	projects/knowledge/interview/linux/376-what-is-network-interface-bonding-and-do-you-know-.txt
linux-networking/486e3389fb5c	linux-networking	medium	linux, processes, ss	Every couple of days, a certain process stops running. How can you look into why it's happening?	One way to investigate why a process stops running is to check the system logs, such as the messages in /var/log/messages or journalctl. Additionally, checking the process's resource usage and system load may provide clues as to what caused the process to stop\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/231-every-couple-of-days-a-certain-process-stops-runni.txt
linux-networking/4df680472ff0	linux-networking	medium	linux, networking	How do you check TCP connection statistics on Linux?	`sar -n TCP,ETCP 1` from the sysstat package. TCP shows active/passive connections per second and segments in/out. ETCP shows retransmits, bad segments, and resets — useful for spotting packet loss or network congestion. The `1` samples every second. Install via `apt install sysstat` or `yum install sysstat`.\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/linux/223-how-to-check-tcp-stats.txt
linux-networking/4f0bc7657f19	linux-networking	medium	linux, processes, ss	How can you find how much memory a specific process consumes?	`\nmem()\n{ \n ps -eo rss,pid,euser,args:100 --sort %mem | grep -v grep | grep -i $@ | awk '{printf $1/1024 "MB"; $1=""; print }'\n}\n`\n[Source](https://stackoverflow.com/questions/3853655/in-linux-how-to-tell-how-much-memory-processes-are-using)\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/226-how-can-you-find-how-much-memory-a-specific-proces.txt
linux-networking/5289cac6451a	linux-networking	medium	linux, networking, bonding, high-availability	What is network bonding? What types are you familiar with?	Bonding combines multiple NICs into one logical interface for redundancy and/or performance.\n\nCommon modes:\n- Mode 0 (balance-rr): Round-robin, load balancing\n- Mode 1 (active-backup): Only one active, failover\n- Mode 2 (balance-xor): XOR hash load balancing\n- Mode 4 (802.3ad): LACP, requires switch support\n- Mode 5 (balance-tlb): Adaptive transmit load balancing\n\nRemember: Modes: 0=rr, 1=active-backup, 4=802.3ad(LACP). Mode 1 and 4 most common.	projects/knowledge/interview/linux/414-what-is-network-bonding-what-types-are-you-familia.txt
linux-networking/568138eabee9	linux-networking	medium	iptables, linux, ss	How do you kill a process in D state?	A process in D state (also known as "uninterruptible sleep") cannot be killed using the "kill" command. The only way to terminate it is to reboot the system.\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/235-how-do-you-kill-a-process-in-d-state.txt
linux-networking/59bb9f63494b	linux-networking	easy	linux, networking, firewall, iptables, nftables	iptables vs nftables?	nftables is the modern replacement: unified framework, cleaner syntax, atomic rule updates, same netfilter hooks underneath.\n\nRemember: Chains: INPUT, OUTPUT, FORWARD. Tables: filter, nat, mangle, raw.\n\nExample: `iptables -A INPUT -p tcp --dport 22 -j ACCEPT` — allow SSH.	projects/knowledge/interview/linux/544-iptables-vs-nftables-concise.txt
linux-networking/5cddb9896db7	linux-networking	medium	linux, processes, ss	How a user process performs a privileged operation, such as reading from the disk?	Using system calls\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/292-how-a-user-process-performs-a-privileged-operation.txt
linux-networking/5f4ca80e883f	linux-networking	hard	linux, networking, iptables, nat	Difference between SNAT, DNAT, and masquerade?	They are NAT modes that rewrite source or destination addresses to enable routing across networks.\n- SNAT: rewrites the source IP to a fixed public address, commonly for outbound traffic.\n- Masquerade: a dynamic SNAT that uses the interface IP, ideal when the public IP can change.\n- DNAT: rewrites the destination IP/port, commonly for inbound port forwarding to internal hosts.\n- In netfilter, SNAT/masquerade happens in POSTROUTING; DNAT happens in PREROUTING.\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/linux/543-snat-dnat-masquerade.txt
linux-networking/6537df4a2605	linux-networking	easy	bridge, interfaces, ip-command, linux, networking	What is a bridge? How is it added in Linux OS?	A network bridge connects multiple network segments at Layer 2.\n\nFunction:\n- Works like a virtual switch\n- Forwards frames based on MAC addresses\n- Connects VMs, containers to physical network\n\nCreate bridge:\n- ip link add br0 type bridge\n- ip link set br0 up\n\nRemember: Linux bridge = L2 switch. Docker uses `docker0` bridge for containers.	projects/knowledge/interview/linux/377-what-is-a-bridge-how-its-added-in-linux-os.txt
linux-networking/68a820cccb3f	linux-networking	easy	interfaces, linux, ssh	What is SSH? How to check if a Linux server is running SSH?	[Wikipedia Definition](https://en.wikipedia.org/wiki/SSH_(Secure_Shell)): "SSH or Secure Shell is a cryptographic network protocol for operating network services securely over an unsecured network."\n\n[Hostinger.com Definition](https://www.hostinger.\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/197-what-is-ssh-how-to-check-if-a-linux-server-is-runn.txt
linux-networking/693eed338272	linux-networking	easy	linux, nfs, networking, storage	What is NFS? What is it used for?	NFS (Network File System) enables sharing files over network.\n\nUse cases:\n- Shared home directories\n- Centralized storage\n- Application data sharing\n- Diskless workstations\n\nComponents:\n- Server: Exports directories\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/linux/353-what-is-nfs-what-is-it-used-for.txt
linux-networking/6a4d44774bbb	linux-networking	medium	dns, interfaces, linux	How can we modify the network connection via `nmcli` command, to use `8.8.8.8` as a DNS server?	1. Find the connection name: \n    ```\n    # nmcli con show\n    NAME         UUID                                  TYPE      DEVICE\n    System ens5  8126c120-a964-e959-ff98-ac4973344505  ethernet  ens5\n    System eth0  5fb06bd0-0bb0-7ffb-45f1-d6edd65f3e03  ethernet  --\n    ```\n    Here the connection name is "System ens5". Let's say we want to modify settings for this connection.\n\n\nRemember: DNS port 53. Records: A(IPv4), AAAA(IPv6), CNAME, MX, NS, TXT.\n\nExample: `dig example.com A +short` or `nslookup example.com`.	projects/knowledge/interview/linux/262-how-can-we-modify-the-network-connection-via-nmcli.txt
linux-networking/6aa351348fc9	linux-networking	medium	linux, ssh	You run ssh 127.0.0.1 but it fails with "connection refused". What could be the problem?	1. SSH server is not installed\n2. SSH server is not running\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/268-you-run-ssh-127001-but-it-fails-with-connection-re.txt
linux-networking/6ee85912d23d	linux-networking	medium	interfaces, linux, ssh	Why SSH is considered better than telnet?	Telnet also allows you to connect to a remote host but as opposed to SSH where the communication is encrypted, in telnet, the data is sent in clear text, so it isn't considered to be secure because anyone on the network can see what exactly is sent, including passwords.\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/198-why-ssh-is-considered-better-than-telnet.txt
linux-networking/7ae1965eb6f0	linux-networking	medium	linux, namespaces, processes, ss	True or False? In every PID (Process ID) namespace the first process assigned with the process id number 1	True. Inside the namespace it's PID 1 while to the parent namespace the PID is a different one.\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/281-true-or-false-in-every-pid-process-id-namespace-th.txt
linux-networking/7c76454ce242	linux-networking	medium	linux, processes, ss, system	How would you recognize a process that is hogging resources?	`top` works reasonably well, as long as you look at the right numbers.\n- **M** Sorts by current resident memory usage\n- **T** Sorts by total ( or cummulative) CPU usage\n- **P** Sorts by current CPU usage (this is the default refresh)\n- **?** Displays a usage summary for all top commands\n\nThis is very important information to obtain when problem solving why a computer process is running slowly and making decisions on what processes to kill/software to uninstall.\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/039-how-would-you-recognize-a-process-that-is-hogging-.txt
linux-networking/7e4a426f1690	linux-networking	easy	interfaces, iptables, linux, networking, routing	What is the routing table? How do you view it?	Routing table determines where network packets are sent.\n\nContents:\n- Destination networks\n- Gateway (next hop)\n- Interface to use\n- Metric (priority)\n\nView commands:\n- ip route (or ip r) - Modern\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/linux/374-what-is-the-routing-table-how-do-you-view-it.txt
linux-networking/85347a03ee49	linux-networking	medium	iptables, linux, system	You need to upgrade `ntpd` service at 200 servers. What is the best way to go about upgrading all of these to the latest?	By using **Infrastructure as a Code** approach, there are multiple good ways:\n\n1. **Configuration Synchronization Change Management Model**:\n\nThere are Configuration Management Tools (Ansible, Chef, Puppet, Saltstack, ...), that can be used to automatically update `ntpd` service on all servers.\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/linux/040-you-need-to-upgrade-codentpdcode-service-at-200-se.txt
linux-networking/85d89a1c5628	linux-networking	easy	dns, interfaces, linux, networking	What is the file /etc/resolv.conf used for? What does it contain?	/etc/resolv.conf configures DNS resolution.\n\nContents:\n- nameserver: DNS server IPs (up to 3)\n- search: Default domain search list\n- domain: Local domain name\n- options: Resolver options\n\nExample:\nnameserver 8.8.8.8\nnameserver 8.8.4.4\nsearch example.com internal.example.com\noptions timeout:2 attempts:3\n\nModern management:\n- systemd-resolved: /etc/resolv.conf is symlink\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/linux/378-what-the-file-etcresolvconf-is-used-for-what-does-.txt
linux-networking/899cfb648ad3	linux-networking	medium	linux	How to trigger neighbor discovery in IPv6?	`ping6 ff02::1` sends a multicast ping to all link-local nodes, triggering IPv6 Neighbor Discovery (NDP). This populates the neighbor cache, similar to ARP in IPv4. View discovered neighbors with `ip -6 neigh show`. \nGotcha: you must specify the interface for link-local addresses: `ping6 ff02::1%eth0`.	projects/knowledge/interview/linux/257-how-to-trigger-neighbor-discovery-in-ipv6.txt
linux-networking/8e13e633608b	linux-networking	medium	high-availability, interfaces, ip-command, linux, networking, ss	What is a virtual IP? In what situation would you use one?	A Virtual IP (VIP) is an IP address not tied to a specific physical interface.\n\nUse cases:\n1. High availability\n   - Failover between servers\n   - Keepalived, Pacemaker manage VIP\n   - Clients connect to VIP, failover is transparent\n\n2. Load balancing\n   - Single entry point\n   - LB distributes to multiple backends\n\n3. Service migration\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/linux/373-what-is-a-virtual-ip-in-what-situation-would-you-u.txt
linux-networking/8fe8b0b9f911	linux-networking	medium	linux, processes, ss	What signal is used by default when you run 'kill *process id*'?	\nThe default signal is SIGTERM (15). This signal kills\nprocess gracefully which means it allows it to save current\nstate configuration.\n\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/227-what-signal-is-used-by-default-when-you-run-kill-p.txt
linux-networking/905d88021c88	linux-networking	medium	linux, processes, ss	How to run a process in the background and why to do that in the first place?	You can achieve that by specifying & at the end of the command.\nAs to why, since some commands/processes can take a lot of time to finish\nexecution or run forever, you may want to run them in the background instead of waiting for them to finish before gaining control again in current session.\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/225-how-to-run-a-process-in-the-background-and-why-to-.txt
linux-networking/92b7d9b63339	linux-networking	easy	linux, networking, troubleshooting, ports	How do you see what process is listening on a port?	`ss -tlnp` (preferred, kernel netlink) or `lsof -i :PORT`.\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/542-find-process-listening-port.txt
linux-networking/97c93cc18e22	linux-networking	easy	iptables, linux, system	What are the main reasons for keeping old log files?	They are essential to investigate issues on the system. **Log management** is absolutely critical for IT security.\n\nServers, firewalls, and other IT equipment keep log files that record important events and transactions. This information can provide important clues about hostile activity affecting your network from within and without.\n\nRemember: ping = ICMP Echo. No reply ≠ host down — firewalls block ICMP.	projects/knowledge/interview/linux/030-what-are-the-main-reasons-for-keeping-old-log-file.txt
linux-networking/9c62f5076e1d	linux-networking	medium	iptables, linux, ss	How the kernel notifies the parent process about child process termination?	The kernel notifies the parent by sending the SIGCHLD to the parent.\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/298-how-the-kernel-notifies-the-parent-process-about-c.txt
linux-networking/9cd1d905cc73	linux-networking	medium	linux, processes, ss	You have a process writing to a file. You don't know which process exactly, you just know the path of the file. You would like to kill the process as it's no longer needed. How would you achieve it?	1. Run `lsof <FILE_PATH>`\n2. Use the pid (process ID) from the lsof command and run `kill <PID>`\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/183-you-have-a-process-writing-to-a-file-you-dont-know.txt
linux-networking/9ef24a335057	linux-networking	hard	iptables, linux, ss, system	What is the advantage of synchronizing UID/GID across multiple systems?	There are several principle reasons why you want to co-ordinate the **user/UID** and **group/GID** management across your network.\n\nThe first is relatively obvious - it has to do with user and administrative convenience.\n\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/084-what-is-the-advantage-of-synchronizing-uidgid-acro.txt
linux-networking/9f8240f09182	linux-networking	medium	interfaces, linux, ss	True or False? The MAC address of an interface is assigned/set by the OS	False. The MAC address is burned into the network interface hardware (NIC) by the manufacturer. The OS can override it (MAC spoofing), but the default address comes from hardware.\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/252-true-or-false-the-mac-address-of-an-interface-is-a.txt
linux-networking/a08d6c01da71	linux-networking	medium	linux, ssh	You try to ssh to a server and you get "Host key verification failed". What does it mean?	It means that the key of the remote host was changed and doesn't match the one that stored on the machine (in ~/.ssh/known_hosts).\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/200-you-try-to-ssh-to-a-server-and-you-get-host-key-ve.txt
linux-networking/a24fe2232679	linux-networking	hard	linux, ss	What happens when socket system call is used?	This is a good article about the topic: https://ops.tips/blog/how-linux-creates-sockets\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/linux/313-what-happens-when-socket-system-call-is-used.txt
linux-networking/a420f1d58f70	linux-networking	medium	linux, networking, firewall, iptables, nftables, security	Explain the difference between iptables and nftables, and when you'd migrate.	nftables is the modern replacement for iptables, designed to address its limitations.\n\nKey differences:\n- nftables: single CLI (nft), replaces iptables/ip6tables/arptables/ebtables\n- nftables: VM-based bytecode execution (more efficient)\n- nftables: atomic rule updates (no race conditions during reload)\n- nftables: native sets and maps (efficient IP/port lookups)\n- nftables: cleaner syntax,\n\nRemember: Chains: INPUT, OUTPUT, FORWARD. Tables: filter, nat, mangle, raw.\n\nExample: `iptables -A INPUT -p tcp --dport 22 -j ACCEPT` — allow SSH.	projects/knowledge/interview/linux/514-iptables-vs-nftables-migration.txt
linux-networking/a793b048229d	linux-networking	hard	interfaces, linux, routing	Can you have more than one default gateway in a given system?	Technically yes, a system can have multiple default gateways with different metrics (priorities). The kernel uses the route with the lowest metric. View with `ip route show default`. \nGotcha: multiple default gateways without proper metrics cause unpredictable routing — use policy-based routing (`ip rule`) for multi-homed hosts that need controlled path selection.	projects/knowledge/interview/linux/253-can-you-have-more-than-one-default-gateway-in-a-gi.txt
linux-networking/aa5bc82a3423	linux-networking	hard	linux, networking, namespaces, veth	How to link two separate network namespaces so you can ping an interface on one ns from the other?	Use veth (virtual ethernet) pairs - they act like a cable connecting namespaces.\n\nSteps:\n1. Create namespaces:\n   ip netns add ns1\n   ip netns add ns2\n\n2. Create veth pair:\n   ip link add veth1 type veth peer name veth2\n\n3. Move each end to a namespace:\n   ip link set veth1 netns ns1\n   ip link set veth2 netns ns2\n\n4. Configure IPs:\n   ip netns exec ns1 ip addr add 10.0.0.\n\nRemember: ping = ICMP Echo. No reply ≠ host down — firewalls block ICMP.	projects/knowledge/interview/linux/415-how-to-link-two-separate-network-namespaces-so-you.txt
linux-networking/acf1a253389b	linux-networking	medium	iptables, linux, ssh	What ssh-keygen is used for?	`ssh-keygen` is a tool to generate an authentication key pair for SSH, that consists of a private and a public key. It supports a number of algorithms to generate authentication keys : \n- dsa\n- ecdsa\n- ecdsa-sk\n- ed25519\n- ed25519-sk\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/201-what-ssh-keygen-is-used-for.txt
linux-networking/ad9d4ca27272	linux-networking	medium	interfaces, iptables, linux, ss, system	Explain in a few points the boot process of the Linux system.	**BIOS**: Full form of BIOS is Basic Input or Output System that performs integrity checks and it will search and load and then it will execute the bootloader.\n\n**Bootloader**: Since the earlier phases are not specific to the operating system, the BIOS-based boot process for x86 and x86-64 architectures is considered to start when the master boot record (MBR) code is executed in real mode and th\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/035-explain-in-a-few-points-the-boot-process-of-the-li.txt
linux-networking/afb6026fa891	linux-networking	easy	interfaces, ip-command, iproute2, linux, networking, routing	What are the following commands used for: ip addr, ip route, ip link?	These are iproute2 commands for network configuration:\n\nip addr (ip a):\n- Shows/configures IP addresses\n- ip addr show - List all addresses\n- ip addr add 192.168.1.10/24 dev eth0 - Add IP\n- ip addr del 192.168.1.10/24 dev eth0 - Remove IP\n\nip route (ip r):\n- Shows/configures routing table\n\nRemember: ip replaces ifconfig. addr(IPs), route(routing), link(interfaces), neigh(ARP).\n\nExample: `ip addr add 10.0.0.5/24 dev eth0`. `ip route add default via 10.0.0.1`.	projects/knowledge/interview/linux/370-what-the-following-commands-are-used-for-ip-addr-i.txt
linux-networking/b61fbe2edcae	linux-networking	medium	linux, monitoring, networking, processes, ss	How to list active connections?	Several commands show network connections:\n\n1. ss (modern, preferred):\n   - ss -tuln - Listening TCP/UDP ports\n   - ss -tunap - All connections with processes\n   - ss -s - Statistics summary\n\n2. netstat (legacy):\n   - netstat -tuln - Listening ports\n   - netstat -tunap - All with processes\n\n3. lsof:\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/linux/375-how-to-list-active-connections.txt
linux-networking/b8c6fa7f289d	linux-networking	medium	linux, processes, ss	What are the possible states of a process in Linux?	\nRunning (R)\nUninterruptible Sleep (D) - The process is waiting for I/O\nInterruptible Sleep (S)\nStopped (T)\nDead (x)\nZombie (z)\n\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/234-what-are-the-possible-states-of-a-process-in-linux.txt
linux-networking/c192751ce6c3	linux-networking	hard	interfaces, iptables, linux, networking, routing	How can you turn your Linux server into a router?	Enable IP forwarding and configure routing:\n\n1. Enable IP forwarding:\n   - echo 1 > /proc/sys/net/ipv4/ip_forward (temporary)\n   - Edit /etc/sysctl.conf: net.ipv4.ip_forward = 1 (permanent)\n   - sysctl -p to apply\n\n2. Configure interfaces:\n   - Each network on different interface\n   - Assign appropriate IP addresses\n\n3. NAT (if needed for internet access):\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/linux/372-how-can-you-turn-your-linux-server-into-a-router.txt
linux-networking/c4250cdeb3ac	linux-networking	hard	interfaces, linux, ss, system	Is it safe to attach the `strace` to a running process on the production? What are the consequences?	`strace` is the system call tracer for Linux. It currently uses the arcane `ptrace()` (process trace) debugging interface, which operates in a violent manner: **pausing the target process** for each syscall so that the debugger can read state. And doing this twice: when the syscall begins, and when it ends.\n\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/124-is-it-safe-to-attach-the-codestracecode-to-a-runni.txt
linux-networking/c44e72dcfc6d	linux-networking	medium	linux, ss	How to check if a certain port is being used?	One of the following would work:\n\n```\nnetstat -tnlp | grep <port_number>\nlsof -i -n -P | grep <port_number>\n```\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/linux/251-how-to-check-if-a-certain-port-is-being-used.txt
linux-networking/cb361afd7cf1	linux-networking	easy	linux, firewall, nftables, networking	What is nftables and how does it replace iptables?	nftables is the modern Linux firewall framework, replacing iptables.\n\nFeatures:\n- Single tool for IPv4, IPv6, ARP\n- Better syntax than iptables\n- Better performance\n- Atomic rule updates\n\nConcepts:\n- Tables: Contain chains\n\nRemember: Chains: INPUT, OUTPUT, FORWARD. Tables: filter, nat, mangle, raw.\n\nExample: `iptables -A INPUT -p tcp --dport 22 -j ACCEPT` — allow SSH.	projects/knowledge/interview/linux/367-what-is-nftables.txt
linux-networking/cb754bf6c0a2	linux-networking	medium	interfaces, ip-command, linux	How to list all the interfaces?	`ip link show` lists all network interfaces with their state (UP/DOWN), MTU, MAC address, and type. Alternatives: `ip addr show` includes IP addresses, `ip -br link` gives a brief one-line-per-interface view. Legacy command `ifconfig` also works but is deprecated. Use `ip link set eth0 up/down` to enable or disable an interface.	projects/knowledge/interview/linux/249-how-to-list-all-the-interfaces.txt
linux-networking/d06bfc4589ba	linux-networking	easy	linux, networking, namespaces, containers	What is a network namespace? What is it used for?	Network namespace provides isolated network stack instances.\n\nEach namespace has own:\n- Network interfaces\n- IP addresses\n- Routing tables\n- Firewall rules\n- Ports (can reuse same port numbers)\n\nUse cases:\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/linux/371-what-is-a-network-namespace-what-is-it-used-for.txt
linux-networking/d2f0cd99a497	linux-networking	hard	dns, iptables, linux, ss, system	Swap usage too high. What are the reasons for this and how to resolve swapping problems?	**Swap** space is a restricted amount of physical memory that is allocated for use by the operating system when available memory has been fully utilized. It is memory management that involves swapping sections of memory to and from physical storage.\n\n\nRemember: ping = ICMP Echo. No reply ≠ host down — firewalls block ICMP.	projects/knowledge/interview/linux/042-swap-usage-too-high-what-are-the-reasons-for-this-.txt
linux-networking/db5a11c1c11d	linux-networking	medium	dns, linux, troubleshooting	What commands are you using for performing DNS queries (or troubleshoot DNS related issues)?	You can specify one or more of the following:\n\n * `dig`\n * `host`\n * `nslookup`\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/260-what-commands-are-you-using-for-performing-dns-que.txt
linux-networking/dd45226e476f	linux-networking	hard	interfaces, linux, ssh, system	How to enforce authorization methods in SSH? In what situations it would be useful?	Force login with a password:\n\n```bash\nssh -o PreferredAuthentications=password -o PubkeyAuthentication=no user@remote_host\n```\n\nForce login using the key:\n\n```bash\nssh -o PreferredAuthentications=publickey -o PubkeyAuthentication=yes -i id_rsa user@remote_host\n```\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/109-how-to-enforce-authorization-methods-in-ssh-in-wha.txt
linux-networking/df6f86e431b9	linux-networking	easy	linux, ss, system	What symbolic representation can you pass to `chmod` to give all users execute access to a file without affecting other permissions?	```bash\nchmod a+x /path/to/file\n```\n\n- `a` - for all users\n- `x` - for execution permission\n- `r` - for read permission\n- `w` - for write permission\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/024-what-symbolic-representation-can-you-pass-to-codec.txt
linux-networking/e308e64a375e	linux-networking	hard	linux, processes, ss, system	How to kills a process that is locking a file?	```bash\nfuser -k filename\n```\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/118-how-to-kills-a-process-that-is-locking-a-file.txt
linux-networking/e637d8eaebf5	linux-networking	medium	iptables, linux, networking, ss	Can you explain how network process/connection is established and how it's terminated?	When a client process on one system wants to establish a connection with a server process on another system, it first creates a socket using the socket system call. The client then calls the connect system call, passing the address of the server as an argument.\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/241-can-you-explain-how-network-processconnection-is-e.txt
linux-networking/ec29dd062a45	linux-networking	medium	linux, ss	True or False? In user space, applications don't have full access to hardware resources	True. Only in kernel space they have full access to hardware resources.\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/279-true-or-false-in-user-space-applications-dont-have.txt
linux-networking/ec5ef11777f7	linux-networking	easy	linux, security, networking, ssh, tls	What is the difference between SSH and SSL?	Both provide encryption but for different purposes:\n\nSSH (Secure Shell):\n- Remote access and command execution\n- Port 22, auth via keys/passwords\n- Use: Server admin, SCP/SFTP, tunneling\n\nSSL/TLS:\n- Encrypt any TCP connection\n- Port 443 (HTTPS), auth via X.509 certs\n- Use: HTTPS, email, VPNs\n\nKey difference: SSH is complete remote access protocol; TLS is encryption layer for other protocols.\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/336-what-is-the-difference-between-ssh-and-ssl.txt
linux-networking/ef5ea9b4ee5a	linux-networking	medium	linux, processes, ss	True or False? The wait() system call won't return until the child process has run and exited	True in most cases though there are cases where wait() returns before the child exits.\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	projects/knowledge/interview/linux/300-true-or-false-the-wait-system-call-wont-return-unt.txt
linux-networking/f93fd9516eeb	linux-networking	hard	linux, control-flow, text-processing	What are packet sniffers? Have you used one in the past? If yes, which packet sniffers have you used and for what purpose?	It is a network utility that analyses and may inject tasks into the data-stream travelling over the targeted network.\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/linux/256-what-are-packet-sniffers-have-you-used-one-in-the-.txt
linux-networking/fea6813d5e26	linux-networking	hard	interfaces, iptables, linux, ss, system	Explain each system calls used for process management in Linux.	There are some system calls for process management. These are as follows:\n\n- `fork()`: it is used to create a new process\n- `exec()`: it is used to execute a new process\n- `wait()`: it is used to make the process to wait\n- `exit()`: it is used to exit or terminate the process\n- `getpid()`: it is used to find the unique process ID\n- `getppid()`: it is used to check the parent process ID\n- `nice()`: it is used to bias the currently running process property	projects/knowledge/interview/linux/087-explain-each-system-calls-used-for-process-managem.txt
linux-networking/z3c4d5e6f7a8	linux-networking	easy	linux,sockets,ss	What question does ss -ltnp answer?	Which TCP ports are currently listening, and which processes own them. -l = listening, -t = TCP, -n = numeric, -p = show process.\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	zines/bite.size.linux.cleaned.notes
linux-networking/z5e6f7a8b9c0	linux-networking	easy	linux,sockets,endpoints	What is a socket in Linux?	An endpoint for interprocess or network communication. Sockets can be Unix domain (local) or network (TCP/UDP). Each has a type, address, and state.\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	zines/bite.size.linux.cleaned.notes
linux-networking/z7a8b9c0d1e2	linux-networking	medium	linux,proc,cmdline,status	How do you find out what command a running process was started with?	Read /proc/<pid>/cmdline (null-delimited arguments) or /proc/<pid>/status (includes process name). The ps command also provides this via ps -p <pid> -o cmd.\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	zines/bite.size.linux.cleaned.notes
linux-networking/z9c0d1e2f3a4	linux-networking	medium	linux,lsof,sockets	How do you find which process is listening on a specific port using lsof?	lsof -i :<port>. For example, lsof -i :8080 shows which process has port 8080 open.\n\nRemember: ss replaces netstat. `ss -tulnp` = TCP+UDP listening, numeric, process.\n\nExample: `ss -tulnp | grep :80` — find what listens on port 80.	zines/bite.size.linux.cleaned.notes
linux-networking/2a1748010bbb	linux-networking	hard	cyber-security, linux, networking	Using a Linux system with a limited number of packages installed, and telnet is not available. Use sysfs virtual filesystem to test connection on all interfaces (without loopback).	For example:\n\n```bash\n#!/usr/bin/bash\n\nfor iface in $(ls /sys/class/net/ | grep -v lo) ; do\n\n  if [[ $(cat /sys/class/net/$iface/carrier) = 1 ]] ; then state=1 ; fi\n\ndone\n\nif [[ ${state:-0} -ne 1 ]] ; then echo "no connection" > /dev/stderr ; exit ; fi\n```\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/cyber-security/002-using-a-linux-system-with-a-limited-number-of-pack.txt
linux-networking/cs-defense-in-depth	linux-networking	easy	cyber-security, strategy, defense-in-depth	What is defense in depth and give three examples of layers.	Defense in depth is a security strategy using multiple layers of controls so that if one fails, others still protect the system. Examples: 1) Network layer: firewalls, network segmentation, WAF; 2) Host layer: OS hardening, patching, antivirus, host-based IDS; 3) Application layer: input validation, authentication, authorization, encryption; 4) Data layer: encryption at rest, access controls, backups.\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	training/interactive/knowledge/data/cards/cyber-security.tsv
linux-networking/cs-zero-trust	linux-networking	medium	cyber-security, zero-trust, architecture	What are the core principles of zero trust security?	Zero trust assumes no implicit trust based on network location. Principles: 1) Verify explicitly (authenticate and authorize every request); 2) Use least privilege access; 3) Assume breach (segment access, use end-to-end encryption, monitor continuously). Implementation involves: identity-based access, micro-segmentation, continuous validation, and device health checks. "Never trust, always verify."\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	training/interactive/knowledge/data/cards/cyber-security.tsv
linux-networking/cs-vuln-scanning	linux-networking	easy	cyber-security, scanning, tools	What is vulnerability scanning and name three common tools.	Vulnerability scanning is the automated process of probing systems and applications for known security weaknesses. It checks against databases like CVE and NVD. Common tools: 1) Nessus: commercial network/host scanner; 2) Trivy: open-source container and filesystem scanner; 3) OWASP ZAP: open-source web application scanner. Scanning should be integrated into CI/CD for continuous security feedback.\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	training/interactive/knowledge/data/cards/cyber-security.tsv
linux-networking/0cf3bc812a36	linux-networking	medium	linux, networking, permissions	What the following commands do?	* chmod - changes access permissions to files system objects\n  * chown - changes the owner of file system files and directories\n  * chgrp - changes the group associated with a file system object\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/linux/163-what-the-following-commands-do-chmod-chown-chgrp.txt
linux-networking/55ec0cab8b7c	linux-networking	medium	linux, networking	How to check which commands you executed in the past?	history command or .bash_history file \n  * also can use up arrow key to access or to show the recent commands you type\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/linux/144-how-to-check-which-commands-you-executed-in-the-pa.txt
linux-networking/bc4f5da75c03	linux-networking	easy	linux, control-flow, dns, networking	You run dig codingshell.com and get the following result:	This is the TTL. When you lookup for an address using a domain/host name, your OS is performing DNS resolution by contacting DNS name servers to get the IP address of the host/domain you are looking for. \nWhen you get a reply, this reply in cached in your OS for a certain period of time. This is period of time is also known as TTL and this is the meaning of 3515 number - it will be cached for 3515 seconds before removed from the cache and during that period of time, you'll get the value from the cache instead of asking DNS name servers for the address again.	projects/knowledge/interview/linux/261-you-run-dig-codingshellcom-and-get-the-following-r.txt
linux-networking/da413fe214c3	linux-networking	easy	linux, cups, printing	What is CUPS and how does it handle printing in Linux?	CUPS (Common Unix Printing System) manages printing on Linux/Unix.\n\nFeatures:\n- Print queue management\n- Driver support (PPD files)\n- Network printing (IPP protocol)\n- Web interface (localhost:631)\n\nComponents:\n- cupsd: Main daemon\n- /etc/cups/: Configuration\n- /var/spool/cups/: Print queues\n\nCommands:\n- lpstat -p: List printers\n- lp -d printer file: Print file\n- lpq: Show queue\n- lprm job_id: Cancel job\n\nWeb admin: http://localhost:631\n- Add printers\n- Manage queues\n- View logs\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/linux/388-what-is-cups.txt
linux-networking/f4a1dd87821f	linux-networking	easy	linux, administration, experience	Tell me about your Linux experience.	I've managed large-scale Linux environments for over 15 years — from RHEL 4–9, CentOS, Ubuntu, and CoreOS. Most of my work has been operational: patching, performance tuning, troubleshooting services, storage, networking, and writing automation around daily tasks. I'm very strong with systemd, networking services, SELinux, and debugging production issues under pressure.\n\nRemember: Key tools: ip(config), ss(connections), dig(DNS), ping/traceroute(reach).\n\nGotcha: Check iptables and ss when debugging connectivity.	projects/knowledge/interview/linux/446-tell-me-about-your-linux-experience.txt

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [Case Study: API Latency Spike — BGP Route Leak, Fix Is Network ACL](../../../../library/case-studies/cross-domain/api-latency-bgp-route-leak-acl/README.md) (Case Study, L2) — Linux Networking Tools
- [Case Study: ARP Flux Duplicate IP](../../../../library/case-studies/networking/arp-flux-duplicate-ip/README.md) (Case Study, L2) — Linux Networking Tools
- [Case Study: DHCP Relay Broken](../../../../library/case-studies/networking/dhcp-relay-broken/README.md) (Case Study, L1) — Linux Networking Tools
- [Case Study: Duplex Mismatch Symptoms](../../../../library/case-studies/networking/duplex-mismatch-symptoms/README.md) (Case Study, L1) — Linux Networking Tools
- [Case Study: IPTables Blocking Unexpected](../../../../library/case-studies/linux_ops/iptables-blocking-unexpected/README.md) (Case Study, L2) — Linux Networking Tools
- [Case Study: Jumbo Frames Partial](../../../../library/case-studies/networking/jumbo-frames-partial/README.md) (Case Study, L2) — Linux Networking Tools
- [Case Study: Service Mesh 503s — Envoy Misconfigured, RBAC Policy](../../../../library/case-studies/cross-domain/service-mesh-503-envoy-rbac/README.md) (Case Study, L2) — Linux Networking Tools
- [Case Study: Source Routing Policy Miss](../../../../library/case-studies/networking/source-routing-policy-miss/README.md) (Case Study, L2) — Linux Networking Tools
- [Case Study: Stuck NFS Mount](../../../../library/case-studies/linux_ops/stuck-nfs-mount/README.md) (Case Study, L2) — Linux Networking Tools
- [Deep Dive: AWS VPC Internals](../../../../library/deep-dives/aws.vpc.internals.md) (deep_dive, L2) — Linux Networking Tools

<!-- wiki:related:end -->
