---
tags:
- networking
- l1
- flashcard-deck
- tcp-ip
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [TCP/IP](../../../../library/portal/topics.md) | **Domain:** Networking
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
networking/01e16144f9aa	networking	easy	network, networking, tcp, udp	Which port is used for `ping` command?	`ping` uses **ICMP**, specifically **ICMP echo request** and **ICMP echo reply** packets. There is no 'port' associated with **ICMP**. Ports are associated with the two IP transport layer protocols, TCP and UDP. **ICMP**, TCP, and UDP are "siblings"; they are not based on each other, but are three separate protocols that run on top of IP.\n\n\nRemember: 22=SSH, 53=DNS, 80=HTTP, 443=HTTPS, 3306=MySQL, 5432=PG.	projects/knowledge/interview/networking/007-which-port-is-used-for-codepingcode-command.txt
networking/0729b883bd5c	networking	medium	network, networking, routing, tcp, tls	What is the difference between CORS and CSPs?	**CORS** allows the **Same Origin Policy** to be relaxed for a domain.\n\ne.g. normally if the user logs into both `example.com` and `example.org`, the Same Origin Policy prevents `example.com` from making an AJAX request to `example.org/current_user/full_user_details` and gaining access to the response.\n\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/039-what-is-the-difference-between-cors-and-csps.txt
networking/0a7e26bce807	networking	hard	dns, network, networking, tcp, troubleshooting	What is the proper way to test NFS performance? Prepare a short checklist.	The best benchmark is always "the application(s) that you normally use". The load on a NFS system when you have 20 people simultaneously compiling a Linux kernel is completely different from a bunch of people logging in at the same time or the accounts uses as "home directories for the local web-server".\n\nBut we have some good tools for testing this.\n\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/054-what-is-the-proper-way-to-test-nfs-performance-pre.txt
networking/113542b12823	networking	medium	firewall, network, networking, tcp, troubleshooting	What does a `tcpdump` do? How to capture only incoming traffic to your interface?	`tcpdump` is a most powerful and widely used command-line packets sniffer or package analyzer tool which is used to capture or filter TCP/IP packets that received or transferred over a network on a specific interface.\n\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/041-what-does-a-codetcpdumpcode-do-how-to-capture-only.txt
networking/13e58f2b28b0	networking	easy	dns, networking	What is a DNS zone and how does it organize domain records?	A DNS zone is a logical container that holds all the DNS resource records for a specific domain name.\n\nRemember: A=IPv4, AAAA=IPv6, CNAME=alias, MX=mail, NS=nameserver, TXT=text.	projects/knowledge/interview/networking/087-what-is-a-dns-zone.txt
networking/152e54d7e1e3	networking	medium	dns, linux, networking, routing, tcp, troubleshooting	How do you debug network issues on Linux?	ip a, ip r, ip link, ss, tcpdump, dig, curl, logs. Start with connectivity and routes, then DNS, then firewall rules, then services.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/090-how-do-you-debug-network-issues-on-linux.txt
networking/196c8540c244	networking	hard	dns, network, networking	Create SPF records for your site to help control spam.	* Start with the SPF version, this part defines the record as SPF. An SPF record should always start with the version number v=spf1 (version 1) this tag defines the record as SPF. There used to be a second version of SPF (called: SenderID), but this was discontinued.\n\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/042-create-spf-records-for-your-site-to-help-control-s.txt
networking/19a01f19345c	networking	easy	dns, network, networking, tcp	What is the difference between 127.0.0.1 and localhost?	Well, the most likely difference is that you still have to do an actual lookup of localhost somewhere.\n\nIf you use `127.0.0.1`, then (intelligent) software will just turn that directly into an IP address and use it. Some implementations of `gethostbyname` will detect the dotted format (and presumably the equivalent IPv6 format) and not do a lookup at all.\n\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/006-what-is-the-difference-between-127001-and-localhos.txt
networking/19ae95e2bf21	networking	medium	network, networking, tcp	How do you kill program using e.g. 80 port in Linux?	To list any process listening to the port 80:\n\n```bash\n# with lsof\nlsof -i:80\n\n# with fuser\nfuser 80/tcp\n```\n\nTo kill any process listening to the port 80:\n\n```bash\nkill $(lsof -t -i:80)\n```\n\nor more violently:\n\n```bash\nkill -9 $(lsof -t -i:80)\n```\n\nor with `fuser` command:\n\n```bash\nfuser -k 80/tcp\n```\n\nRemember: 22=SSH, 53=DNS, 80=HTTP, 443=HTTPS, 3306=MySQL, 5432=PG.	projects/knowledge/interview/networking/032-how-do-you-kill-program-using-eg-80-port-in-linux.txt
networking/1a7e73fd5a22	networking	easy	network, networking, routing, switching	What is the smallest IPv4 subnet mask that can be applied to a network containing up to 30 devices?	Whether you have a standard `/24` VLAN for end users, a `/30` for point-to-point links, or something in between and subnet that must contain up to 30 devices works out to be a `/27` - or a subnet mask of `255.255.255.224`.\n\nRemember: /24=256, /16=65536, /8=16M. Formula: 2^(32-prefix).	projects/knowledge/interview/networking/020-what-is-the-smallest-ipv4-subnet-mask-that-can-be-.txt
networking/23462f925a94	networking	easy	network, networking, routing, tcp	What is the difference between a router and a gateway? What is the default gateway?	**Router** describes the general technical function (layer-3 forwarding) or a hardware device intended for that purpose, while gateway describes the function for the local segment (providing connectivity to elsewhere). You could also state that "_you set up a router as gateway_". Another term is hop which describes the forwarding in between subnets.\n\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/017-what-is-the-difference-between-a-router-and-a-gate.txt
networking/23613f618bb9	networking	medium	dns, networking, tcp, udp	Why does DNS "sometimes" fail?	Intermittent DNS failures have several common causes:\n\n1. **TTL mismatch**: Cached record expired but new one not fetched\n\n2. **Resolver caching**: Local nscd/systemd-resolved caching stale records\n\n3. **Broken search domains**: `/etc/resolv.conf` search directive causes unexpected lookups\n\n4. **Split-horizon DNS**: Internal vs external DNS returning different results\n\n5.\n\nRemember: DNS port 53. Resolution: cache→hosts→recursive→root→TLD→authoritative.	projects/knowledge/interview/networking/092-why-does-dns-sometimes-fail.txt
networking/24b60bbf0387	networking	easy	dns, networking	What is a DNS NS record and what role does it play?	A DNS NS (Name Server) record specifies which authoritative DNS servers can answer queries for a domain. \nExample: `example.com. NS ns1.example.com.` delegates resolution to that nameserver. Every domain must have at least two NS records for redundancy. Mnemonic: A=IPv4, AAAA=IPv6, CNAME=alias, MX=mail, NS=nameserver, TXT=metadata.	projects/knowledge/interview/networking/082-what-is-a-ns-record.txt
networking/25c5424e7ca8	networking	hard	http, network, networking, tls	You should rewrite POST with payload to an external API but the POST requests loose the parameters passed on the URL. How to fix this problem (e.g. in Nginx) and what are the reasons for this behavior?	The issue is that external redirects will never resend **POST** data. This is written into the HTTP spec (check the `3xx` section). Any client that does do this is violating the spec.\n\n**POST** data is passed in the body of the request, which gets dropped if you do a standard redirect.\n\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/053-you-should-rewrite-post-with-payload-to-an-externa.txt
networking/27da46d19bb4	networking	hard	http, network, networking	Developer says: <i>`htaccess` is full of magic and it should be used</i>. What is your opinion about using `htaccess` files? How has this effect on the web app	`.htaccess` files were born out of an era when shared hosting was common­place:\n\n- sysadmins needed a way to allow multiple clients to access their server under different accounts, with different configurations for their web­sites.\n\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/050-developer-says-icodehtaccesscode-is-full-of-magic-.txt
networking/2a225b12e745	networking	medium	firewall, network, networking, tcp, tls	You get `curl: (56) TCP connection reset by peer`. What steps will you take to solve this problem?	- check if the URL is correct, maybe you should add `www` or set correctly `Host:` header? Check also scheme (http or https)\n- check the domain is resolving into a correct IP address\n- enable debug tracing with `--trace-ascii curl.dump`.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/033-you-get-codecurl-56-tcp-connection-reset-by-peerco.txt
networking/30b17340bec1	networking	easy	http, network, networking	What are some common HTTP status codes?	- **1xx** - Informational responses - communicates transfer protocol-level information\n- **2xx** - Success - indicates that the client’s request was accepted successfully\n- **3xx** - Redirection - indicates that the client must take some additional action in order to complete their request\n- **4xx** - Client side error - this category of error status codes points the finger at clients\n- **5xx** - Server side error - the server takes responsibility for these error status codes\n\nRemember: 2xx=success, 3xx=redirect, 4xx=client error, 5xx=server. 200/404/500 are key.	projects/knowledge/interview/networking/021-what-are-some-common-http-status-codes.txt
networking/30e8f2344a7d	networking	easy	http, network, networking, tls	What is the difference between `wget` and `curl`?	The main differences are: `wget's` major strong side compared to `curl` is its ability to download recursively. `wget` is command line only. `curl` supports FTP, FTPS, HTTP, HTTPS, SCP, SFTP, TFTP, TELNET, DICT, LDAP, LDAPS, FILE, POP3, IMAP, SMTP, RTMP and RTSP.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/012-what-is-the-difference-between-codewgetcode-and-co.txt
networking/31584c38902d	networking	medium	http, network, networking	How to send an HTTP request using `telnet`?	For example:\n\n```bash\ntelnet example.com 80\nTrying 192.168.252.10...\nConnected to example.com.\nEscape character is '^]'.\nGET /questions HTTP/1.0\nHost: example.com\n\nHTTP/1.1 200 OK\nContent-Type: text/html; charset=utf-8\n...\n```\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/031-how-to-send-an-http-request-using-codetelnetcode.txt
networking/31ba975315a9	networking	medium	firewall, network, networking	Explain four types of responses from firewall when scanning with `nmap`.	There might be four types of responses:\n\n- **Open port** - few ports in the case of the firewall\n- **Closed port** - most ports are closed because of the firewall\n- **Filtered** - `nmap` is not sure whether the port is open or not\n- **Unfiltered** - `nmap` can access the port but is still confused about the open status of the port\n\nRemember: Types: packet filter(L3/4), stateful(connections), WAF(L7). Defense in depth.	projects/knowledge/interview/networking/040-explain-four-types-of-responses-from-firewall-when.txt
networking/3405e226b779	networking	easy	dns, networking	What is DNS resolution?	DNS resolution is the process of translating a domain name (like example.com) to an IP address. The resolution chain: local cache -> /etc/hosts -> recursive resolver -> root nameserver -> TLD nameserver -> authoritative nameserver. This typically completes in milliseconds. Use `dig +trace example.com` to see each step.	projects/knowledge/interview/networking/066-what-is-dns-resolution.txt
networking/367c7a37eab2	networking	easy	dns, networking	What is a DNS MX record and how does it route email?	MX (Mail Exchange) Specifies a mail exchange server for the domain, which allows mail to be delivered to the correct mail servers in the domain.\n\nRemember: A=IPv4, AAAA=IPv6, CNAME=alias, MX=mail, NS=nameserver, TXT=text.	projects/knowledge/interview/networking/081-what-is-a-mx-record.txt
networking/381a1c4beb3b	networking	easy	dns, networking, osi-model	What is DNS? What is it used for?	DNS (Domain Name Systems) is a protocol used for converting domain names into IP addresses. \ncomputer networking (at layer 3 of the OSP model) is done with IP addresses but for as humans it's hard to remember IP addresses, it's much easier to remember names. This why we need something such as DNS to convert any domain name we type into an IP address. You can think on DNS as a huge phonebook or database where each corresponding name has an IP.	projects/knowledge/interview/networking/065-what-is-dns-what-is-it-used-for.txt
networking/3cdd549e3d52	networking	hard	http, network, networking	What are the security risks of setting `Access-Control-Allow-Origin`?	By responding with `Access-Control-Allow-Origin: *`, the requested resource allows sharing with every origin. This basically means that any site can send an XHR request to your site and access the server’s response which would not be the case if you hadn’t implemented this CORS response.\n\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/060-what-are-the-security-risks-of-setting-codeaccess-.txt
networking/3d0bcc60ef16	networking	medium	network, networking, routing, switching	What is the purpose of Spanning Tree?	This protocol operates at layer 2 of the OSI model with the purpose of preventing loops on the network. Without **STP**, a redundant switch deployment would create broadcast storms that cripple even the most robust networks. There are several iterations based on the original IEEE 802.1D standard; each operates slightly different than the others while largely accomplishing the same loop-free goal.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/028-what-is-the-purpose-of-spanning-tree.txt
networking/3ee92ef4bcf5	networking	medium	dns, networking, tcp, tls	Explain DNS Records TTL	[varonis.com](https://www.varonis.com/blog/dns-ttl): "DNS TTL (time to live) is a setting that tells the DNS resolver how long to cache a query before requesting a new one. The information gathered is then stored in the cache of the recursive or local resolver for the TTL before it reaches back out to collect new, updated details."\n\nRemember: A=IPv4, AAAA=IPv6, CNAME=alias, MX=mail, NS=nameserver, TXT=text.	projects/knowledge/interview/networking/083-explain-dns-records-ttl.txt
networking/402a49b6fa02	networking	easy	network, networking, routing, switching	What is the difference between a VLAN and a subnet? Do you need a VLAN to setup a subnet?	**VLANs** and **subnets** solve different problems. **VLANs** work at Layer 2, thereby altering broadcast domains (for instance). Whereas **subnets** are Layer 3 in the current context.\n\n**Subnet** - is a range of IP addresses determined by part of an address (often called the network address) and a subnet mask (netmask). For example, if the netmask is `255.255.255.\n\nRemember: /24=256, /16=65536, /8=16M. Formula: 2^(32-prefix).	projects/knowledge/interview/networking/002-what-is-the-difference-between-a-vlan-and-a-subnet.txt
networking/410aaac4c89b	networking	easy	dns, networking	Given the following fqdn, www.blipblop.com, what is the second level domain?	`blipblop.com.` is the second level domain\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/072-given-the-following-fqdn-wwwblipblopcom-what-is-th.txt
networking/42705648d32e	networking	medium	dns, load-balancing, networking	True or False? DNS can be used for load balancing	True. DNS round-robin returns multiple IPs for a hostname in rotating order, distributing requests across servers. It's simple but lacks health checking — use a proper load balancer for production.\n\nRemember: DNS port 53. Resolution: cache→hosts→recursive→root→TLD→authoritative.	projects/knowledge/interview/networking/085-true-or-false-dns-can-be-used-for-load-balancing.txt
networking/42c8c943fe26	networking	medium	network, networking, tcp	Developer uses private key on the server to deploy app through ssh. Why it is incorrect behavior and what is the better (but not ideal) solution in such situations?	You have the private key for your personal account. The server needs your public key so that it can verify that your private key for the account you are trying to use is authorized.\n\nThe whole point with private keys is that they are private, meaning only you have your private key. If someone takes over your private key, it will be able to impersonate you any time he wants.\n\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/038-developer-uses-private-key-on-the-server-to-deploy.txt
networking/477051e307d5	networking	hard	network, networking, tcp, troubleshooting	Developer reports a problem with connectivity to the remote service. Use `/dev` for troubleshooting.	```bash\n# <host> - set remote host\n# <port> - set destination port\n\n# 1\ntimeout 1 bash -c "</dev/tcp/<host>/<port>" >/dev/null 2>&1 ; echo $?\n\n# 2\ntimeout 1 bash -c 'cat < /dev/null > </dev/tcp/<host>/<port>' ; echo $?\n\n# 2\n&> echo > "</dev/tcp/<host>/<port>"\n```\n\nRemember: 22=SSH, 53=DNS, 80=HTTP, 443=HTTPS, 3306=MySQL, 5432=PG.	projects/knowledge/interview/networking/046-developer-reports-a-problem-with-connectivity-to-t.txt
networking/47f09fdd857b	networking	easy	dns, networking	What is a name server?	A server which is responsible for resolving DNS queries.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/067-what-is-a-name-server.txt
networking/4de3cdeb16da	networking	hard	network, networking, routing, tcp, udp	You need to block several IPs from the same subnet. What is the most efficient way for the system to traverse the iptables rule set or the black-hole route?	If you have a system with thousands of routes defined in the routing table and nothing in the iptables rules than it might actually be more efficient to input an iptables rule.\n\nIn most systems however the routing table is fairly small, in cases like this it is actually more efficient to use null routes. This is especially true if you already have extensive iptables rules in place.\n\n\nRemember: /24=256, /16=65536, /8=16M. Formula: 2^(32-prefix).	projects/knowledge/interview/networking/055-you-need-to-block-several-ips-from-the-same-subnet.txt
networking/5644a27420b1	networking	hard	http, network, networking	How are cookies passed in the HTTP protocol?	The server sends the following in its response header to set a cookie field:\n\n`Set-Cookie:name=value`\n\nIf there is a cookie set, then the browser sends the following in its request header:\n\n`Cookie:name=value`\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/052-how-are-cookies-passed-in-the-http-protocol.txt
networking/59b1074a718d	networking	medium	dns, networking, tcp, udp	Is DNS using TCP or UDP?	DNS uses UDP port 53 for resolving queries either regular or reverse. DNS uses TCP for zone transfer.\n\nRemember: TCP=reliable/ordered/connected. UDP=fast/unreliable. TCP for web, UDP for DNS/video.	projects/knowledge/interview/networking/084-is-dns-using-tcp-or-udp.txt
networking/5e72fbdd73d1	networking	medium	dns, http, network, networking	According to an HTTP monitor, a website is down. You're able to telnet to the port, so how do you resolve it?	If you can telnet to the port, this means that the service listening on the port is running and you can connect to it (it's not a networking problem). It is good to check this way for the IP address to which the domain is resolved and using the same domain to test connection.\n\n\nRemember: 22=SSH, 53=DNS, 80=HTTP, 443=HTTPS, 3306=MySQL, 5432=PG.	projects/knowledge/interview/networking/022-according-to-an-http-monitor-a-website-is-down-you.txt
networking/622b014ec371	networking	easy	dns, networking, osi-model	What is a PTR record?	While an A record points a domain name to an IP address, a PTR record does the opposite and resolves the IP address to a domain name.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/080-what-is-a-ptr-record.txt
networking/638f2db232a9	networking	easy	network, networking, tcp	What POP and IMAP are, and how to choose which of them you should implement?	POP and IMAP are both protocols for retrieving messages from a mail server to a mail client.\n\n**POP** (_Post Office Protocol_) uses a one way push from mail server to client. By default this will send messages to the POP mail client and remove them from the mail server, though it is possible to configure the mail server to retain all messages.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/004-what-pop-and-imap-are-and-how-to-choose-which-of-t.txt
networking/65b7d53d70ec	networking	hard	network, networking, tcp, udp	Create a single-use TCP or UDP proxy with `netcat`.	```bash\n### TCP -> TCP\nnc -l -p 2000 -c "nc [ip|hostname] 3000"\n\n### TCP -> UDP\nnc -l -p 2000 -c "nc -u [ip|hostname] 3000"\n\n### UDP -> UDP\nnc -l -u -p 2000 -c "nc -u [ip|hostname] 3000"\n\n### UDP -> TCP\nnc -l -u -p 2000 -c "nc [ip|hostname] 3000"\n```\n\nRemember: TCP=reliable/ordered/connected. UDP=fast/unreliable. TCP for web, UDP for DNS/video.	projects/knowledge/interview/networking/061-create-a-single-use-tcp-or-udp-proxy-with-codenetc.txt
networking/6863a866ae1b	networking	medium	dns, networking	Describe DNS resolution workflow in high-level	In general the process is as follows:\n\n  * The user types an address in the web browser (some_site.com)\n  * The operating system gets a request from the browser to translate the address the user entered\n  * A query created to check if a local entry of the address exists in the system.\n\nRemember: DNS port 53. Resolution: cache→hosts→recursive→root→TLD→authoritative.	projects/knowledge/interview/networking/074-describe-dns-resolution-workflow-in-high-level.txt
networking/6878243e9dcb	networking	easy	http, network, networking	Why should you avoid `telnet` to administer a system remotely?	Modern operating systems have turned off all potentially insecure services by default. On the other hand, some vendors of network devices still allow to establish communication using the telnet protocol.\n\n**Telnet** uses most insecure method for communication. It sends data across the network in plain text format and anybody can easily find out the password using the network tool.\n\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/011-why-should-you-avoid-codetelnetcode-to-administer-.txt
networking/6c21286771a1	networking	hard	dns, network, networking	If you try resolve hostname you get `NXDOMAIN` from `host` command. Your `resolv.conf` stores two nameservers but only second of this store this domain name. Why did not the local resolver check the second nameserver?	**NXDOMAIN** is nothing but non-existent Internet or Intranet domain name. If domain name is unable to resolved using the DNS, a condition called the **NXDOMAIN** occurred.\n\nThe default behavior for `resolv.conf` and the `resolver` is to try the servers in the order listed. The resolver will only try the next nameserver if the first nameserver times out.\n\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/044-if-you-try-resolve-hostname-you-get-codenxdomainco.txt
networking/6e33cb9a05ca	networking	medium	dns, http, network, networking	Dev team reports an error: `POST http://ws.int/api/v1/Submit/ resulted in a 413 Request Entity Too Large`. What's wrong?	**Modify NGINX configuration file for domain**\n\nSet correct `client_max_body_size` variable value:\n\n```bash\nclient_max_body_size 20M;\n```\n\nRestart Nginx to apply the changes.\n\n**Modify php.ini file for upload limits**\n\n\n\nRemember: 22=SSH, 53=DNS, 80=HTTP, 443=HTTPS, 3306=MySQL, 5432=PG.	projects/knowledge/interview/networking/024-dev-team-reports-an-error-codepost-httpwsintapiv1s.txt
networking/74b9a83f5d7f	networking	easy	network, networking, routing, switching, tcp	Why couldn't MAC addresses be used instead of IPv4/6 for networking?	The **OSI** model explains why it doesn't make sense to make routing, a **layer 3** concept, decisions based on a physical, **layer 2**, mechanism.\n\nModern networking is broken into many different layers to accomplish your end to end communication.\n\nRemember: MAC = 48-bit. First 3 bytes=vendor(OUI). Format: AA:BB:CC:DD:EE:FF.	projects/knowledge/interview/networking/019-why-couldnt-mac-addresses-be-used-instead-of-ipv46.txt
networking/813206ffaef2	networking	easy	networking, dns, dhcp, load-balancing	What's your networking experience?	I've managed DNS, DHCP, HAProxy/Nginx load balancers, routing on Mellanox/Cumulus/HP gear, and firewall/SELinux rules. My strength is troubleshooting: understanding what layer the problem lives in, running packet traces, validating routes, MTU issues, or misconfigured ACLs. I can work comfortably across L2–L7.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/089-whats-your-networking-experience.txt
networking/83925991e398	networking	easy	network, networking, osi-model	What are the most important things to understand about the OSI (or any other) model?	The most important things to understand about the **OSI** (or any other) model are:\n\n- we can divide up the protocols into layers\n- layers provide encapsulation\n- layers provide abstraction\n- layers decouple functions from others\n\nRemember: 7 layers: Physical, Data Link, Network, Transport, Session, Presentation, App. "Please Do Not Throw Sausage Pizza Away."	projects/knowledge/interview/networking/001-what-are-the-most-important-things-to-understand-a.txt
networking/848a22dc6f79	networking	easy	networking, network	What is SSH and how does it work?	**SSH** stands for **Secure Shell**. It is a protocol that lets you drop from a server "A" into a shell session to a server "B". It allows you interact with your server "B".\n\nAn **SSH** connection to be established, the remote machine (server A) must be running a piece of software called an **SSH** daemon and the user's computer (server B) must have an **SSH** client.\n\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/013-what-is-ssh-and-how-does-it-work.txt
networking/87d9b578712a	networking	easy	dns, networking	Given the following fqdn, www.blipblop.com, what is the root?	`.` is the root\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/070-given-the-following-fqdn-wwwblipblopcom-what-is-th.txt
networking/88e925e4c9da	networking	easy	arp, dns, network, networking, tcp	How to resolve the domain name (using external dns) with CLI? Can IPs be resolved to domain names?	Examples for resolve IP address to domain name:\n\n```bash\n# with host command:\nhost domain.com 8.8.8.8\n\n# with dig command:\ndig @9.9.9.9 google.com\n\n# with nslookup command:\nnslookup domain.com 8.8.8.8\n```\n\nYou can (sometimes) resolve an IP Address back to a hostname. IP Address can be stored against a **PTR** record.\n\nRemember: DNS port 53. Resolution: cache→hosts→recursive→root→TLD→authoritative.	projects/knowledge/interview/networking/009-how-to-resolve-the-domain-name-using-external-dns-.txt
networking/892c1c218026	networking	medium	firewall, network, networking, tcp	How to allow traffic to/from specific IP with iptables?	For example:\n\n```bash\n/sbin/iptables -A INPUT -p tcp -s XXX.XXX.XXX.XXX -j ACCEPT\n/sbin/iptables -A OUTPUT -p tcp -d  XXX.XXX.XXX.XXX -j ACCEPT\n```\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/034-how-to-allow-traffic-tofrom-specific-ip-with-iptab.txt
networking/8988bb84519f	networking	hard	dns, network, networking	What is the difference between an authoritative and a nonauthoritative answer to a DNS query?	An authoritative DNS query answer comes from the server that contains the zone files for the domain queried. This is the name server that the domain administrator set up the DNS records on. A nonauthoriative answer comes from a name server that does not host the domain zone files (for example, a commonly used name server has the answer cached such as Google's 8.8.8.8 or OpenDNS 208.67.222.222).\n\nRemember: DNS port 53. Resolution: cache→hosts→recursive→root→TLD→authoritative.	projects/knowledge/interview/networking/043-what-is-the-difference-between-an-authoritative-an.txt
networking/8bab30596644	networking	easy	http, network, networking	How to test port connectivity with `telnet` or `nc`?	Test port connectivity with `telnet host port` or `nc -vz host port`. \nExample: `nc -vz db.example.com 5432` tests PostgreSQL reachability. The `-z` flag in nc does a scan without sending data. Common ports to remember: 22=SSH, 53=DNS, 80=HTTP, 443=HTTPS, 3306=MySQL, 5432=PostgreSQL, 6379=Redis.	projects/knowledge/interview/networking/010-how-to-test-port-connectivity-with-codetelnetcode-.txt
networking/8bdcb885f3b1	networking	medium	dns, networking, tls	What types of DNS records are there?	* A\n  * CNAME\n  * PTR\n  * MX\n  * AAAA\n  ...\n\nA more detailed list, can be found [here](https://www.nslookup.io/learning/dns-record-types)\n\nRemember: A=IPv4, AAAA=IPv6, CNAME=alias, MX=mail, NS=nameserver, TXT=text.	projects/knowledge/interview/networking/076-what-types-of-dns-records-are-there.txt
networking/8be1abdda6e5	networking	easy	dns, networking	What is a DNS record?	A DNS record is a database entry that maps a domain name to specific data, most commonly an IP address. Record types: A (domain to IPv4), AAAA (domain to IPv6), CNAME (alias to another domain), MX (mail server), NS (authoritative nameserver), TXT (arbitrary text, used for SPF/DKIM/verification). Query with: `dig example.com A`.	projects/knowledge/interview/networking/075-what-is-a-dns-record.txt
networking/8f3427da8a08	networking	easy	load-balancing, network, networking, routing, tcp	What are the advantages of using a reverse proxy server?	**Hide the topology and characteristics of your back-end servers**\n\nThe **reverse proxy server** can hide the presence and characteristics of the origin server. It acts as an intermediate between internet cloud and web server. It is good for security reason especially when you are using web hosting services.\n\n\nRemember: Forward=hide client. Reverse=hide server. "Forward=client, Reverse=server."	projects/knowledge/interview/networking/016-what-are-the-advantages-of-using-a-reverse-proxy-s.txt
networking/9054b84744fd	networking	medium	networking, routing, switching, tcp	What is the difference between TCP retransmits and packet loss?	They're related but not the same:\n\n**Packet loss**: Network-level event - packets dropped by router, switch, NIC, or firewall.\n\n**TCP retransmits**: TCP's response to perceived loss (timeout or duplicate ACKs). TCP retransmits when it thinks packets were lost.\n\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/090-difference-between-tcp-retransmits-and-packet-loss.txt
networking/9737a1409f0e	networking	easy	dhcp, dns, network, networking, udp	List 5 common network ports you should know.	Five essential ports: SMTP (25) — email relay. FTP (20 data transfer, 21 control connection). DNS (53) — name resolution. DHCP (67/UDP server, 68/UDP client) — dynamic IP assignment. SSH (22) — encrypted remote shell access.\n\nRemember: 22=SSH, 53=DNS, 80=HTTP, 443=HTTPS, 3306=MySQL, 5432=PG.	projects/knowledge/interview/networking/003-list-5-common-network-ports-you-should-know.txt
networking/9f47e97f46d6	networking	easy	dns, networking	Given the following fqdn, www.blipblop.com, what is the domain?	`www.blipblop.com.` is the domain\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/073-given-the-following-fqdn-wwwblipblopcom-what-is-th.txt
networking/a0f70351f3f8	networking	medium	http, network, networking, tls	Analyse web server log and show only `5xx` http codes. What external tools do you use?	```bash\ntail -n 100 -f /path/to/logfile | grep "HTTP/[1-2].[0-1]\" [5]"\n```\n\nExamples of http/https log management tools:\n\n- **goaccess** - is an open source real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through your browser\n- **graylog** - is a free and open-source log management platform that supports in-depth log collection and analysis\n\nRemember: 2xx=success, 3xx=redirect, 4xx=client error, 5xx=server. 200/404/500 are key.	projects/knowledge/interview/networking/037-analyse-web-server-log-and-show-only-code5xxcode-h.txt
networking/a2bd8edd9e90	networking	easy	network, networking, tcp	Most tutorials suggest using SSH key authentication rather than password authentication. Why it is considered more secure?	An **SSH key** is an access credential in the SSH protocol. Its function is similar to that of user names and passwords, but the keys are primarily used for automated processes and for implementing single sign-on by system administrators and power users.\n\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/014-most-tutorials-suggest-using-ssh-key-authenticatio.txt
networking/a3fb4077b571	networking	easy	dns, network, networking, tcp	Explain the function of each of the following DNS records: SOA, PTR, A, MX, and CNAME.	**DNS records** are basically mapping files that tell the DNS server which IP address each domain is associated with, and how to handle requests sent to each domain. Some **DNS records** syntax that are commonly used in nearly all DNS record configurations are `A`, `AAAA`, `CNAME`, `MX`, `PTR`, `NS`, `SOA`, `SRV`, `TXT`, and `NAPTR`.\n\n\nRemember: A=IPv4, AAAA=IPv6, CNAME=alias, MX=mail, NS=nameserver, TXT=text.	projects/knowledge/interview/networking/018-explain-the-function-of-each-of-the-following-dns-.txt
networking/a63347d9f631	networking	hard	linux, networking, switching, troubleshooting	How do you debug intermittent network drops?	Systematic approach across layers:\n\n1. **Interface errors**:\n```bash\nip -s link show eth0\nethtool -S eth0 | grep -i error\n```\n\n2. **MTU mismatches**: Path MTU discovery issues cause intermittent failures\n```bash\nping -M do -s 1472 destination\n```\n\n3. **Bonding/LACP state**: Check both sides match\n```bash\ncat /proc/net/bonding/bond0\n```\n\n4.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/091-how-do-you-debug-intermittent-network-drops.txt
networking/a6ba31c2dfc9	networking	medium	tcp, handshake, protocols	Explain the TCP three-way handshake and why it's necessary.	The three-way handshake establishes a TCP connection between client and server.\nIt ensures both sides are ready to communicate and synchronizes sequence numbers.\n\nThe process:\n1. SYN: Client sends SYN packet with initial sequence number (ISN)\n2. SYN-ACK: Server responds with SYN-ACK, its own ISN, and ACKs client's ISN\n3.\n\nRemember: TCP 3-way: SYN→SYN-ACK→ACK. Teardown: FIN→ACK, FIN→ACK (4-way).	projects/knowledge/interview/networking/001-tcp-three-way.txt
networking/a96011925072	networking	medium	dns, linux, networking, routing, switching	How does Linux routing actually work?	Linux routing follows this order:\n\n1. **Longest prefix match**: Most specific route wins from the routing table\n2. **Policy routing** (if configured): Rules in `ip rule` can override normal lookup\n3. **ARP/neighbor resolution**: Once next-hop determined, resolve MAC address\n\n```bash\n# View routing table\nip route show\n# View routing decision for specific destination\nip route get 8.8.8.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/089-how-does-linux-routing-actually-work.txt
networking/ad13d0a09d86	networking	easy	dns, networking	What is a CNAME record?	CNAME: maps a hostname to another hostname.\n\nThe target should be a domain name which must have an A or AAAA record. Think of it as an alias record.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/079-what-is-a-cname-record.txt
networking/b45ed4818f60	networking	easy	dns, networking	What is a AAAA record?	An AAAA Record performs the same function as an A Record, but for an IPv6 Address.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/078-what-is-a-aaaa-record.txt
networking/b87da7139f33	networking	hard	firewall, network, networking, tcp	Explain 3 techniques for avoiding firewalls with `nmap`.	**Use Decoy addresses**\n\n```bash\n# Generates a random number of decoys.\nnmap -D RND:10 [target]\n\n# Manually specify the IP addresses of the decoys.\nnmap -D decoy1,decoy2,decoy3\n```\n\nIn this type of scan you can instruct Nmap to spoof packets from other hosts.\n\nRemember: Types: packet filter(L3/4), stateful(connections), WAF(L7). Defense in depth.	projects/knowledge/interview/networking/062-explain-3-techniques-for-avoiding-firewalls-with-c.txt
networking/b8ddadc2e901	networking	hard	http, load-balancing, network, networking	Does having Varnish in front of your website/app mean you don't need to care about load balancing or redundancy?	It depends. Varnish is a cache server, so its purpose is to cache contents and to act as a reverse proxy, to speed up retrieval of data and to lessen the load on the webserver.\nVarnish can be also configured as a load-balancer for multiple web servers, but if we use just one Varnish server, this will become our single point of failure on our infrastructure.\n\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/048-does-having-varnish-in-front-of-your-websiteapp-me.txt
networking/ba941bb54106	networking	easy	dhcp, dns, networking, tls	What is a domain name registrar?	[Cloudflare](https://www.cloudflare.com/en-gb/learning/dns/glossary/what-is-a-domain-name-registrar): "A domain name registrar provides domain name registrations to the general public. A common misconception is that registrars sell domain names; these domain names are actually owned by registries and can only be leased by users."\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/069-what-is-a-domain-name-registrar.txt
networking/bb6c281c6888	networking	hard	dhcp, dns, network, networking, routing	What types of dns cache working when you type api.example.com in your browser and press return?	Browser checks if the domain is in its cache (to see the DNS Cache in Chrome, go to `chrome://net-internals/#dns`). When this cache fails, it simply asks the OS to resolve the domain.\n\nThe OS resolver has it's own cache which it will check. If it fails this, it resorts to asking the OS configured DNS servers.\n\n\nRemember: DNS port 53. Resolution: cache→hosts→recursive→root→TLD→authoritative.	projects/knowledge/interview/networking/058-what-types-of-dns-cache-working-when-you-type-apie.txt
networking/c48496a8e44e	networking	hard	network, networking, vpn	How to run `scp` with a second remote host?	With `ssh`:\n\n```bash\nssh user1@remote1 'ssh user2@remote2 "cat file"' > file\n```\n\nWith `tar` (with compression):\n\n```bash\nssh user1@remote1 'ssh user2@remote2 "cd path2; tar cj file"' | tar xj\n```\n\nWith `ssh` and port forwarding tunnel:\n\n```bash\n# First, open the tunnel\nssh -L 1234:remote2:22 -p 45678 user1@remote1\n\n# Then, use the tunnel to copy the file directly from remote2\nscp -P 1234 user2@localhost:file .\n```\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/056-how-to-run-codescpcode-with-a-second-remote-host.txt
networking/cb5fc1ed9fb2	networking	hard	networking, mtu, performance, troubleshooting	Why can increasing MTU actually reduce throughput?	Path MTU mismatches cause fragmentation or black-holed packets.\n\nThe problem:\n\n1. Path MTU mismatch\n   - Your server: MTU 9000 (jumbo frames)\n   - Intermediate router: MTU 1500\n   - Packets too big to forward\n\n2. ICMP black holes\n   - Router should send "Fragmentation Needed"\n   - Firewalls often block ICMP\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/100-mtu-increase-reduce-throughput.txt
networking/cb9e8f67966d	networking	easy	dns, networking	What is the resolution sequence of: www.site.com	It's resolved in this order:\n\n1) .\n2) .com\n3) site.com\n4) www.site.com\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/068-what-is-the-resolution-sequence-of-wwwsitecom.txt
networking/d00b77b500b4	networking	easy	dns, networking	Given the following fqdn, www.blipblop.com, what is the top level domain?	`.com.` is the top level domain\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/071-given-the-following-fqdn-wwwblipblopcom-what-is-th.txt
networking/d032fea70d3f	networking	medium	firewall, network, networking, routing, tcp	What is NAT? What is it used for?	It enables private IP networks that use unregistered IP addresses to connect to the Internet. **NAT** operates on a router, usually connecting two networks together, and translates the private (not globally unique) addresses in the internal network into legal addresses, before packets are forwarded to another network.\n\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/027-what-is-nat-what-is-it-used-for.txt
networking/d09570dad546	networking	hard	network, networking, tls	Is it safe to use SNI SSL in production? How to test connection with and without it? In which cases it is useful?	With OpenSSL:\n\n```bash\n# Testing connection to remote host (with SNI support)\necho | openssl s_client -showcerts -servername google.com -connect google.com:443\n# Testing connection to remote host (without SNI support)\necho | openssl s_client -connect google.\n\nRemember: TLS 1.3 current. ClientHello→ServerHello→Key Exchange→Encrypted. Port 443.	projects/knowledge/interview/networking/051-is-it-safe-to-use-sni-ssl-in-production-how-to-tes.txt
networking/d112f8827183	networking	medium	network, networking, tcp, udp	How to check which ports are listening on my Linux Server?	Use the:\n\n- `lsof -i`\n- `ss -l`\n- `netstat -atn` - for tcp\n- `netstat -aun` - for udp\n- `netstat -tulapn`\n\nRemember: 22=SSH, 53=DNS, 80=HTTP, 443=HTTPS, 3306=MySQL, 5432=PG.	projects/knowledge/interview/networking/029-how-to-check-which-ports-are-listening-on-my-linux.txt
networking/d3ab24d7c3b2	networking	medium	networking, http, protocols	Explain the difference between HTTP 1.1 and HTTP 2.0	HTTP/2 introduces major performance improvements over HTTP/1.1:\n\nHTTP/1.1:\n- Text-based protocol\n- One request per connection (or pipelining)\n- Head-of-line blocking\n- Headers sent every request (redundant)\n- Multiple connections per domain (6 typical)\n\nHTTP/2:\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/023-explain-difference-between-http-11-and-http-20.txt
networking/d9078a151355	networking	easy	network, networking, routing	How to check default route and routing table?	Using the commands `netstat -nr`, `route -n` or `ip route show` we can see the default route and routing tables.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/005-how-to-check-default-route-and-routing-table.txt
networking/d9352f18b8d3	networking	hard	http, network, networking	What is the difference between `Cache-Control: max-age=0` and `Cache-Control: no-cache`?	**When sent by the origin server**\n\n`max-age=0` simply tells caches (and user agents) the response is stale from the get-go and so they SHOULD revalidate the response (e.g. with the If-Not-Modified header) before using a cached copy, whereas, `no-cache` tells them they MUST revalidate before using a cached copy.\n\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/059-what-is-the-difference-between-codecache-control-m.txt
networking/d951087c2923	networking	easy	dns, networking	What is a DNS A record and what does it map?	A (Address): Maps a host name to an IPv4 address.\n\nWhen a computer has multiple adapter cards and IP addresses, it should have multiple address records.\n\nRemember: A=IPv4, AAAA=IPv6, CNAME=alias, MX=mail, NS=nameserver, TXT=text.	projects/knowledge/interview/networking/077-what-is-a-a-record.txt
networking/d989eb86b818	networking	medium	network, networking, routing, tcp, udp	Why is UDP faster than TCP?	**UDP** is faster than **TCP**, and the simple reason is because its nonexistent acknowledge packet (`ACK`) that permits a continuous packet stream, instead of TCP that acknowledges a set of packets, calculated by using the TCP window size and round-trip time (`RTT`).\n\nRemember: TCP=reliable/ordered/connected. UDP=fast/unreliable. TCP for web, UDP for DNS/video.	projects/knowledge/interview/networking/026-why-is-udp-faster-than-tcp.txt
networking/d9d7bbd63547	networking	easy	dns, network, networking, routing, tcp	Server A can't talk to Server B. Describe possible reasons in a few steps.	To troubleshoot communication problems between servers, it is better to ideally follow the TCP/IP stack:\n\n1. **Application Layer**: are the services up and running on both servers? Are they correctly configured (eg. bind the correct IP and correct port)? Do application and system logs show meaningful errors?\n\n2.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/008-server-a-cant-talk-to-server-b-describe-possible-r.txt
networking/e2f48086b393	networking	medium	networking, network	How to block abusive IP addresses with `pf` in OpenBSD?	The best way to do this is to define a table and create a rule to block the hosts, in `pf.conf`:\n\n```bash\ntable <badhosts> persist\nblock on fxp0 from <badhosts> to any\n```\n\nAnd then dynamically add/delete IP addresses from it:\n\n```bash\npfctl -t badhosts -T add 1.2.3.4\npfctl -t badhosts -T delete 1.2.3.4\n```\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/035-how-to-block-abusive-ip-addresses-with-codepfcode-.txt
networking/e4f0fb102c85	networking	medium	network, networking, tcp, tls	What is handshake mechanism and why do we need 3 way handshake?	**Handshaking** begins when one device sends a message to another device indicating that it wants to establish a communications channel. The two devices then send several messages back and forth that enable them to agree on a communications protocol.\n\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/025-what-is-handshake-mechanism-and-why-do-we-need-3-w.txt
networking/e690eea0e31d	networking	hard	networking, network	How can you reduce load time of a dynamic website?	- webpage optimization\n- cached web pages\n- quality web hosting\n- compressed text files\n- apache/nginx tuning\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/057-how-can-you-reduce-load-time-of-a-dynamic-website.txt
networking/e6967743571b	networking	medium	network, networking, tcp	What mean `Host key verification failed` when you connect to the remote host? Do you accept it automatically?	`Host key verification failed` means that the host key of the remote host was changed. This can easily happen when connecting to a computer who's host keys in `/etc/ssh` have changed if that computer was upgraded without copying its old host keys.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/030-what-mean-codehost-key-verification-failedcode-whe.txt
networking/ea0460782c35	networking	easy	dns, network, networking, tcp, udp	What is a packet filter and how does it work?	**Packet filtering** is a firewall technique used to control network access by monitoring outgoing and incoming packets and allowing them to pass or halt based on the source and destination Internet Protocol (IP) addresses, protocols and ports.\n\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/015-what-is-a-packet-filter-and-how-does-it-work.txt
networking/edc28c1f7a21	networking	medium	dns, networking	What types of zones are there?	There are several types, including:\n\n* Primary zone: A primary zone is a read/write zone that is stored in a master DNS server.\n\n* Secondary zone: A secondary zone is a read-only copy of a primary zone that is stored in a slave DNS server. \n\n* Stub zone: A stub zone is a type of zone that contains only the essential information about a domain name. It is used to reduce the amount of DNS traffic and improve the efficiency of the DNS resolution process.	projects/knowledge/interview/networking/088-what-types-of-zones-are-there.txt
networking/eeb198dbfde8	networking	medium	dns, load-balancing, networking	Which techniques a DNS can use for load balancing?	There are several techniques that a DNS can use for load balancing, including:\n\n* Round-robin DNS\n\n* Weighted round-robin DNS\n\n* Least connections\n\n* GeoDNS\n\nRemember: DNS port 53. Resolution: cache→hosts→recursive→root→TLD→authoritative.	projects/knowledge/interview/networking/086-which-techniques-a-dns-can-use-for-load-balancing.txt
networking/ef226ef9b31a	networking	hard	networking, network	What are hits, misses, and hit-for-pass in Varnish Cache?	A **hit** is a request which is successfully served from the cache, a **miss** is a request that goes through the cache but finds an empty cache and therefore has to be fetched from the origin, the **hit-for-pass** comes in when Varnish Cache realizes that one of the objects it has requested is uncacheable and will result in a pass.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/049-what-are-hits-misses-and-hit-for-pass-in-varnish-c.txt
networking/f3591599b2f0	networking	hard	networking, network	How do I measure request and response times at once using `curl`?	`curl` supports formatted output for the details of the request (see the `curl` manpage for details, under `-w| -write-out 'format'`). For our purposes we’ll focus just on the timing details that are provided.\n\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/047-how-do-i-measure-request-and-response-times-at-onc.txt
networking/f88a65131655	networking	hard	network, networking, tcp, tls	Is it possible to have SSL certificate for IP address, not domain name?	It is possible (but rarely used) as long as it is a public IP address.\n\nAn SSL certificate is typically issued to a Fully Qualified Domain Name (FQDN) such as `https://www.domain.com`. However, some organizations need an SSL certificate issued to a public IP address. This option allows you to specify a public IP address as the Common Name in your Certificate Signing Request (CSR).\n\nRemember: TLS 1.3 current. ClientHello→ServerHello→Key Exchange→Encrypted. Port 443.	projects/knowledge/interview/networking/045-is-it-possible-to-have-ssl-certificate-for-ip-addr.txt
networking/faf2d0efe6d2	networking	medium	dns, resolution, networking-basics	Walk through what happens when you type a URL in your browser (DNS resolution).	When you enter example.com, here's the DNS resolution process:\n\n1. Browser Cache: Check if IP is cached locally\n2. OS Cache: Check system DNS cache (/etc/hosts, systemd-resolved)\n3. Resolver Query: If not cached, query configured DNS resolver\n\nRecursive resolution (by resolver):\n4. Root Servers: Resolver asks root servers (.) for .com nameservers\n5. TLD Servers: Ask .\n\nRemember: DNS port 53. Resolution: cache→hosts→recursive→root→TLD→authoritative.	projects/knowledge/interview/networking/002-dns-resolution.txt
networking/fea1e2c2af3f	networking	medium	dns, http, network, networking	When does the web server like Apache or Nginx write info to log file? Before or after serving the request?	Both servers provides very comprehensive and flexible logging capabilities - for logging everything that happens on your server, from the initial request, through the URL mapping process, to the final resolution of the connection, including any errors that may have occurred in the process.\n\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	projects/knowledge/interview/networking/036-when-does-the-web-server-like-apache-or-nginx-writ.txt
networking/z1a2b3c4d5e6	networking	easy	networking,layers,encapsulation	What are the four main header layers in a typical network packet?	Ethernet frame (L2), IP header (L3), TCP or UDP header (L4), and application protocol data (L7, e.g., HTTP or DNS). Each layer wraps the payload of the layer above.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	zines/networking.ack.zine.cleaned.notes
networking/z2b3c4d5e6f7	networking	easy	networking,IP,port,distinction	What is the difference between an IP address and a port number?	An IP address identifies which host on the network should receive the packet (L3 routing). A port number identifies which service or socket on that host should process it (L4 demultiplexing).\n\nRemember: 22=SSH, 53=DNS, 80=HTTP, 443=HTTPS, 3306=MySQL, 5432=PG.	zines/networking.ack.zine.cleaned.notes
networking/z3c4d5e6f7a8	networking	medium	networking,TCP,UDP,comparison	Name three features TCP provides that UDP does not.	Connection state (established sessions), ordered delivery (sequence numbers ensure correct order), and automatic retransmission of lost packets. UDP trades these for lower overhead and latency.\n\nRemember: TCP=reliable/ordered/connected. UDP=fast/unreliable. TCP for web, UDP for DNS/video.	zines/networking.ack.zine.cleaned.notes
networking/z4d5e6f7a8b9	networking	medium	networking,packet-journey,steps	Describe the typical journey of an HTTP request from browser to server.	1. DNS resolves hostname to IP.\n2. TCP three-way handshake (SYN, SYN-ACK, ACK).\n3. TLS handshake if HTTPS.\n4. HTTP request sent.\n5. Server processes and sends HTTP response.\n6. Packets traverse routers using IP forwarding at each hop.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	zines/networking.ack.zine.cleaned.notes
networking/z5e6f7a8b9c0	networking	easy	networking,TTL,routing-loops	What is the purpose of the TTL field in an IP packet?	TTL (Time To Live) is decremented at each router hop. When it reaches zero, the packet is dropped. This prevents packets from circulating forever in routing loops.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	zines/networking.ack.zine.cleaned.notes
networking/z6f7a8b9c0d1	networking	medium	networking,routers,forwarding	What do routers primarily use to make forwarding decisions?	The destination IP address in the IP header. Routers consult their routing table to determine the next hop. They do not typically look at ports or application-layer data (unless doing deep packet inspection or NAT).\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	zines/networking.ack.zine.cleaned.notes
networking/z7a8b9c0d1e2	networking	medium	networking,troubleshooting,layer-by-layer	What is the systematic approach to debugging a network connectivity failure?	Work through layers: 1. Does DNS resolve? (dig) 2. Is the IP reachable? (ping) 3. Is the port open? (nc, telnet) 4. Does TCP connect? (curl, ss) 5. Does TLS succeed? (openssl s_client) 6. Does HTTP respond correctly? (curl -v)\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	zines/networking.ack.zine.cleaned.notes
networking/z8b9c0d1e2f3	networking	easy	networking,UDP,use-cases	Name two protocols that use UDP and explain why.	DNS (fast, small queries where retransmit at application layer is simpler) and real-time media like VoIP/video (latency matters more than occasional packet loss; retransmitting stale audio is useless).\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	zines/networking.ack.zine.cleaned.notes
networking/z9c0d1e2f3a4	networking	hard	networking,headers,questions	What five questions do packet headers collectively answer?	Where did this come from? (source IP/MAC) Where is it going? (destination IP/MAC) Which protocol is next? (protocol field) Which service should receive it? (port) How long can it live? (TTL)\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	zines/networking.ack.zine.cleaned.notes
networking/zad1e2f3a4b5	networking	medium	networking,NAT,home-router	What role does a home router play in the packet journey?	It acts as the default gateway and typically performs NAT (Network Address Translation), rewriting private source IPs to the public IP for outgoing traffic and reversing for return traffic. It connects the local LAN to the ISP.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	zines/networking.ack.zine.cleaned.notes
networking/0b5b20050a67	networking	medium	miscellaneous, control-flow, networking, processes	Have you been involved in the procurement process for data center equipment and services?	• Needs Assessment: Collaborate with relevant stakeholders to assess the specific needs and requirements for data center equipment and services. • Vendor Evaluation: Participate in the evaluation of vendors, considering factors such as performance, reliability, cost, and support services. • Budget Planning: Contribute to budget planning by providing insights into the estimated costs of equipment and services. • Request for Proposals (RFPs): Assist in the creation of RFPs, ensuring they clearly articulate the specifications and expectations for potential vendors.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	
networking/18f6d1dbc619	networking	medium	miscellaneous, control-flow, networking, package-management	How do you ensure that documentation for server configurations is accurate and up-to-date?	• Version Control: Use version control systems for documentation to track changes and updates, ensuring a clear history of configurations. • Change Management: Require documentation updates as part of the change management process, ensuring any configuration changes are reflected promptly. • Automated Documentation Tools: Implement tools that automatically generate documentation based on real-time server configurations, reducing manual efforts and minimizing errors.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	
networking/243e217fae47	networking	medium	miscellaneous, control-flow	What steps do you take to maintain an inventory of all servers and networking equipment?	• Asset Discovery: Regularly conduct asset discovery scans to identify all servers and networking equipment connected to the data center network. • Asset Tracking: Implement an asset tracking system that records details such as make, model, serial number, location, and owner for each server and networking device. • Automated Tools: Utilize automated inventory management tools that can continuously monitor the network and update the inventory database in real-time.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	
networking/31625dfa9656	networking	medium	miscellaneous, networking, text-processing	How do you handle conflicting priorities and requests from different teams?	• Prioritization Framework: Establish a prioritization framework based on business impact, urgency, and strategic importance to guide decision-making. • Collaborative Discussions: Engage in open and transparent discussions with teams to understand the urgency and impact of their requests. • Communication: Clearly communicate the reasons behind prioritization decisions to ensure teams understand the rationale. • Stakeholder Alignment: Align with key stakeholders and leadership to ensure a unified approach to prioritization.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	
networking/333248d59846	networking	medium	miscellaneous, control-flow, networking, text-processing	How do you handle environmental considerations like temperature and humidity in a data center?	Handling temperature and humidity in a data center is crucial for maintaining optimal conditions for hardware performance and longevity. Here's how a Data Center Engineer might handle these considerations: • **Temperature Control:* • Air Conditioning Systems: Implementing precision air conditioning systems to regulate and maintain the temperature within the recommended range. • **Hot Aisle/Cold Aisle Configuration:* • Designing server racks in a way that optimizes airflow and reduces hotspots.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	
networking/4ca1a6a5e72b	networking	medium	miscellaneous, control-flow, debugging, dns	Walk us through your approach to troubleshooting a server that is experiencing intermittent connectivity issues.	• Define the Problem: • Gather information about the specific connectivity issues reported. • Identify affected users, applications, or services. • Check Physical Connections: • Ensure physical connections, such as network cables and power cables, are secure. • Review Network Configurations: • Examine network configurations, including IP addresses, DNS settings, and subnet masks. • Ping and Traceroute: • Use tools like ping and traceroute to identify where connectivity issues may be occurring.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	
networking/5b7410029f9e	networking	medium	miscellaneous, control-flow, load-balancing, logging	Discuss your experience with high-availability configurations and clustering in a data center.	• Load Balancing: Implemented load balancing configurations to distribute incoming traffic across multiple servers, ensuring optimal resource utilization and preventing single points of failure. • Redundant Networking: Configured redundant networking infrastructure, including multiple network paths and switches, to enhance network availability and resilience. • Server Clustering: Implemented server clustering using technologies such as Microsoft Failover Clustering or Linux-based clustering solutions to achieve high availability for critical applications.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	
networking/5e5a045cf22e	networking	medium	miscellaneous, control-flow, networking, processes	Explain the concept of edge computing and its relevance to data center operations.	Edge computing involves processing data closer to the source of data generation, reducing latency by decentralizing computation and storage resources. • Relevance to Data Centers: Edge computing complements traditional centralized data centers by distributing processing capabilities to the network edge, addressing the limitations of latency-sensitive applications. **Key Components:* •  • In edge computing, data processing occurs on devices or edge servers located near the data source, reducing the need for data to travel to a centralized data center.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	
networking/68283837e72b	networking	medium	miscellaneous, control-flow, load-balancing, networking	Discuss the concept of load balancing in a data center network.	Load balancing is the distribution of network traffic across multiple servers or paths to ensure that no single server or network link is overwhelmed with too much traffic. The primary purpose of load balancing is to improve the availability, reliability, and performance of applications by distributing the workload across multiple resources. **How it Works:* •  • Distribution Algorithms: Load balancers use various distribution algorithms (round-robin, least connections, weighted distribution, etc.) to determine how to distribute incoming traffic among the available servers.	
networking/79386a0378f2	networking	medium	miscellaneous, control-flow, dns, networking	What tools and techniques do you use for diagnosing network latency issues?	• Ping and Traceroute: Use ping to measure round-trip time and traceroute to identify network hops and potential latency points. • Network Monitoring Tools: Utilize network monitoring tools like Wireshark, Nagios, or SolarWinds to capture and analyze network traffic for latency issues. • PathPing: Use pathping to trace the route to a destination and measure packet loss and latency at each hop. • Packet Loss Analysis: Analyze packet loss rates, as high packet loss can contribute to latency.\n\nRemember: 7 layers: Physical, Data Link, Network, Transport, Session, Presentation, App. "Please Do Not Throw Sausage Pizza Away."	
networking/7d9a624ed7a1	networking	medium	miscellaneous, control-flow, networking, package-management	Discuss your experience in negotiating contracts with data center equipment vendors.	• Requirement Identification: Thoroughly identify and document the organization's requirements and priorities before entering contract negotiations to ensure clarity and alignment with business objectives. • Benchmarking and Market Research: Conduct benchmarking and market research to understand industry standards, pricing models, and common terms, providing a basis for informed negotiations. • Multiple Vendor Engagement: Engage with multiple vendors to create competition, allowing for negotiation leverage and potentially securing more favorable terms and pricing.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	
networking/851dd51b463c	networking	medium	miscellaneous, control-flow, dns, networking	How do you mitigate DDoS (Distributed Denial of Service) attacks in a data center?	Mitigating DDoS attacks involves implementing a combination of proactive and reactive measures: • **Traffic Scrubbing:* • Utilize DDoS mitigation services or appliances that can identify and filter out malicious traffic, allowing only legitimate traffic to reach the data center. • **Rate Limiting and Throttling:* • Implement rate limiting and throttling mechanisms to control the incoming traffic, preventing a sudden surge that could overwhelm the network.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	
networking/86e5590d14d3	networking	medium	miscellaneous, control-flow, networking, package-management	Discuss the benefits of Infrastructure as Code (IaC) in data center operations.	Infrastructure as Code (IaC) transforms infrastructure management into code, providing numerous benefits: **Consistency:* • IaC ensures consistency in infrastructure deployment by representing configurations as code, reducing the risk of configuration drift. **Automation:* • IaC automates the provisioning and management of infrastructure, enabling rapid and repeatable deployments. **Version Control:* • Infrastructure configurations are stored in version control systems, allowing for versioning, rollback, and collaboration among team members.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	
networking/b0022033f1dd	networking	medium	miscellaneous, control-flow, functions, networking	Have you worked on cross-functional projects involving data center upgrades or migrations?	Yes, I have experience working on cross-functional projects involving data center upgrades and migrations. In one instance, our organization decided to migrate from an on-premises data center to a cloud-based solution. • Project Planning: Collaborated with system administrators, network engineers, and cloud architects during the project planning phase to outline goals, timelines, and resource requirements. • Risk Assessment: Conducted a comprehensive risk assessment to identify potential challenges and develop mitigation strategies.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	
networking/e091c3796d54	networking	medium	miscellaneous, control-flow, networking, processes	How do you prioritize systems and services during a disaster recovery scenario?	Prioritizing systems and services during a disaster recovery scenario involves the following steps: • Criticality Assessment: Evaluate the criticality of each system and service to the business. Identify those essential for core business operations. • Recovery Time Objectives (RTO): Assign RTOs to each system based on business needs. Prioritize systems with shorter RTOs. • Dependencies: Consider dependencies between systems. Prioritize systems that are prerequisites for others or have significant interdependencies. • Customer Impact: Assess the impact on customers and end-users.	
networking/ed5e80215fad	networking	medium	miscellaneous, control-flow, load-balancing, logging	How do you optimize storage performance in a data center?	• **Storage Tiering:* • Implement storage tiering to place frequently accessed data on high-performance storage and less accessed data on lower-tier, cost-effective storage. • **Caching:* • Use caching mechanisms, such as SSD-based caching, to accelerate read and write operations by storing frequently accessed data in faster storage. • **RAID Configuration:* • Choose an appropriate RAID configuration based on performance and redundancy requirements. For example, RAID 10 provides both performance and redundancy.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	
networking/f050ecc14188	networking	medium	miscellaneous, control-flow, networking	Explain the importance of effective communication in a data center team.	• Coordination: Effective communication fosters coordination among team members, ensuring everyone is on the same page regarding tasks, timelines, and goals. • Issue Resolution: Clear communication facilitates quick identification and resolution of issues, preventing potential escalations. • Knowledge Sharing: Team members can share insights, best practices, and lessons learned, fostering a culture of continuous learning and improvement. • Project Alignment: Communication aligns team members with the objectives and priorities of ongoing projects, promoting a unified approach.\n\nRemember: 22=SSH, 53=DNS, 80=HTTP, 443=HTTPS, 3306=MySQL, 5432=PG.	
networking/f18af6c2276b	networking	medium	miscellaneous, control-flow, networking, processes	Explain the differences between traditional data center management and cloud-based data center management.	• Infrastructure Ownership: Traditional data center management involves owning and maintaining physical infrastructure, while cloud-based data center management relies on infrastructure provided by a third-party cloud service provider. • Scalability and Elasticity: Cloud-based data center management offers greater scalability and elasticity, allowing rapid scaling up or down based on demand, which is more challenging in traditional environments.\n\nRemember: OSI helps debug: check L1(physical)→L7(app). Most issues: DNS, firewall, routing.\n\nGotcha: Network troubleshooting: check DNS, firewall, routing first — covers 90% of issues.	

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [AWS Networking](../../../../library/topics/aws-networking/index.md) (Topic Pack, L1) — TCP/IP
- [Adversarial Interview Gauntlet (30 sequences)](../../../../library/interview-scenarios/gauntlet/README.md) (Scenario, L2) — TCP/IP
- [Case Study: Duplex Mismatch Symptoms](../../../../library/case-studies/networking/duplex-mismatch-symptoms/README.md) (Case Study, L1) — TCP/IP
- [Case Study: NAT Exhaustion Intermittent](../../../../library/case-studies/networking/nat-exhaustion-intermittent/README.md) (Case Study, L2) — TCP/IP
- [Case Study: TCP RST After Idle](../../../../library/case-studies/networking/tcp-rst-after-idle/README.md) (Case Study, L2) — TCP/IP
- [DHCP & IP Address Management](../../../../library/topics/dhcp-ipam/index.md) (Topic Pack, L1) — TCP/IP
- [Deep Dive: TCP/IP Deep Dive](../../../../library/deep-dives/tcp.ip.deep.dive.md) (deep_dive, L2) — TCP/IP
- [Deep Dive: TLS Handshake](../../../../library/deep-dives/tls.handshake.deep.dive.md) (deep_dive, L2) — TCP/IP
- [Networking Deep Dive](../../../../library/topics/networking/index.md) (Topic Pack, L1) — TCP/IP
- [Networking Drills](../../../../library/drills/networking_drills.md) (Drill, L1) — TCP/IP

<!-- wiki:related:end -->
