Use this guide to prepare for Network or Systems Engineer interviews, with a focus on osi model layers, linux boot process, spanning tree protocol. Explain your reasoning and connect it to experience you can substantiate.
These preparation themes come from the questions in this role’s bank. They help you organise your examples; individual employers may assess different things.
OSI model layers
Linux boot process
Spanning Tree Protocol
Campus network design
Network strategy and budget
Active Directory basics
A useful preparation sequence
Choose your experience level and the round you expect.
Answer one question in your own words before opening its guide.
Compare your reasoning, evidence and trade-offs; adapt the answer to your experience.
Practise the follow-up, then revisit one answer you want to improve.
Representative questions and answer guidance
Open any question to read its answer. The complete guidance is included on this page.
Technical · Fresher
1. What is the OSI model, and why do network engineers still use it?
Answer guide
The OSI model splits network communication into seven layers: physical, data link, network, transport, session, presentation and application. Each layer has a defined job and talks to the same layer on the other side through the layer below it. I use it mainly as a shared vocabulary and a troubleshooting map. If a cable is unplugged I think layer one, if a MAC or VLAN problem I think layer two, if routing or IP addressing I think layer three, and so on. Real protocols such as TCP/IP do not match it exactly, but the model still helps isolate faults systematically.
What this question explores
Whether you can explain layered networking clearly and connect the model to practical troubleshooting rather than just reciting layer names.
Common mistakes
Reciting the seven layer names from memory without explaining what each layer actually does.
Claiming real networks strictly implement OSI, when TCP/IP is the model actually used in practice.
Practise a follow-up
How does the TCP/IP model map onto the OSI layers?
At which layer does a switch normally operate, and why?
2. Can you describe the main stages of the Linux boot process on a typical server?
Answer guide
On a typical server the firmware, BIOS or UEFI, runs hardware checks and finds a boot device. It hands control to a bootloader such as GRUB, which shows a menu and loads the kernel along with an initial RAM filesystem. The kernel initialises hardware, uses the initramfs to find and mount the real root filesystem, and then starts the first user space process, which is systemd on most modern distributions. Systemd then brings up services and targets until the system reaches its default state. Knowing these stages helps me decide where to look when a machine fails to boot.
What this question explores
Whether you understand the order of boot stages well enough to locate where a boot failure happens.
Common mistakes
Skipping the initramfs and describing the kernel as mounting the root filesystem on its own.
Confusing the bootloader with the kernel or the init system.
Practise a follow-up
What is the purpose of the initramfs?
How would you recover a server that stops at the GRUB prompt?
3. Why is Spanning Tree needed, and how does it choose the root bridge?
Answer guide
Redundant layer two links create loops, and because Ethernet frames have no TTL, broadcasts can circulate endlessly and cause storms and MAC table instability. Spanning Tree blocks some redundant ports to leave a loop-free topology while keeping them ready as backups. Switches elect one root bridge, the one with the lowest bridge ID, which is the priority value followed by the MAC address. Other switches choose a root port toward the root by lowest path cost, and each segment gets a designated port. I set the priority deliberately on core switches so the root is predictable instead of an old access switch.
What this question explores
Whether you understand why loops are harmful at layer two and can influence root bridge placement rather than leaving it to chance.
Common mistakes
Leaving default priorities so the oldest switch with the lowest MAC address becomes root.
Saying Spanning Tree removes the redundant cables, instead of logically blocking ports.
Practise a follow-up
What is the benefit of Rapid Spanning Tree over classic STP?
What do PortFast and BPDU guard do on access ports?
4. How would you design a resilient enterprise campus network with core, distribution and access layers?
Answer guide
I would use the hierarchical model. Access switches connect users and devices, distribution switches aggregate them and apply policy, and a core provides fast transport between blocks, and in smaller sites core and distribution can be collapsed. Every access switch uplinks to two distribution switches, with routed links or well designed layer two so no single failure isolates a closet. I use first hop redundancy or a stacking or multi-chassis approach, link aggregation, redundant power, and consistent VLAN design that keeps VLANs local to a closet. Routed access reduces spanning tree exposure. I plan capacity, oversubscription and failure domains explicitly, and document the design.
What this question explores
Whether you can design layered, redundant networks with controlled failure domains and justify the choices, not just draw boxes.
Common mistakes
Spanning a VLAN across the whole campus, which enlarges the failure and broadcast domain.
Providing redundant links but a single shared device or power source that remains a failure point.
Practise a follow-up
When would you collapse the core and distribution layers?
How do you decide on the oversubscription ratio at the access layer?
5. How would you build a business case to replace ageing network equipment, and how do you prioritise spending?
Answer guide
I would frame it in business risk and cost, not technology. I inventory equipment, its end of support dates, failure history and outage impact, and map each device to the services that depend on it, so the board sees what is exposed. I compare options, such as refresh now, phased replacement or managed service, with the total cost over several years including support, power, licensing and staff time. Priorities go to single points of failure and unsupported security-critical devices. I present phased funding with clear milestones and measurable results such as fewer incidents, then report back on them to keep trust.
What this question explores
Whether you can translate network risk into business terms and justify phased investment with measurable outcomes.
Common mistakes
Presenting the case in technical features rather than business risk and cost of downtime.
Asking for the whole budget upfront with no phasing, milestones or fallback options.
Practise a follow-up
How would you respond if the request is cut by half?
How do you decide between buying and managed network services?
6. What is Active Directory, and what problems does it solve in an organisation?
Answer guide
Active Directory is Microsoft's directory service for Windows networks. It stores objects such as users, computers, groups and policies in a central database and provides authentication, so people sign in once with one account instead of having separate accounts on every machine. It also provides authorisation, because permissions can be granted to groups, and central management through Group Policy. Domain controllers hold the directory and answer logon requests. For an administrator this means accounts can be created, disabled or changed in one place, security settings are applied consistently, and resources like file shares can be controlled by group membership.
What this question explores
Whether you understand Active Directory as a central identity and management system, not just a list of user accounts.
Common mistakes
Describing it as only a user database and ignoring authentication, groups and policy.
Thinking every computer keeps its own copy of all domain accounts.
7. What is ESXi, and how does a bare-metal hypervisor differ from one that runs on top of an operating system?
Answer guide
ESXi is VMware's bare-metal hypervisor, installed directly on the server hardware, so it has no general-purpose operating system underneath it. It schedules CPU, memory, storage and network access among virtual machines and keeps its own footprint small. A hosted hypervisor such as Workstation runs as an application on Windows or Linux, which adds a layer and shares resources with that host operating system. Because ESXi talks to hardware through its own drivers and kernel, it gives better performance, isolation and density, which is why it is used for production data centres while hosted products suit desktops and labs.
What this question explores
Whether you understand the basic architecture of a type 1 hypervisor and why it is preferred for production workloads.
Common mistakes
Describing ESXi as an application installed on top of Windows or Linux.
Saying virtualisation only means running many operating systems without mentioning resource scheduling or isolation.
8. What is the difference between TCP and UDP, and when would you choose each?
Answer guide
TCP is connection oriented. It sets up a session with a three-way handshake, numbers segments, acknowledges them, retransmits lost data and controls flow and congestion, so applications get a reliable ordered byte stream. UDP is connectionless and just sends datagrams with minimal overhead, no delivery guarantee and no ordering. I would choose TCP for web, email, file transfer and database traffic where correctness matters. I would choose UDP for DNS queries, voice, video streaming and some games where low latency matters more than a retransmitted packet, or where the application handles reliability itself.
What this question explores
Whether you understand the transport layer trade-off between reliability and low latency and can match protocols to real applications.
Common mistakes
Saying UDP is always faster and therefore better, ignoring that applications needing reliability would break.
Describing TCP only as slow, without mentioning ordering, acknowledgements and congestion control.
Practise a follow-up
What are the steps in the TCP three-way handshake?
Why does DNS usually use UDP but sometimes switch to TCP?
9. What is the difference between a public and a private IPv4 address?
Answer guide
A public IPv4 address is globally unique and routable on the internet, allocated through regional registries and providers. Private addresses come from ranges reserved for internal use, which are 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. They are not routed on the public internet, so many organisations can reuse the same ranges inside their own networks. To let private hosts reach the internet, a router or firewall performs network address translation to a public address. Private addressing also conserves scarce public IPv4 space and adds a basic layer of separation from direct inbound connections.
What this question explores
Whether you know the reserved private ranges and understand why NAT is needed to connect private networks to the internet.
Common mistakes
Believing private addresses are secure by themselves, without any firewall or access control in place.
Mixing up the private ranges, for example treating 172.32.x.x as private.
Practise a follow-up
What is the APIPA range and when does a host use it?
Can two companies use 10.0.0.0/8 internally and still connect by VPN?
10. What does a subnet mask do, and what does a /24 mean?
Answer guide
A subnet mask tells a device which part of an IPv4 address identifies the network and which part identifies the host. A /24 means the first 24 bits are the network portion, which is the same as 255.255.255.0. That leaves 8 host bits, so 256 addresses in the block, of which the first is the network address and the last is the broadcast address, leaving 254 usable hosts. A host compares a destination against its own network using the mask. If the destination is inside the subnet it sends directly, otherwise it sends the packet to its default gateway.
What this question explores
Whether you can apply CIDR notation correctly and explain how hosts use the mask to decide between local delivery and the gateway.
Common mistakes
Forgetting to subtract the network and broadcast addresses when counting usable hosts.
Treating the mask as a security feature rather than a way to separate network and host bits.
Practise a follow-up
How many usable hosts are in a /26 subnet?
What is the default gateway and what happens if it is misconfigured?
11. What is the difference between a switch and a router?
Answer guide
A switch works mainly at layer two. It learns source MAC addresses into a table and forwards frames only out of the port where the destination MAC was seen, which keeps traffic within one broadcast domain or VLAN. A router works at layer three. It forwards packets between different IP networks using a routing table and, by default, does not forward broadcasts, so it separates broadcast domains. Many modern devices combine both roles, such as a layer three switch that can route between VLANs. In a small office the router also commonly handles internet connectivity and NAT.
What this question explores
Whether you grasp the practical split between layer two forwarding within a network and layer three routing between networks.
Common mistakes
Saying a hub and a switch behave the same way, when a hub repeats frames to every port.
Thinking a router forwards broadcasts across networks by default.
Practise a follow-up
What happens when a switch receives a frame for an unknown destination MAC?
ARP, the Address Resolution Protocol, maps a known IPv4 address to a MAC address on the local network. When a host wants to send to an IP in its own subnet, it broadcasts an ARP request asking who owns that address, and the owner replies with its MAC address. The sender stores the result in an ARP cache for a limited time. For a destination outside the subnet, the host resolves the MAC of the default gateway instead. Without ARP, a device would know where to send a packet logically but not which physical frame address to use.
What this question explores
Whether you understand how layer three addresses are tied to layer two delivery on a local segment.
Common mistakes
Saying ARP resolves names to IP addresses, confusing it with DNS.
Forgetting that off-subnet traffic uses the gateway's MAC address, not the final destination's.
Practise a follow-up
What is ARP spoofing and how can it be mitigated?
How can you view and clear the ARP cache on a host?
Choose one answer containing an example or practical sequence. Explain what you would actually do, what you would check and when you would ask for help. Keep claims about your experience honest.
For technical or regulated work, check current documentation and applicable local requirements alongside this practice material.