Computer Networks Interview Questions for Freshers (2026) — with Answers
Updated August 2026
Networks is the core subject that rewards one well-prepared answer more than any other, because a single question — "what happens when you type a URL into a browser?" — walks through DNS, TCP, TLS, HTTP and routing in one go. Interviewers love it precisely because it is impossible to fake, and candidates who have rehearsed it once sound fluent across the whole subject.
The rest of the syllabus that actually gets asked is smaller than the textbook suggests: the layer models, TCP versus UDP and why the difference matters, the handshake, DNS resolution, HTTP semantics and status codes, addressing and the difference between a switch and a router. Almost everything else is depth you can add later.
Answer each of these in 30–60 seconds and finish with why the mechanism exists. Sockets and inter-process communication appear in our operating systems set from the OS side; this page takes the network side, and being able to move between the two is what separates a prepared candidate from a memorised one.
Frequently asked questions
What happens when you type a URL into a browser and press enter?
The browser checks its caches, then resolves the domain to an IP address via DNS — browser cache, OS cache, resolver, then root, TLD and authoritative servers as needed. It opens a TCP connection to that IP on the port (80 or 443), completing the three-way handshake, and for HTTPS performs a TLS handshake to agree keys and validate the certificate. It sends an HTTP request; the server responds with a status code and body; the browser parses the HTML, issues further requests for CSS, JavaScript and images, and renders. Rehearse this once end to end — it is the single highest-return answer in the whole subject, and interviewers use it to decide how deep to probe.
Explain the OSI model and how it maps to TCP/IP.
OSI has seven layers — physical, data link, network, transport, session, presentation, application. The TCP/IP model collapses these into four: link, internet, transport and application, with OSI's top three folded into the application layer. OSI is a teaching and troubleshooting reference; TCP/IP is what the internet actually runs. Name a protocol per layer rather than reciting the list: Ethernet at data link, IP at network, TCP and UDP at transport, HTTP and DNS at application.
TCP vs UDP — when would you choose each?
TCP is connection-oriented and reliable: it establishes a connection, numbers segments, acknowledges them, retransmits losses and delivers in order, with flow and congestion control. UDP is connectionless and unreliable — it sends datagrams with no handshake, no acknowledgement and no ordering, which makes it faster and lighter. Use TCP where correctness matters (web pages, file transfer, email) and UDP where timeliness beats completeness (live video and voice, gaming, DNS queries). The interview-winning line: a lost packet in a video call is better dropped than retransmitted late.
Explain the TCP three-way handshake, and how a connection closes.
The client sends SYN with an initial sequence number; the server replies SYN-ACK acknowledging it and sending its own; the client sends ACK. Three messages establish agreed sequence numbers in both directions, which is what makes ordered, reliable delivery possible. Closing takes four steps — FIN, ACK, FIN, ACK — because each direction is shut down independently, and the side that closes first waits in TIME_WAIT to absorb any delayed packets. The follow-up to expect: why is it three and not two, and the answer is that both sides must confirm each other's sequence numbers.
How does DNS resolution actually work?
DNS maps names to IP addresses through a hierarchy. The resolver checks caches first, then queries a root server, which points to the TLD server for .com, which points to the authoritative name server for the domain, which returns the record. Results are cached at each level according to their TTL, which is why a DNS change takes time to propagate. Know the common record types — A and AAAA for addresses, CNAME for aliases, MX for mail, TXT for verification — and that DNS queries usually travel over UDP for speed, falling back to TCP for large responses.
HTTP vs HTTPS — what does the S actually add?
HTTPS is HTTP carried over TLS. It adds encryption so an observer cannot read the traffic, integrity so it cannot be modified undetected, and authentication so you know the server is who it claims to be, verified through a certificate signed by a trusted certificate authority. It does not make the server secure or the application safe — it protects the channel, not what sits at either end, and saying that distinction out loud marks you as someone who understands it rather than repeating it.
What happens in a TLS handshake, roughly?
The client and server agree on a protocol version and cipher suite, the server presents its certificate, the client validates it against trusted certificate authorities and checks the domain and expiry, and the two derive a shared symmetric key — in modern TLS via an ephemeral key exchange that provides forward secrecy. The rest of the session uses that symmetric key because symmetric encryption is far faster. The essential point: asymmetric cryptography establishes trust and a key; symmetric cryptography does the bulk work.
Explain the common HTTP status codes.
The first digit gives the class: 2xx success, 3xx redirection, 4xx client error, 5xx server error. Know the specific ones — 200 OK, 201 Created, 301 permanent redirect versus 302 temporary, 304 Not Modified for caching, 400 Bad Request, 401 unauthenticated versus 403 authenticated-but-not-allowed, 404 Not Found, 429 Too Many Requests, 500 Internal Server Error, 502 Bad Gateway and 503 Service Unavailable. The 401-versus-403 distinction and 301-versus-302 are the two most commonly asked, because they test understanding rather than recall.
GET vs POST, and what does idempotent mean?
GET retrieves data, carries parameters in the URL, and can be cached, bookmarked and re-sent safely. POST submits data in the request body, is not cached, and may change server state. Idempotent means making the same request repeatedly has the same effect as making it once — GET, PUT and DELETE are idempotent, POST generally is not, which is exactly why browsers warn before re-submitting a form. Never put sensitive data in a GET query string, since URLs land in logs and browser history.
What is an IP address, and what do public, private and subnet mask mean?
An IP address identifies a host on a network; IPv4 uses 32 bits written as four octets, IPv6 uses 128 bits to solve exhaustion. Private ranges — 10.x, 172.16–31.x and 192.168.x — are reserved for internal networks and are not routable on the public internet, which is why your home devices share one public address through NAT. The subnet mask splits the address into a network part and a host part, so 192.168.1.0/24 means the first 24 bits identify the network, leaving 254 usable host addresses.
What do ARP, DHCP and NAT each do?
ARP resolves an IP address to a MAC address on the local network, because the actual frame delivery happens at layer two. DHCP hands a joining device its IP address, subnet mask, gateway and DNS servers automatically instead of you configuring them. NAT translates many private addresses to one public address at the router, tracking connections by port so replies return to the right device — the mechanism that let IPv4 survive far longer than it should have. Expect these three together, as they are the joining-a-network story.
MAC address vs IP address?
A MAC address is a hardware identifier burned into the network interface and used for delivery within a local network segment; an IP address is a logical, assignable address used for routing across networks. The clean framing: IP gets the packet across the internet to the right network, MAC gets the frame to the right machine on that network. This is why the destination MAC changes at every hop while the destination IP does not.
Switch vs router vs hub?
A hub is a dumb repeater — it copies incoming signals to every port and is effectively obsolete. A switch operates at layer two, learns which MAC address sits on which port, and forwards frames only where they need to go. A router operates at layer three, connects different networks and forwards packets between them using a routing table. One line to finish on: switches build a network, routers connect networks.
What is a port, and what is a socket?
A port is a 16-bit number identifying a specific service on a host, so one machine can run many services — 80 for HTTP, 443 for HTTPS, 22 for SSH, 53 for DNS. A socket is the endpoint of a connection, identified by the combination of IP address and port on each side; the four-tuple of source IP, source port, destination IP and destination port uniquely identifies a TCP connection. That is how a server holds thousands of simultaneous connections on a single port.
How do flow control and congestion control differ?
Flow control stops a fast sender overwhelming a slow receiver, and it is handled by the receiver advertising a window size. Congestion control stops senders overwhelming the network itself, and it is inferred by the sender from packet loss and delay — slow start ramps the sending rate exponentially until loss appears, then congestion avoidance grows it cautiously. The distinction is the point: one protects the endpoint, the other protects the path between endpoints.
What is the difference between latency, bandwidth and throughput?
Latency is delay — how long one packet takes to arrive, measured as round-trip time. Bandwidth is capacity, the maximum data rate a link can carry. Throughput is what you actually achieve, which is bandwidth minus the effects of latency, loss, protocol overhead and congestion. The analogy that lands: bandwidth is how many lanes the road has, latency is how long the journey takes, and adding lanes does not make the trip shorter.
What is a firewall, and what does a load balancer do?
A firewall filters traffic against rules based on addresses, ports and protocols, and a stateful one tracks connections so it can allow replies to traffic you initiated. A load balancer distributes incoming requests across multiple servers to spread load and remove single points of failure, using strategies such as round robin, least connections or hashing, and it typically health-checks backends so traffic stops going to a failed one. Both sit in front of applications, but one is about who may connect and the other about which server answers.
What is a CDN and why does it help?
A content delivery network caches static content on servers distributed geographically, so a user is served from a nearby location instead of the origin server. That cuts latency, which is bounded by physical distance and cannot be fixed with more bandwidth, and it reduces load on the origin. It also absorbs traffic spikes. This question usually follows a latency-versus-bandwidth answer, so prepare them as a pair.
How do cookies and sessions maintain state over a stateless protocol?
HTTP is stateless — each request is independent and the server remembers nothing by itself. A cookie is a small piece of data the server sets in the browser, which the browser returns on subsequent requests to the same domain; a session is server-side state keyed by an identifier usually carried in that cookie. Mention the security flags to sound like someone who has built this: HttpOnly stops JavaScript reading the cookie, Secure restricts it to HTTPS, and SameSite limits cross-site sending.
Is computer networks still asked in 2027-batch placement interviews?
Yes — networks sits alongside OS and DBMS as a consistently asked core subject, and it comes up even in web-development interviews because every application is a networked application. Panels rarely go deep with freshers, but they reliably ask the URL walkthrough, TCP versus UDP, HTTP status codes and DNS. Prepare those four properly and you cover most of what a fresher panel has time for.
Don't just read Computer networks questions — get asked them
Phiny's AI interviews you on exactly these topics, follows up on weak answers, and tells you what a stronger answer looks like. Text interviews are free and unlimited.
Start a free AI mock interviewHow to prepare
- Rehearse the URL walkthrough out loud until it flows in about ninety seconds. It is the highest-return answer in the subject, it demonstrates the whole stack at once, and interviewers frequently use your version of it to decide how hard to probe afterwards.
- Draw the layers and the handshake while you speak. A three-arrow SYN, SYN-ACK, ACK sketch on the rough sheet turns a hesitant answer into a confident one, and it gives the interviewer something to ask a follow-up about on your terms.
- Connect networks to your own project. If you built anything with an API, a database connection or a deployment, you have real material — why your requests were slow, what a 502 meant, why HTTPS mattered — and panels much prefer that to textbook recall.
- Prepare the chains, not isolated facts: URL walkthrough → DNS → TCP handshake → TLS → HTTP status codes, and latency → bandwidth → CDN. Interviewers walk down these, and candidates who prepared each answer separately fall off halfway.
- Pair this with our operating systems set. Sockets, ports and IPC sit on the boundary between the two subjects, and being able to move between the OS view and the network view of the same connection is exactly what makes a fresher sound prepared rather than rehearsed.
Where these questions get asked
- TCS NQT guide and Infosys hiring guide — the two biggest exams these questions appear in.
- All company placement guides — pattern, syllabus and rounds for every mass recruiter.