This lesson is the revision companion for the whole Computer Networks track. It collects the questions most commonly asked in campus placements and fresher interviews at product and service companies, grouped by layer and topic, each with a crisp model answer you can say aloud in under a minute. After the questions come eight numerical problems of the kind that appear in written tests and technical rounds (subnetting, delays, CRC, sliding windows, utilisation), solved step by step with every number checked. The lesson ends with a revision checklist.
How to use it: first try to answer each question yourself, out loud, before reading the model answer. If an answer feels unfamiliar, follow the link to the lesson that covers it in depth. Interviewers rarely stop at the first answer; they ask "why?" and "what happens if...?". The model answers are written to anticipate the first follow-up.
How to answer networking questions
Use a three-part shape: definition (one sentence), how it works (two or three steps), why it matters or a trade-off (one sentence). For example: "TCP is a reliable, connection-oriented transport. It numbers bytes, acknowledges them and retransmits losses, after a three-way handshake. That reliability costs latency, which is why real-time apps often prefer UDP."
Fundamentals and network models
Deep dives: networking basics and OSI and TCP/IP models.
Q1. What is a computer network, and what are LAN, MAN and WAN?
A computer network is a set of devices connected so they can exchange data using agreed protocols. A LAN (local area network) covers a building or campus, a MAN (metropolitan area network) a city, and a WAN (wide area network) countries or continents; the Internet is a network of networks. They differ in scale, ownership, speed and typical technology (Ethernet and Wi-Fi for LANs, leased lines and MPLS or the Internet for WANs).
Q2. Name the seven OSI layers and what each does.
From bottom to top: Physical (bits on a medium), Data Link (frames between neighbours, MAC addresses), Network (routing packets between networks, IP), Transport (end-to-end delivery between processes, TCP/UDP), Session (managing dialogues), Presentation (formats, encoding, encryption) and Application (protocols users' programs speak, such as HTTP). A mnemonic is "Please Do Not Throw Sausage Pizza Away".
Q3. How does the TCP/IP model map to OSI?
The TCP/IP model has four layers: Link (OSI 1 and 2), Internet (OSI 3), Transport (OSI 4) and Application (OSI 5 to 7). Some textbooks split Link into Physical and Data Link, giving five. TCP/IP is the model the Internet actually implements; OSI is the reference vocabulary ("an L7 load balancer").
Q4. What is encapsulation?
As data moves down the stack, each layer wraps it with its own header: application data becomes a TCP segment, then an IP packet, then an Ethernet frame. The receiver strips headers on the way up. The data unit names are message, segment (or datagram for UDP), packet and frame.
Q5. Which devices work at which layer?
Hubs and repeaters at layer 1 (they repeat bits to all ports), switches and bridges at layer 2 (forward frames by MAC address), routers at layer 3 (forward packets by IP address), and load balancers, proxies and firewalls at layers 4 to 7 depending on what they inspect. A "layer 3 switch" is a switch that can also route.
Q6. What is the difference between circuit switching and packet switching?
Circuit switching reserves a dedicated path and bandwidth for the whole conversation, like the old telephone network, giving guaranteed quality but wasting capacity when idle. Packet switching splits data into packets that share links and are forwarded independently, which uses links efficiently but introduces variable delay and possible loss. The Internet is packet switched.
Q7. What are bandwidth, throughput and latency?
Bandwidth is the maximum data rate a link supports. Throughput is the rate actually achieved, limited by the bottleneck link, congestion and protocol behaviour. Latency is the time for data to get from sender to receiver, made up of transmission, propagation, queuing and processing delays.
Q8. What are unicast, multicast, broadcast and anycast?
Unicast sends to one receiver, broadcast to all hosts on the local network, multicast to a subscribed group, and anycast to the nearest of several hosts sharing the same address. Anycast is how root DNS servers and CDNs route users to a nearby server.
Data link layer
Deep dive: data link layer.
Q9. What is a MAC address?
A 48-bit hardware address identifying a network interface on a local link, written as six hex pairs such as 3c:84:6a:12:34:56. The first 24 bits traditionally identify the manufacturer (OUI). Unlike an IP address, it is used only within one local network and is rewritten hop by hop.
Q10. How does ARP work?
When a host needs the MAC address for an IP on its local network, it broadcasts "who has this IP?" and the owner replies with its MAC by unicast. The result is cached in the ARP table for a few minutes. For destinations outside the subnet, the host ARPs for its default gateway, never for the remote host.
Q11. How does a switch learn where to send frames?
It records the source MAC address of each incoming frame against the port it arrived on, building a MAC address table. Frames to a known MAC go out only on that port; frames to an unknown MAC, and broadcasts, are flooded to all other ports in the VLAN.
Q12. What are collision domains and broadcast domains?
A collision domain is a segment where simultaneous transmissions collide; every switch port is its own collision domain, while a hub shares one among all ports. A broadcast domain is the set of devices that receive each other's broadcasts; switches forward broadcasts, routers and VLAN boundaries stop them.
Q13. What is a VLAN?
A virtual LAN splits one physical switch network into separate logical broadcast domains, using a 12-bit 802.1Q tag on trunk links. It provides isolation and smaller broadcast domains without extra hardware. Traffic between VLANs must be routed.
Q14. Explain CSMA/CD and CSMA/CA.
CSMA/CD (carrier sense multiple access with collision detection), used in classic half-duplex Ethernet, listens before sending, detects collisions while sending, and retries after a random exponential backoff. CSMA/CA (collision avoidance), used in Wi-Fi, cannot detect collisions reliably over radio, so it waits random backoff times, relies on acknowledgements and optionally uses RTS/CTS. Modern full-duplex switched Ethernet has no collisions at all.
Q15. Why does Spanning Tree Protocol exist?
Redundant links between switches create loops, and since Ethernet frames have no TTL, broadcasts would circulate forever (a broadcast storm). STP elects a root bridge and blocks redundant ports to form a loop-free tree, re-enabling them if an active link fails. RSTP is its faster-converging successor.
IP addressing and subnetting
Deep dive: IP addressing and subnetting.
Q16. What is the difference between IPv4 and IPv6?
IPv4 uses 32-bit addresses (about 4.3 billion), which have run out, so NAT is widespread. IPv6 uses 128-bit addresses, a simpler fixed-size header, no fragmentation by routers, built-in autoconfiguration (SLAAC), and replaces ARP with Neighbor Discovery. The two are not directly compatible, so networks run both (dual stack) or translate.
Q17. What is a subnet mask and CIDR notation?
A subnet mask marks which bits of an address are the network part; /24 (255.255.255.0) means the first 24 bits. CIDR (classless inter-domain routing) allows any prefix length rather than fixed classes, so address blocks fit actual needs and routes can be aggregated. A /24 has 256 addresses and 254 usable hosts.
Q18. Why do we subtract 2 when counting usable hosts?
The all-zeros host address identifies the network itself and the all-ones host address is the directed broadcast, so neither can be assigned to a host. A /30 therefore has 2 usable hosts, a common choice for point-to-point links (a /31 is also allowed for point-to-point links by RFC 3021).
Q19. What are private IP ranges?
10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16 (RFC 1918). They are not routed on the public Internet and are reused inside many organisations, reaching the Internet through NAT. 100.64.0.0/10 is reserved for carrier-grade NAT, and 169.254.0.0/16 for link-local auto-configuration.
Q20. What is NAT and what are its downsides?
Network address translation rewrites private source addresses (and usually ports, called PAT) to a public address so many devices share one IP, keeping a table to map replies back. It conserves IPv4 addresses, but breaks end-to-end connectivity: unsolicited inbound connections fail without port forwarding, peer-to-peer needs STUN/TURN, and logs lose the original client address.
Q21. What is the purpose of the IP TTL field?
Time to live is decremented by every router; when it reaches zero, the packet is dropped and an ICMP "time exceeded" message is sent back. It prevents packets looping forever when routing is broken, and traceroute exploits it to discover each hop.
Q22. What is ICMP?
The Internet Control Message Protocol carries error and diagnostic messages for IP: destination unreachable, time exceeded, fragmentation needed, echo request and reply. Ping and traceroute use it. Blocking all ICMP can break Path MTU discovery.
Q23. What is MTU and fragmentation?
MTU (maximum transmission unit) is the largest packet a link can carry, 1500 bytes for standard Ethernet. IPv4 routers may fragment larger packets, which hurts performance and reliability; IPv6 routers never fragment. Path MTU discovery sends packets with "don't fragment" set and lowers the size when ICMP "too big" messages come back.
Q24. What is the difference between a public and a private IP, and a static and a dynamic IP?
Public addresses are globally unique and routable on the Internet; private ones are reused internally behind NAT. Static addresses are assigned permanently (servers, printers); dynamic ones are leased by DHCP and may change.
Routing
Deep dive: routing.
Q25. How does a router decide where to send a packet?
It looks up the destination address in its routing table and chooses the entry with the longest matching prefix, then forwards the packet to that entry's next hop and interface. If nothing matches, it uses the default route, or drops the packet and sends ICMP unreachable.
Q26. What is longest prefix match? Give an example.
When several routes contain the destination, the most specific one wins. For destination 10.1.2.3 with routes 10.0.0.0/8 and 10.1.2.0/24, the /24 is chosen because it matches 24 bits instead of 8.
Q27. Distance vector versus link state routing?
In distance vector routing (RIP), each router shares its distance table with neighbours and uses Bellman-Ford; it is simple but converges slowly and suffers count-to-infinity. In link state routing (OSPF, IS-IS), each router floods its link information to all routers, builds the full topology and runs Dijkstra; it converges faster but uses more memory and CPU.
Q28. What is the count-to-infinity problem?
In distance vector routing, after a link fails, routers can keep advertising stale routes to each other, increasing the metric step by step until it reaches "infinity" (16 in RIP). Mitigations include split horizon, poison reverse and hold-down timers.
Q29. What is BGP?
The Border Gateway Protocol routes between autonomous systems (independently run networks such as ISPs and cloud providers). It is a path-vector protocol: routes carry the list of ASes they pass through, which prevents loops and allows policy-based choices. It runs over TCP port 179.
Q30. Static versus dynamic routing?
Static routes are configured by hand: simple, predictable and with no protocol overhead, but they do not adapt to failures. Dynamic routing protocols discover routes and react to topology changes automatically, which is essential in larger networks.
Transport layer: TCP and UDP
Deep dive: transport layer: TCP and UDP.
Q31. TCP versus UDP?
TCP is connection-oriented and reliable: handshake, ordered delivery, acknowledgements, retransmission, flow and congestion control, with a 20 to 60 byte header. UDP is connectionless with an 8-byte header and no delivery guarantees, so it has lower latency and overhead. TCP suits web, email and file transfer; UDP suits DNS queries, streaming, gaming, VoIP and QUIC.
Q32. Explain the TCP three-way handshake.
The client sends SYN with its initial sequence number; the server responds SYN-ACK with its own sequence number and an acknowledgement of the client's; the client sends ACK. Three messages are needed so both sides confirm the other can send and receive, and agree on both initial sequence numbers.
Q33. Why not a two-way handshake?
With two messages, the server could not confirm the client received its sequence number, and delayed duplicate SYNs from old connections could open spurious connections on the server. The third message confirms both directions.
Q34. How is a TCP connection closed?
Each direction closes separately: one side sends FIN, the other ACKs it, later sends its own FIN, and the first side ACKs that, often four segments (the middle two can be combined). The side that closed first enters TIME_WAIT.
Q35. What is TIME_WAIT and why does it exist?
After actively closing, a socket waits for twice the maximum segment lifetime (often 60 seconds on Linux) before the 4-tuple can be reused. It ensures the final ACK can be retransmitted if lost and that delayed segments from the old connection are not mistaken for a new one.
Q36. How does TCP guarantee reliable, ordered delivery?
It numbers every byte with sequence numbers, the receiver sends cumulative acknowledgements, and the sender retransmits on timeout or after three duplicate ACKs (fast retransmit). The receiver reorders out-of-order segments and discards duplicates, and a checksum detects corruption.
Q37. What is a port and a socket?
A port is a 16-bit number identifying a process or service on a host. A socket is an endpoint the OS gives an application; a TCP connection is uniquely identified by the 4-tuple of source IP, source port, destination IP and destination port.
Q38. What is a SYN flood and how do SYN cookies help?
Attackers send many SYNs without completing handshakes, filling the server's half-open connection queue. SYN cookies let the server store nothing and encode the connection state in its initial sequence number, rebuilding the connection when a valid ACK arrives. See TLS and network security.
Q39. Why do DNS and video calls use UDP?
DNS queries are single small request-response exchanges, so a handshake would double latency, and retrying is cheap. Real-time media prefers a late packet dropped over a delayed stream, and applications add only the reliability they need. QUIC builds reliability on UDP in user space.
Q40. What is head-of-line blocking in TCP?
Because TCP delivers bytes strictly in order, one lost segment holds back all data after it until retransmitted, even if that later data belongs to unrelated requests multiplexed on the connection. HTTP/3 over QUIC avoids it with independent streams.
Flow and congestion control
Deep dive: TCP flow and congestion control.
Q41. What is the difference between flow control and congestion control?
Flow control protects the receiver: the receiver advertises a window (rwnd) of how much buffer it has free. Congestion control protects the network: the sender keeps a congestion window (cwnd) based on observed loss or delay. The sender may have in flight at most the minimum of the two.
Q42. Explain slow start and congestion avoidance.
In slow start, cwnd starts small (commonly 10 segments) and grows by one segment per ACK, roughly doubling each RTT, until it reaches the slow-start threshold. Then congestion avoidance grows it by about one segment per RTT (additive increase). On loss, cwnd and the threshold are reduced (multiplicative decrease).
Q43. What happens on a timeout versus three duplicate ACKs?
Three duplicate ACKs suggest a single lost segment while later ones still arrive, so TCP Reno fast-retransmits and halves cwnd (fast recovery). A timeout suggests severe congestion, so cwnd drops to its initial small value and slow start begins again.
Q44. What is AIMD and why is it used?
Additive increase, multiplicative decrease: grow the window slowly and cut it sharply on loss. It converges towards a fair and efficient share of the bottleneck among competing flows while backing off quickly when the network is overloaded.
Q45. What is the bandwidth-delay product?
Bandwidth multiplied by round-trip time: the amount of data that must be in flight to keep the link fully used. If the window is smaller, throughput is limited to window divided by RTT. Large BDP links need TCP window scaling.
Q46. What is Nagle's algorithm, and when do you disable it?
Nagle's algorithm buffers small writes while previous data is unacknowledged, reducing tiny packets. Combined with delayed ACKs it can add latency to interactive request-response traffic, so latency-sensitive applications set TCP_NODELAY.
DNS
Deep dive: DNS.
Q47. Walk through DNS resolution of www.example.com.
The browser and OS check their caches. The stub resolver sends a recursive query to the configured resolver, which, on a cache miss, iteratively asks a root server (referral to .com), a .com TLD server (referral to example.com's name servers) and the authoritative server, which returns the record with a TTL. The resolver caches everything and answers the client.
Q48. Recursive versus iterative query?
A recursive query asks the server to return the final answer, doing all the work; clients send these to resolvers. An iterative query accepts the best the server knows, often a referral; resolvers send these to root, TLD and authoritative servers.
Q49. What do A, AAAA, CNAME, MX, NS, TXT and PTR records hold?
A and AAAA map a name to IPv4 and IPv6 addresses; CNAME aliases one name to another; MX names the mail servers with priorities; NS lists a zone's authoritative servers; TXT holds text such as SPF and verification tokens; PTR maps an address back to a name for reverse DNS.
Q50. What is TTL in DNS, and why do changes take time?
TTL is how many seconds a record may be cached. Changes appear only as cached copies expire at resolvers worldwide, so lower the TTL well before a planned change. Negative answers (NXDOMAIN) are cached too.
Q51. Does DNS use TCP or UDP?
Port 53 on both. UDP for normal queries; TCP for responses too large for UDP (truncated replies), zone transfers and DNS over TLS.
Q52. What is DNS cache poisoning, and what does DNSSEC do?
An attacker races forged answers into a resolver's cache, redirecting users. Randomised ports and IDs make it harder; DNSSEC signs records so resolvers can verify them through a chain of trust from the root. DNSSEC provides authenticity, not privacy; DoH and DoT provide privacy.
HTTP and the web
Deep dive: HTTP and the web.
Q53. Which HTTP methods are safe and which are idempotent?
GET, HEAD and OPTIONS are safe (no state change) and idempotent. PUT and DELETE are idempotent but not safe. POST is neither, and PATCH is not guaranteed to be idempotent.
Q54. Explain the status code classes, and 401 versus 403.
1xx informational, 2xx success, 3xx redirection, 4xx client error, 5xx server error. 401 means not authenticated (send credentials); 403 means authenticated but not allowed.
Q55. What is the difference between 502, 503 and 504?
502 Bad Gateway: a proxy got an invalid response from the upstream server. 503 Service Unavailable: the server is overloaded or in maintenance. 504 Gateway Timeout: the proxy gave up waiting for the upstream server.
Q56. How does HTTP caching work with ETag?
The server sends Cache-Control for freshness and an ETag identifying the version. When the cached copy is stale, the browser sends If-None-Match with the ETag; the server replies 304 Not Modified with no body if unchanged, or 200 with the new content.
Q57. What is the difference between cookies, sessions and tokens?
A cookie is a browser storage and transport mechanism for small values. A session is server-side state referenced by an id, usually stored in a cookie, and is easy to revoke. A token such as a JWT is a signed, self-contained credential verified without a lookup, but hard to revoke before expiry.
Q58. HTTP/1.1 versus HTTP/2 versus HTTP/3?
HTTP/1.1 is text-based with one outstanding request per connection, so browsers open several connections. HTTP/2 uses binary frames, multiplexes many streams on one TCP connection and compresses headers with HPACK. HTTP/3 runs over QUIC on UDP, removing TCP head-of-line blocking, cutting handshake round trips and supporting connection migration.
Q59. What is CORS?
Cross-Origin Resource Sharing lets a server tell browsers which other origins may read its responses, via Access-Control-Allow-* headers, relaxing the same-origin policy. Non-simple requests trigger a preflight OPTIONS request. It is enforced only by browsers.
Q60. WebSockets versus SSE versus long polling?
Long polling holds a request open until data arrives, then reconnects. SSE streams text events from server to client over one long HTTP response with automatic reconnection. WebSockets upgrade a connection to full-duplex messaging, best for frequent two-way traffic like chat.
Security and TLS
Deep dive: TLS and network security.
Q61. Symmetric versus asymmetric encryption?
Symmetric encryption uses one shared key and is fast (AES, ChaCha20), but the key must be shared securely. Asymmetric encryption uses a public/private pair (RSA, ECC), enabling key exchange and signatures but slowly. TLS uses asymmetric cryptography to authenticate and agree keys, then symmetric encryption for data.
Q62. What happens in a TLS 1.3 handshake?
The client sends ClientHello with cipher suites and a Diffie-Hellman key share. The server answers with its key share, then (encrypted) its certificate, a signature over the handshake and Finished. The client verifies the certificate chain and signature and sends Finished; data flows after one round trip.
Q63. How does the browser trust a certificate?
It verifies the chain of signatures from the server's certificate through intermediates to a root CA in its trust store, checks the host name against the Subject Alternative Names, the validity dates and revocation status. Any failure shows a warning.
Q64. What is forward secrecy?
Using ephemeral Diffie-Hellman keys per session so that stealing the server's long-term private key later cannot decrypt recorded past sessions. TLS 1.3 makes it mandatory.
Q65. Hashing versus encryption versus MAC versus signature?
Hashing creates a keyless one-way fingerprint. Encryption is reversible with a key and gives confidentiality. A MAC is a keyed hash with a shared secret, giving integrity and authentication. A signature uses a private key to sign and a public key to verify, adding non-repudiation.
Q66. What is a man-in-the-middle attack, and what is ARP spoofing?
In a MITM attack, an attacker secretly relays and may alter traffic between two parties. ARP spoofing is one way in on a LAN: the attacker sends forged ARP replies so victims map the gateway's IP to the attacker's MAC. TLS with proper certificate validation makes the intercepted traffic useless.
Q67. Stateless versus stateful firewall, and IDS versus IPS?
A stateless firewall filters each packet by header fields alone; a stateful firewall tracks connections and admits return traffic for established ones. An IDS detects and alerts; an IPS sits inline and blocks.
Q68. IPsec versus TLS VPN?
IPsec protects IP packets at the network layer using IKE and ESP, typical for site-to-site tunnels. TLS VPNs run over TLS on port 443, traverse firewalls easily and suit remote access.
Application protocols, the full flow and tools
Deep dives: what happens when you type a URL, application protocols and modern networking and tools.
Q69. What happens when you type a URL into a browser?
The browser parses the URL, applies HSTS, checks caches, and resolves the host via DNS. It sends packets through the default gateway (found with ARP), opens TCP and TLS connections and sends the HTTP request, which passes through a CDN, load balancer and reverse proxy to the application. The browser then builds the DOM and CSSOM, lays out, paints and composites the page and fetches sub-resources over the same connection.
Q70. Explain DHCP.
DORA over UDP 67/68: the client broadcasts Discover, servers Offer an address and options (mask, gateway, DNS), the client broadcasts a Request for one offer, and the server confirms with an ACK. Addresses are leased and renewed at 50 percent of the lease time.
Q71. SMTP versus IMAP versus POP3?
SMTP sends and relays mail (587 for submission, 25 between servers). IMAP (143/993) keeps mail on the server and syncs state across devices; POP3 (110/995) downloads mail to one client.
Q72. FTP versus SFTP?
FTP uses separate control (21) and data connections and sends credentials in plain text. SFTP is a different protocol that runs inside SSH on port 22, encrypting everything over a single connection.
Q73. What are the well-known ports for SSH, DNS, HTTP, HTTPS, SMTP and DHCP?
SSH 22, DNS 53 (UDP and TCP), HTTP 80, HTTPS 443 (TCP, and UDP for HTTP/3), SMTP 25 and 587, DHCP 67 for servers and 68 for clients.
Q74. L4 versus L7 load balancer, and forward versus reverse proxy?
An L4 load balancer routes connections by IP and port; an L7 one routes individual HTTP requests by content. A forward proxy acts on behalf of clients going out; a reverse proxy acts on behalf of servers receiving requests.
Q75. How do you check whether a remote port is open, and which local process owns a port?
Use nc -vz host port or curl -v to the port: a connection means open, "refused" means reachable but closed, a timeout suggests a firewall. Locally, ss -tlnp or lsof -i :port shows the listening process.
Q76. A user says the website is slow. How do you debug it?
Scope it (who, what, since when, what changed), then split the request with curl -w into DNS, connect, TLS, time to first byte and download. A large connect time points to distance or routing (check dig and mtr), loss that persists to the last hop points to the network, and a large TTFB points to the server (logs, database, dependencies). Fix, re-measure and add monitoring.
Numerical problems
These are the problem types that appear most often in written rounds. Every answer below has been computed and checked.
Problem 1: dividing a network into subnets
Question. Divide 192.168.10.0/24 into at least 6 equal subnets. Give the new prefix, the number of usable hosts per subnet, and the range of each subnet.
Solution.
- We need at least 6 subnets. Borrowing
nbits from the host part gives2^nsubnets.2^2 = 4is too few;2^3 = 8is enough. Borrow 3 bits. - New prefix:
24 + 3 = /27. Mask:255.255.255.224(the last octet is11100000= 224). - Host bits left:
32 − 27 = 5, so each subnet has2^5 = 32addresses and32 − 2 = 30usable hosts. - The block size is 32, so subnets start at multiples of 32 in the last octet.
| Subnet | Network | First host | Last host | Broadcast |
|---|---|---|---|---|
| 1 | 192.168.10.0/27 | .1 | .30 | .31 |
| 2 | 192.168.10.32/27 | .33 | .62 | .63 |
| 3 | 192.168.10.64/27 | .65 | .94 | .95 |
| 4 | 192.168.10.96/27 | .97 | .126 | .127 |
| 5 | 192.168.10.128/27 | .129 | .158 | .159 |
| 6 | 192.168.10.160/27 | .161 | .190 | .191 |
| 7 | 192.168.10.192/27 | .193 | .222 | .223 |
| 8 | 192.168.10.224/27 | .225 | .254 | .255 |
Answer: /27 (255.255.255.224), 8 subnets of 30 usable hosts each.
Problem 2: network, broadcast and host count from an address
Question. A host has address 172.16.45.200/20. Find the network address, broadcast address and number of usable hosts.
Solution.
- A /20 mask is
255.255.240.0. The "interesting" octet is the third, where the mask is 240, so the block size is256 − 240 = 16. - Third octet of the address: 45. Multiples of 16: 0, 16, 32, 48. 45 falls in the block starting at 32 (32 to 47).
- Network address:
172.16.32.0. Broadcast: the last address of the block,172.16.47.255. - Host bits:
32 − 20 = 12, so2^12 − 2 = 4096 − 2 = 4094usable hosts.
Check in binary: 45 is 00101101; masking with 240 (11110000) gives 00100000 = 32.
Answer: network 172.16.32.0, broadcast 172.16.47.255, 4094 usable hosts (172.16.32.1 to 172.16.47.254).
Problem 3: transmission and propagation delay
Question. A 1500-byte packet is sent over a 10 Mbps link that is 2000 km long. Signals travel at 2 × 10^8 m/s. Find the transmission delay, propagation delay and total time until the last bit arrives (ignore queuing and processing). Then find the total if the same distance is split into two 1000 km links joined by one store-and-forward router.
Solution.
- Transmission delay (time to push all bits onto the link) = packet size / bandwidth =
1500 × 8 bits / (10 × 10^6 bits/s) = 12000 / 10^7 = 0.0012 s =1.2 ms. - Propagation delay (time for a bit to travel the distance) = distance / speed =
2 × 10^6 m / (2 × 10^8 m/s) = 0.01 s =10 ms. - Total for one link = 1.2 + 10 = 11.2 ms.
- Two links with a router: a store-and-forward router must receive the entire packet before forwarding it, so the packet is transmitted twice. Propagation: each link takes 5 ms, total 10 ms. Total =
2 × 1.2 + 2 × 5 =12.4 ms.
Answer: 1.2 ms transmission, 10 ms propagation, 11.2 ms total; 12.4 ms with one router in the middle.
Problem 4: stop-and-wait utilisation
Question. A stop-and-wait protocol sends 1000-byte frames on a 1 Mbps link with a one-way propagation delay of 20 ms. Ignoring ACK transmission time and processing, what is the link utilisation?
Solution.
- Transmission time
Tt = 1000 × 8 / 10^6 = 8000 / 10^6 = 0.008 s =8 ms. - Propagation delay
Tp = 20 ms. Definea = Tp / Tt = 20 / 8 = 2.5. - In stop-and-wait, the sender transmits one frame (Tt) and then waits for it to arrive and for the ACK to return (2 Tp) before sending the next. One cycle =
Tt + 2Tp = 8 + 40 = 48 ms. - Utilisation = useful time / cycle time =
Tt / (Tt + 2Tp) = 1 / (1 + 2a) = 8 / 48 = 1/6 ≈16.67 percent. - Effective throughput =
0.1667 × 1 Mbps ≈ 167 kbps.
Answer: about 16.67 percent utilisation.
Problem 5: sliding window size and sequence number bits
Question. For the link in Problem 4, what sender window size gives 100 percent utilisation? How many sequence number bits are needed with Go-Back-N and with Selective Repeat?
Solution.
- During one cycle (
Tt + 2Tp = 48 ms), the link could transmit48 / 8 = 6frames. The sender must be allowed to have 6 frames outstanding: windowW = 1 + 2a = 1 + 5 = 6. - Go-Back-N: with
nsequence bits, the maximum window is2^n − 1. We need2^n − 1 ≥ 6, so2^n ≥ 7, giving n = 3 (window up to 7). - Selective Repeat: the maximum window is
2^(n−1)(half the sequence space, so new and old frames cannot be confused). We need2^(n−1) ≥ 6, son − 1 = 3, giving n = 4 (window up to 8).
Answer: window 6; 3 bits for Go-Back-N, 4 bits for Selective Repeat.
Problem 6: CRC calculation
Question. The data bits are 1101011011 and the generator polynomial is x^4 + x + 1. Find the CRC and the transmitted frame.
Solution.
- The generator
x^4 + x + 1in binary is10011(coefficients ofx^4, x^3, x^2, x^1, x^0are 1, 0, 0, 1, 1). Its degree is 4, so append 4 zeros to the data:11010110110000. - Divide by
10011using modulo-2 (XOR) division, without carries:
11010110110000
10011 XOR at bit 1
-----
01001110110000
10011 XOR at bit 2
-----
00000010110000 bits 3-6 are 0, skip to bit 7
10011 XOR at bit 7
-----
00000000101000 bit 8 is 0, skip
10011 XOR at bit 9
-----
00000000001110 remainder = last 4 bits: 1110
- The remainder is 1110. Replace the appended zeros with it: transmitted frame =
1101011011+1110=11010110111110. - Check: dividing
11010110111110by10011at the receiver gives remainder0000, so the frame is accepted. Any single-bit error would leave a non-zero remainder.
Answer: CRC = 1110; transmitted frame = 11010110111110.
Problem 7: TCP throughput limited by window
Question. A TCP connection has a maximum window of 65,535 bytes (no window scaling) and an RTT of 100 ms. What is the maximum throughput? What window would be needed to fill a 100 Mbps link with the same RTT?
Solution.
- TCP can send at most one window per round trip. Maximum throughput = window / RTT =
65535 × 8 bits / 0.1 s = 524280 / 0.1 = 5,242,800 bits/s ≈5.24 Mbps, no matter how fast the link is. - To fill a 100 Mbps link, the window must equal the bandwidth-delay product:
100 × 10^6 bits/s × 0.1 s = 10^7 bits = 1.25 × 10^6 bytes ≈1.25 MB. - 1.25 MB is far more than the 16-bit window field allows (65,535 bytes), which is why the TCP window scale option exists (shifting the window by up to 14 bits).
Answer: about 5.24 Mbps; about 1.25 MB of window (requiring window scaling) to fill 100 Mbps.
Problem 8: minimum frame size for CSMA/CD
Question. A CSMA/CD network runs at 10 Mbps over a maximum cable length of 2 km, with signal speed 2 × 10^8 m/s. What is the minimum frame size so that collisions are always detected?
Solution.
- A sender must still be transmitting when news of a collision returns from the far end; otherwise it cannot tell its frame collided. In the worst case, that takes one round trip:
2 × Tp. Tp = 2000 m / (2 × 10^8 m/s) = 10^-5 s = 10 µs. So2Tp = 20 µs.- Condition: transmission time ≥
2Tp, soL / B ≥ 2Tp, givingL ≥ 2 × Tp × B = 20 × 10^-6 × 10 × 10^6 =200 bits = 25 bytes.
Answer: at least 200 bits (25 bytes). For comparison, classic Ethernet uses a 64-byte (512-bit) minimum frame, which allows for repeaters and other delays in a larger network.
Common numerical mistakes
Mixing bits and bytes (multiply bytes by 8), mixing Mbps as 10^6 bits with MB as bytes, forgetting that stop-and-wait waits for two propagation delays, forgetting the "minus 2" for usable hosts, and using 2^n instead of 2^n − 1 for the Go-Back-N window. Write units next to every number and the mistakes disappear.
Revision checklist
Tick each item when you can explain it aloud without notes.
Fundamentals and models
- OSI layers, what each does, and the TCP/IP mapping
- Encapsulation and data unit names (segment, packet, frame)
- Devices by layer: hub, switch, router, load balancer
- The four delay components and bandwidth versus throughput versus latency
Data link and network layers
- MAC addresses, ARP, switch MAC learning, VLANs, STP
- CSMA/CD versus CSMA/CA; CRC calculation
- IPv4 versus IPv6, CIDR, private ranges, NAT
- Subnetting quickly: network, broadcast, host count, splitting into subnets
- TTL, ICMP, MTU and fragmentation
- Longest prefix match; distance vector versus link state; BGP basics
Transport
- TCP versus UDP and when to use each
- Three-way handshake, four-way close, TIME_WAIT
- Sequence numbers, ACKs, retransmission, fast retransmit
- Flow control versus congestion control; slow start, AIMD; bandwidth-delay product
- Stop-and-wait, Go-Back-N and Selective Repeat utilisation and window sizes
Application layer
- DNS resolution path, recursive versus iterative, record types, TTL, DNSSEC versus DoH
- HTTP methods (safe and idempotent), status codes, caching headers, cookies
- HTTP/1.1 versus HTTP/2 versus HTTP/3; CORS; WebSockets versus SSE
- Email (SMTP, IMAP, POP3, SPF/DKIM/DMARC), DHCP DORA, NTP, FTP versus SFTP
- Well-known ports table and the socket API lifecycle
Security and operations
- Symmetric versus asymmetric, hash, MAC, signature, Diffie-Hellman
- Certificates and chain of trust; TLS 1.2 versus 1.3 handshake
- MITM, ARP spoofing, DNS spoofing, DDoS, SYN flood, replay, XSS, CSRF
- Firewalls (stateless, stateful, application), IDS/IPS, VPNs, SSH keys
- CDN, L4 versus L7 load balancing, forward versus reverse proxy
- Tools: ping, traceroute/mtr, ss, dig, curl -v, tcpdump, and the "site is slow" method
- "What happens when you type a URL" in two minutes and in fifteen
Key takeaways
- Answer in three beats: definition, mechanism, trade-off. Expect "why?" as the follow-up.
- The highest-frequency topics are OSI/TCP-IP, TCP versus UDP and the handshake, subnetting, DNS resolution, HTTP methods and status codes, TLS, and the "type a URL" flow.
- Numericals reward careful units: bits versus bytes,
1/(1 + 2a)for stop-and-wait,1 + 2afor the ideal window, and2^n − 1versus2^(n−1)for sliding-window sequence space. - Subnetting is mechanical once you use block sizes: 256 minus the mask octet.
- Throughput is capped by window / RTT; the bandwidth-delay product tells you the window you need.
- Security questions test whether you can separate confidentiality, integrity and authentication, and match each attack with a defence.
- Practical questions (debugging slowness, open ports) are answered layer by layer with a named tool at each step.
- Revisit the linked lessons for any question you could not answer confidently.
Next lesson
You have finished the Computer Networks track. Start again from networking basics to revise from the beginning, or test yourself with the practice quizzes.

