Free guides, interview Q&As, and job responsibility breakdowns — curated by industry veterans to help you crack MNC interviews

Figure 2: How an NSG evaluates rules — lowest priority number wins, first match stops evaluation
Virtual Network (VNet)
Definition: An isolated, private network within Azure that lets resources securely communicate with each other, the internet, and on-premises networks.
Day-to-Day Example: Like a private office building's internal wiring — everything inside can talk to everything else, separate from the outside world.
Subnet
Definition: A smaller range of IP addresses carved out of a VNet's address space to organize and secure groups of resources.
Day-to-Day Example: Like dividing an office building into separate floors, each dedicated to a different department.
Network Security Group (NSG)
Definition: A set of allow/deny security rules that filters inbound and outbound network traffic to Azure resources.
Day-to-Day Example: Like a security guard at a door checking a list of who is allowed in or out.
Application Security Group (ASG)
Definition: A logical grouping of VMs by application role, used inside NSG rules instead of individual IP addresses.
Day-to-Day Example: Like giving every employee on the sales team the same badge color instead of listing each person by name.
Route Table (User Defined Route)
Definition: A set of custom rules that overrides Azure's default routing to control the path network traffic takes.
Day-to-Day Example: Like a custom detour sign redirecting delivery trucks through a specific checkpoint instead of the default road.
VNet Peering
Definition: A connection linking two Virtual Networks so resources in each can communicate privately using internal IP addresses.
Day-to-Day Example: Like two neighboring office buildings connecting a private hallway between them instead of using the public street.
Global VNet Peering
Definition: VNet Peering between Virtual Networks located in different Azure regions.
Day-to-Day Example: Like connecting two branch offices in different cities with a private, direct courier route.
Service Endpoint
Definition: A feature that extends a VNet's private address space to an Azure PaaS service, keeping traffic on the Azure backbone.
Day-to-Day Example: Like giving delivery trucks a private highway lane to a warehouse, even though the warehouse still has a public front door.
Private Endpoint
Definition: A network interface with a private IP address that connects privately and securely to a PaaS service, removing its public exposure.
Day-to-Day Example: Like installing a private back entrance to the warehouse so trucks never use the public front door at all.
Public IP Address
Definition: An internet-routable address that allows a resource to be reached from, or reach out to, the internet.
Day-to-Day Example: Like a storefront's public street address that any customer can visit.
Private IP Address
Definition: An internal address only reachable within the VNet or networks connected to it.
Day-to-Day Example: Like an internal office extension number that only coworkers inside the building can dial.
Azure Load Balancer
Definition: A Layer 4 (TCP/UDP) service that distributes incoming network traffic across multiple VMs for availability and performance.
Day-to-Day Example: Like a host at a restaurant sending guests to whichever open table is next, without caring what they plan to order.
Application Gateway
Definition: A Layer 7 (HTTP/HTTPS) web traffic load balancer with URL-based routing and Web Application Firewall (WAF) capability.
Day-to-Day Example: Like a smart receptionist who reads each visitor's request and directs them to the right department, while also screening out troublemakers.
VPN Gateway
Definition: An Azure resource that creates an encrypted connection between an on-premises network (or device) and a VNet over the public internet.
Day-to-Day Example: Like a locked, armored courier van driving over ordinary public roads.
ExpressRoute
Definition: A private, dedicated connection between on-premises infrastructure and Azure that does not travel over the public internet.
Day-to-Day Example: Like a private rail line built directly between two company sites, separate from public traffic entirely.
Azure Private DNS Zone
Definition: A DNS zone that resolves custom domain names privately, only for VNets linked to it.
Day-to-Day Example: Like an internal company phone directory that only employees can look up, unlisted anywhere public.
Azure Bastion
Definition: A fully managed service providing secure RDP/SSH access to VMs through the Azure portal, without exposing a public IP.
Day-to-Day Example: Like entering a secured building through a monitored front desk instead of climbing through a window.
NAT Gateway
Definition: A service that lets resources without public IPs make outbound internet connections through one shared, static public IP.
Day-to-Day Example: Like an office's single shared mailroom address used to send outgoing mail for everyone inside.
Azure Firewall
Definition: A managed, stateful, cloud-native firewall providing centralized traffic filtering, threat intelligence, and logging.
Day-to-Day Example: Like a company's central security checkpoint that every outgoing and incoming shipment must pass through.
Hub-and-Spoke Topology
Definition: A network design where a central "hub" VNet hosts shared services, and "spoke" VNets peer only to the hub, not to each other.
Day-to-Day Example: Like airline routes where regional airports (spokes) all connect through one major hub airport instead of flying directly to each other.

Figure 3: Hub-and-Spoke VNet topology — spokes peer with the hub, not with each other

Figure 4: VPN Gateway (encrypted, over the internet) vs. ExpressRoute (private, dedicated circuit)
1. Network Security Group (NSG) vs. Application Security Group (ASG)
Feature NSG ASG Purpose Filters inbound/outbound traffic with allow/deny rules Groups VMs by application role for use inside NSG rules Works alone? Yes — a complete filtering mechanism on its own No — always referenced inside an NSG rule Common confusion Mistaken as only working with individual IPs It's a label, not a rule engine, on its own
2. NSG vs. Route Table (UDR)
Feature NSG Route Table (UDR) Question answered Is this traffic allowed? Which path should this traffic take? Focus Security filtering Traffic direction / next hop Example Block inbound port 3389 from the internet Send all outbound traffic through a firewall appliance
3. VNet Peering vs. VPN Gateway
Feature VNet Peering VPN Gateway Connects VNet to VNet On-premises network (or device) to a VNet Path Microsoft private backbone Encrypted tunnel over the public internet Typical use Linking Azure VNets together Connecting a branch office or remote user to Azure
4. Regional Peering vs. Global Peering
Feature Regional Peering Global Peering Scope VNets in the same region VNets in different regions Latency Lower (same region) Slightly higher (cross-region) Common confusion Assumed to be the only type available Mistaken as requiring a VPN Gateway instead
5. Service Endpoint vs. Private Endpoint
Feature Service Endpoint Private Endpoint PaaS still has a public IP? Yes No — fully private IP address used Traffic tagged with VNet identity, service keeps public IP Service gets a private IP from the VNet Security level Good — restricts to VNet, but public endpoint remains Stronger — removes public exposure entirely
6. Public IP vs. Private IP
Feature Public IP Private IP Reachable from The internet Only within the VNet or connected networks Typical use Web-facing resources, VPN endpoints Internal communication between resources Common confusion Assumed every resource needs one Mistaken as unreachable even from peered VNets
7. Load Balancer vs. Application Gateway
Feature Load Balancer Application Gateway OSI layer Layer 4 (TCP/UDP) Layer 7 (HTTP/HTTPS) Routing intelligence Based on IP/port only Based on URL path, host header, etc. Extra capability None built in Web Application Firewall (WAF)
8. VPN Gateway vs. ExpressRoute
Feature VPN Gateway ExpressRoute Path Public internet (encrypted) Private, dedicated circuit Reliability / latency Good, but internet-dependent Higher reliability, lower and more predictable latency Best suited for Smaller sites, quick setup, remote users Large enterprises needing consistent, high-volume connectivity
9. Azure DNS (Public) vs. Azure Private DNS Zone
Feature Azure DNS (Public) Azure Private DNS Zone Resolvable from Anywhere on the internet Only VNets linked to the zone Typical use Hosting a public website's domain Internal service names like db.internal.contoso.com Common confusion Assumed to be the same service as Private DNS Mistaken as visible outside the linked VNets
10. Hub-and-Spoke vs. Full Mesh (Direct Peer-to-Peer) Topology
Feature Hub-and-Spoke Full Mesh Peering pattern Each spoke peers only with the hub Every VNet peers directly with every other VNet Management complexity Low — centralized in the hub High — grows quickly as VNets are added Best suited for Enterprises with shared services (firewall, gateway) Very small numbers of VNets needing direct links
Q1. What is an Azure Virtual Network (VNet), and what is its main purpose?
Answer: A VNet is an isolated, private network in Azure that lets resources communicate securely with each other, the internet, and on-premises networks; its main purpose is to provide a private, controllable networking boundary in the cloud.
Q2. What is a subnet, and why do administrators divide a VNet into multiple subnets?
Answer: A subnet is a smaller IP address range carved out of a VNet; administrators use multiple subnets to organize resources by role (web, app, data) and apply different security and routing rules to each group.
Q3. How does an NSG decide whether to allow or block a piece of traffic?
Answer: An NSG evaluates its rules in order of priority number, from lowest to highest, and applies the first rule that matches the traffic, stopping evaluation at that point.
Q4. What problem does an Application Security Group (ASG) solve?
Answer: An ASG lets administrators group VMs by application role and reference that group name in NSG rules, avoiding the need to hardcode and continually update individual IP addresses.
Q5. What is a Route Table (UDR), and when would an administrator need one?
Answer: A Route Table (User Defined Route) overrides Azure's default routing so traffic follows a custom path; it's needed when traffic must be forced through a firewall or network virtual appliance instead of going directly to its destination.
Q6. What is VNet Peering, and why is traffic through it considered fast and secure?
Answer: VNet Peering connects two VNets so resources communicate using private IP addresses; it's fast and secure because the traffic travels over Microsoft's private backbone network rather than the public internet.
Q7. Why is VNet Peering described as "not transitive"?
Answer: Because if VNet A peers with VNet B, and VNet B peers with VNet C, VNet A cannot automatically reach VNet C — a direct peering connection would need to be created between A and C.
Q8. What is the key difference between a Service Endpoint and a Private Endpoint?
Answer: A Service Endpoint keeps the PaaS service's public endpoint but restricts and optimizes traffic from the VNet, while a Private Endpoint assigns the service a private IP inside the VNet, removing public exposure entirely.
Q9. How do Azure Load Balancer and Application Gateway differ in what they can route on?
Answer: Load Balancer works at Layer 4 and routes based only on IP address and port, while Application Gateway works at Layer 7 and can route based on URL path, host header, or other HTTP-level details, and adds Web Application Firewall protection.
Q10. What is the core difference between a VPN Gateway connection and an ExpressRoute connection?
Answer: A VPN Gateway creates an encrypted connection over the public internet, while ExpressRoute is a private, dedicated circuit that bypasses the public internet, offering more predictable performance and reliability.
Q11. What is the difference between Azure-provided DNS and an Azure Private DNS Zone?
Answer: Azure-provided DNS handles basic default name resolution automatically inside a VNet, while a Private DNS Zone lets an organization define its own custom domain names that resolve only within the VNets linked to that zone.
Q12. What problem does Azure Bastion solve?
Answer: Azure Bastion lets administrators securely RDP or SSH into VMs directly through the Azure portal without ever assigning the VM a public IP address, reducing its exposure to internet-based attacks.
Q13. What does a NAT Gateway do for resources that don't have a public IP?
Answer: A NAT Gateway lets those resources initiate outbound connections to the internet through a single, shared, static public IP address, without needing a public IP of their own.
Q14. What is Azure Firewall, and how does it typically fit into a network design?
Answer: Azure Firewall is a managed, stateful, cloud-native firewall that centrally filters traffic and applies threat intelligence; it's typically deployed in the hub VNet of a hub-and-spoke design so all spokes route through it.
Q15. What is the Hub-and-Spoke topology, and what is its main advantage?
Answer: It's a design where a central hub VNet hosts shared services (like a firewall or gateway) and spoke VNets peer only with the hub; its main advantage is centralizing management and security instead of configuring every VNet individually.
Q1. A company needs its Web, Application, and Database tiers to be logically separated within a single VNet, each with different security rules. What should they configure?
Answer: They should create separate subnets for Web, Application, and Database tiers within the VNet, and apply a distinct NSG to each subnet to enforce tier-specific security rules.
Q2. An administrator wants to reference a group of 20 web server VMs in an NSG rule without listing each VM's IP address individually, and wants the rule to keep working automatically as VMs are added or removed.
Answer: They should create an Application Security Group (ASG) for the web servers, add the VM NICs to it, and reference the ASG inside the NSG rule instead of individual IP addresses.
Q3. A company wants all outbound traffic from its Application subnet to pass through a third-party firewall appliance before reaching the internet, instead of going directly.
Answer: They should create a Route Table (User Defined Route) that sends the Application subnet's outbound traffic to the firewall appliance's private IP as the next hop, then associate that route table with the subnet.
Q4. Two VNets in the same Azure region need their VMs to communicate using private IP addresses with minimal latency. What should be configured?
Answer: They should configure Regional VNet Peering between the two VNets, allowing their resources to communicate privately over Microsoft's backbone network.
Q5. A company wants its on-premises SQL Server to securely sync data with an Azure SQL Database, keeping traffic off the public internet entirely, and needs guaranteed low, predictable latency.
Answer: They should provision an ExpressRoute circuit, giving them a private, dedicated connection between on-premises infrastructure and Azure that bypasses the public internet.
Q6. A security team wants an Azure Storage Account to be reachable only from inside its VNet, with absolutely no public internet exposure.
Answer: They should configure a Private Endpoint for the Storage Account, which assigns it a private IP address inside the VNet and removes its public endpoint from being reachable.
Q7. An e-commerce site needs incoming HTTPS traffic routed to different backend pools based on the URL path (e.g., /images vs. /api), plus protection against common web attacks.
Answer: They should deploy an Application Gateway with URL-based routing rules and enable its Web Application Firewall (WAF) to route traffic correctly and protect against common web-based attacks.
Q8. A growing company has one hub VNet with a shared firewall and five separate spoke VNets for different departments, and wants all internet-bound traffic from every spoke inspected centrally.
Answer: They should keep the Hub-and-Spoke topology, peer each spoke only to the hub, and configure route tables in each spoke that force outbound traffic through the Azure Firewall sitting in the hub VNet.