Network engineer screening questions: routing, firewalls, outages, CCNA/CCNP and on-call
On this page
- NOC technician, administrator, engineer or architect: place the candidate
- Network scope: the numbers that set the level
- Routing, switching and firewalls: configured or recognized
- Changes, outages and on-call
- Automation and newer networking claims
- Certifications: status, recertification and what they show
- How network resumes overstate the work
- Logistics, knockout checklist and scorecard
- Questions people ask
Network engineer screening questions should establish what the candidate changed in a live network, not which vendors their employer owned. Ask how big the network was, which routing protocols and firewalls they configured themselves, the last change they designed and who approved it, the worst outage they worked and how they found the cause, and whether their certifications are current. Engineers with real ownership talk about a BGP session that would not come up, a firewall rule that broke payroll, and a change they rolled back at 2 a.m. Inflated resumes list Cisco, Juniper, Palo Alto, Fortinet and Meraki with no change they can walk through.
This bank covers on-premise and hybrid networks. For cloud infrastructure and pipelines, use DevOps engineer screening questions; for SOC and incident analysts, use cybersecurity analyst screening questions; for first-line support, use help desk technician screening questions. Network roles sit between all three, and the questions below are the ones those pages do not ask.
NOC technician, administrator, engineer or architect: place the candidate
| Role in practice | What the work produces | Question that places them | Common mismatch |
|---|---|---|---|
| NOC technician or analyst | Monitoring, first response to alerts, escalations, tickets | "When an alert fired, what could you change yourself and what did you escalate?" | Watched dashboards, listed as network engineering |
| Network administrator | Moves, adds and changes: ports, VLANs, access points, user VPN | "What was the last change you made, and did you design it or follow a ticket?" | Followed runbooks, described as design |
| Network engineer | Routing, switching, firewall policy, change design, outage leadership | "What was the biggest change you designed last year, and who approved it?" | Senior administrator with no design authority |
| Network architect | Standards, vendor selection, multi-site and data center design, budgets | "Which design standard did you write, and who follows it?" | Lead engineer on one project, titled architect |
| Field or deployment engineer | Site installs, cabling, rack and stack, staging hardware | "How much of the configuration was yours once the hardware was in?" | Installed pre-built configs, listed as configuration |
Network scope: the numbers that set the level
A 3-site office network and a 400-site retail network with two data centers are different jobs. You do not need to judge the numbers. You need the candidate to know them.
- "How many sites, and roughly how many switches, routers and firewalls?" Strong: numbers stated easily, with what they personally managed. Red flag: "a big network."
- "How did the sites connect: MPLS, SD-WAN, site-to-site VPN, direct connections to cloud?" Strong: names the design and a problem with it. Red flag: does not know how branches reached the data center.
- "Which vendors did you configure every week, and which were only present?" Strong: one or two primary vendors with depth. Red flag: six vendors at equal depth.
- "How big was the network team, and who did what?" Strong: a clear split between NOC, engineering and security. Red flag: claims all of it at a company with a large team.
- "Did the network connect to a cloud provider? Who owned that part?" Strong: honest ownership of the hybrid link. Red flag: "cloud networking" with no idea how traffic got there.
Routing, switching and firewalls: configured or recognized
These questions do not require you to know the answer. They require the candidate to have done the work and to describe it in their own words.
| Question | What a strong answer sounds like | Red flags |
|---|---|---|
| Which routing protocols ran in your network, and which did you configure yourself? | Names them with a location: "OSPF inside each campus, BGP to our two ISPs and to the cloud; I set up the second ISP peering." | Lists OSPF, EIGRP, BGP and IS-IS without saying where any of them ran. |
| Tell me about a routing problem you troubleshot. | A specific symptom, what they checked in order, the cause (a route leak, an asymmetric path, a wrong prefix list) and the fix. | "We rebooted the router." |
| How were VLANs and switch ports managed, and what went wrong? | A convention, a tool or template, and a real incident such as a spanning tree loop or a mislabeled trunk. | Never had a switching problem. |
| Which firewalls did you manage, and how were rules requested and reviewed? | Vendor and model family, a request process, periodic rule cleanup, and a rule they removed. | Added any rule requested; no review. |
| Tell me about a firewall change that broke something. | What broke, how they found the rule, the rollback, and what changed in the process. | Blames the application team without evidence. |
| Did you manage wireless? How many access points, on which controller or cloud dashboard? | Numbers, the platform, and a coverage or roaming issue they solved. | "Wireless just works." |
| How did you handle load balancers, DNS or DHCP, if at all? | A clear line on what the network team owned versus the server team. | Claims ownership of everything, then cannot describe any of it. |
Changes, outages and on-call
Network mistakes take everything down at once, so how a candidate handles change and failure matters as much as protocol knowledge.
| Question | What a strong answer sounds like | Red flags |
|---|---|---|
| Walk me through the last significant change you designed, from plan to done. | A written plan, peer review, a change approval board or approver, a maintenance window, pre- and post-checks, and a rollback plan. | Made changes in business hours with no rollback plan. |
| Tell me about a change you rolled back. | Why they rolled back, how fast, and what they did differently next time. | Has never rolled back, or pushed through a failing change. |
| What was the worst outage you worked, and what was your role? | Timeline, their part (lead, investigator, communicator), how the cause was found, and the follow-up. | Only watched the bridge call. |
| How was the network monitored, and what alert did you fix because it was noisy? | The tool (SolarWinds, LogicMonitor, PRTG, Datadog and others), what was monitored, and a tuned alert. | Found out about outages from users. |
| What did on-call look like: rotation, pages per week, response time? | Concrete numbers and a recent page. | Never on call, for a role that includes it. |
| How was the configuration backed up and documented? | A backup tool, diagrams kept current, and a time the backup saved them. | Diagrams years out of date; no backups. |
Automation and newer networking claims
Network automation and software-defined networking appear on more resumes each year. Check the depth the same way as any other claim.
- "What have you automated, and in what?" Strong: a specific task (config backups, VLAN deployment across 200 switches, compliance checks) and the tool (Python, Ansible, vendor APIs). Red flag: "automation" meaning copying the same config into many terminals.
- "Did you write the scripts or run ones others wrote?" Strong: honest ownership and where the code lived. Red flag: no version control.
- "Was your SD-WAN or fabric designed by you, a colleague or the vendor's professional services?" Strong: clear ownership and a policy they built. Red flag: claims design of a vendor-delivered rollout.
- "How did your network connect to AWS, Azure or Google Cloud?" Strong: names the link type and the routing across it. Red flag: cloud networking as a label only.
Certifications: status, recertification and what they show
| Certification | Issuer | Notes, as of September 2026 |
|---|---|---|
| CCNA (exam 200-301) | Cisco | Associate level, covering network fundamentals, IP connectivity and services, security fundamentals and automation, per Cisco. A common baseline for junior roles. |
| CCNP Enterprise | Cisco | Professional level: the ENCOR core exam (350-401) plus a concentration exam. Passing ENCOR alone earns a specialist certification, per Cisco. Ask which concentration they passed. |
| CCIE | Cisco | Expert level with a hands-on lab exam. Rare; verify it rather than taking the resume's word. |
| Vendor firewall and SD-WAN certifications | Palo Alto Networks, Fortinet, Juniper and others | Useful when the client runs that vendor. Check the issuer's verification and expiry. |
Cisco's recertification policy says most of its certifications are active for three years, and can be renewed by retaking an exam, passing a higher-level exam or earning continuing education credits. A lapsed CCNP on a senior engineer is common and not disqualifying; a "CCNP" that turns out to be only the core exam is a labeling problem worth correcting before the client sees it.
How network resumes overstate the work
| Pattern | What it looks like | How to check |
|---|---|---|
| Vendor list | Cisco, Juniper, Arista, Palo Alto, Fortinet, Meraki, Aruba | "Which did you log into every week last year?" |
| Protocol list | BGP, OSPF, EIGRP, MPLS, VXLAN | "Where did each run, and which did you configure?" |
| NOC as engineering | "Maintained enterprise network" | "What could you change without escalating?" |
| Project presence as design | "Designed SD-WAN for 150 sites" | "Who wrote the design document, and what policy did you build?" |
| Certification in progress as held | "CCNP" with only one exam passed | "Which exams, and when does it expire?" |
| Lab as production | A home lab listed with job experience | "Was that at work or in a lab?" Labs are good; labeling matters. |
Logistics, knockout checklist and scorecard
| Question | What a strong answer sounds like | Red flags |
|---|---|---|
| Changes run Saturday 10 p.m. to 2 a.m. twice a month, and on-call is one week in four. Can you commit? | A clear yes or limit. Describe the schedule; do not ask about family to judge it. | Accepts without asking how often pages happen. |
| The role covers three sites and some travel to them. Does that work? | A clear answer and a vehicle or license note if the client requires driving. | Remote-only expectations for a hands-on role. |
| What salary or rate do you need, and do you expect on-call pay? | A number and a view. See salary expectation questions. | Only a salary-site figure. |
| Are you legally authorized to work in the US, and will you now or in the future need visa sponsorship? | A direct answer to both. | None. Ask everyone the same two questions. |
Knock out, or flag to the client before submitting, if:
- The role designs changes and the candidate has never had change authority beyond tickets.
- The client's primary firewall or routing platform is a must-have and the candidate has never configured it.
- The role includes on-call and the candidate cannot commit to the rotation.
- A required certification is expired or only partly earned, and the client said it must be current.
| Area | 1 | 2 | 3 | 4 |
|---|---|---|---|---|
| Routing, switching and security | Recognizes the terms | Follows runbooks | Configures and troubleshoots independently | Designs and sets standards |
| Change discipline | No process | Follows the process | Designs changes with rollback | Owns the change process |
| Outages and on-call | No on-call | Joined outages | Found causes and fixed them | Led outages and follow-up |
| Automation | None | Runs others' scripts | Wrote scripts for real tasks | Automation in version control used by the team |
| Logistics fit | Deal-breaker | Two open questions | One open question | All aligned |
Record the outage and the change story in the candidate's words: "led the ISP failover outage; 'the backup route was never advertised, we found it in 40 minutes'" tells an infrastructure manager far more than "strong troubleshooting." Interview Signal attaches quotes like that to each score from the call, so the evidence is ready when you write the submittal.
Questions people ask
Is a CCNA enough for a network engineer role?
For junior and network operations roles, a CCNA is a common baseline. For engineer roles that design or own the network, clients usually want production experience with routing, firewalls and changes, and often a CCNP or equivalent. Ask what the candidate changed in a live network either way.
How long are Cisco certifications valid?
Cisco states that most of its certifications are active for three years. Candidates can recertify by retaking the exam, passing a higher-level exam or earning continuing education credits, so ask for the current expiry date, not the year they passed.
What is the difference between a network engineer and a network administrator?
Titles overlap. An administrator usually keeps an existing network running: moves, adds, changes, monitoring and tickets. An engineer usually designs changes, owns routing and firewall policy and leads outages. Ask who designed the last major change and who approved it.
Can I ask a network engineer about after-hours work?
Yes. Describe the change window and on-call rotation concretely, then ask whether the candidate can commit. Ask about the schedule itself, not about family or caregiving.