What You Actually Need to Know Before Sitting Down
Cisco interview questions tend to fall into a few buckets, but the reality is most hiring managers will test you on whichever protocols they use daily. If a company runs OSPF and EIGRP alongside BGP, don't bother prepping for IS-IS unless you want to look foolish trying. I spent three years preparing for the wrong routing protocol because I followed a generic blog post. That was a mistake. Routing and switching form the backbone. Expect questions about OSPF areas, LSA types, DR/BDR election mechanics, and why OSPF forms two-way-not-full. I once got asked why a router would never become DR on a broadcast network even when it had the highest priority. The answer involved checking if the interface priority was set to zero, which disqualifies it entirely. This is the kind of thing nobody warns you about until you've stared at a lab topology for an hour. VLANs and trunking come up constantly. Native VLAN mismatches, VLAN hopping risks, DTP negotiation modes, and when to explicitly disable DTP. Port security mac-address sticky, aging timers, violation modes. These are fundamentals most candidates can recite, but interviewers often ask follow-ups that expose whether you actually configured these or just read about them. Be honest about your hands-on experience level.
STP variations matter more than you think. RSTP convergence times, PVST+ versus MST, and why spanning-tree cost adjustments should be made on the root port side. A lot of people forget that changing cost on a non-root port won't influence the root path selection correctly during a topology change. It sounds like a trick question until you've debugged one at 2am when a link flap took down your primary path.
How to Approach These Questions in Practice
Start by understanding the OSI model without memorizing it like a poem. When someone asks about a Layer 2 issue versus a Layer 3 issue, walk through your diagnostic process step by step. Check MAC address tables first. Then ARP caches. Then routing tables. This shows structured thinking rather than random guessing. For BGP questions, know the path selection algorithm cold. Local preference, AS path length, origin type, MED, eBGP over iBGP, IGP metric to next hop, and router ID. The order matters. I remember an interview where they asked which attribute BGP evaluates first after receiving a route. Most people jump to AS path because it gets the most attention in labs. Local preference wins on iBGP routes, and AS path comes later. Getting this wrong signals you haven't worked with BGP in production. NAT translations confuse a lot of candidates. Static versus dynamic NAT, PAT overload behavior, how NAT table expiration works, and what happens when you exceed the translation limit. During a real migration project I ran into a situation where PAT overload caused asymmetric routing because the return traffic hit a different router without the NAT table entry. We fixed it by implementing hairpin NAT with static entries for the affected servers. This is exactly the kind of war story that separates people who have actually managed networks from people who have only configured homelabs.
Get the Full Details

Where Candidates Regularly Fail
ACL configuration is a common weak spot. People understand permit and deny conceptually but struggle with implicit deny, the ordering of statements, and applying ACLs inbound versus outbound on interfaces. An inbound ACL on a LAN interface filters traffic before it reaches the router. An outbound ACL filters traffic leaving an interface toward another network. This distinction changes everything about how you design access policies. IPsec VPN troubleshooting is another area where theoretical knowledge falls apart quickly. Phase 1 and Phase 2 negotiations, ISAKMP policies, transform sets, crypto maps, and the difference between main mode and aggressive mode. I had a candidate who could recite every tunnel phase detail but couldn't explain why a site-to-site VPN kept cycling between ACTIVE and INACTIVE states. The answer was a mismatched PFS setting between the two endpoints. It's always something simple that you wouldn't catch from memorization alone. Subnetting questions sometimes appear even though no one uses them in production anymore. They persist because they reveal whether you understand CIDR notation and variable-length subnet masking. Be comfortable calculating /27 subnets, understanding how many usable hosts exist in different prefix lengths, and explaining why supernetting works the way it does. These skills transfer directly to VLAN planning and addressing schemes.
What to Study If You're Starting From Scratch
Get GNS3 or EVE-NG installed and build actual topologies. Watching videos about configuring HSRP teaches you nothing until you break it yourself and watch the failover happen. Configure VTP incorrectly and watch every switch in your lab lose its VLAN database. These mistakes cost you time but they teach you more than any certification study guide ever will. Focus on Cisco IOS command syntax, not just conceptual understanding. Know the exact commands for show ip ospf neighbor detail, show running-config, show ip route statically, and show access-lists. Interviewers occasionally ask you to walk through a command output and identify the problem. If you can't read show commands fluently, you won't pass the technical screening regardless of how well you know the theory. Read through Cisco documentation for the protocols you plan to discuss. The official configuration guides are dry but accurate. They'll tell you things like the maximum number of equal-cost paths OSPF installs by default (four), or that BGP route reflection requires specific cluster ID configuration. These details matter when an interviewer probes deeper into your answers.
The Honest Truth About Preparation
No amount of study materials replaces actual network experience. I've interviewed candidates who aced every textbook question but couldn't explain what happens when you shut down an interface that has IP helper-address configured. They froze because they had never actually seen DHCP requests fail when the helper interface went down. The answer involves the relay agent losing its ability to forward broadcasts, which causes DHCP discovery packets to drop on that segment entirely. Study the protocols your target employer uses. A company running Cisco DNA Center will ask different questions than one managing legacy Catalyst switches with CLI-only configurations. Check the job posting carefully. Look for mentioned products, protocols, and responsibilities. Tailor your preparation accordingly. Generic study plans produce generic interview performance, and generic performance rarely wins offers.
