Group A — Short Answer Questions (1 Mark Each)

Q1Define Computer Network.

Ans: Concise point-wise definition/formula for Define Computer Network. in accordance with MAKAUT examination pattern.

Q2What is OSI Reference Model?

Ans: Concise point-wise definition/formula for What is OSI Reference Model? in accordance with MAKAUT examination pattern.

Q3Name all 7 layers of OSI Model in order.

Ans: Concise point-wise definition/formula for Name all 7 layers of OSI Model in order. in accordance with MAKAUT examination pattern.

Q4What is TCP/IP Model?

Ans: Concise point-wise definition/formula for What is TCP/IP Model? in accordance with MAKAUT examination pattern.

Q5Define Physical Topology.

Ans: Concise point-wise definition/formula for Define Physical Topology. in accordance with MAKAUT examination pattern.

Q6What is Star Topology?

Ans: Concise point-wise definition/formula for What is Star Topology? in accordance with MAKAUT examination pattern.

Q7What is Mesh Topology?

Ans: Concise point-wise definition/formula for What is Mesh Topology? in accordance with MAKAUT examination pattern.

Q8Define Bandwidth.

Ans: Concise point-wise definition/formula for Define Bandwidth. in accordance with MAKAUT examination pattern.

Q9Define Throughput in networking.

Ans: Concise point-wise definition/formula for Define Throughput in networking. in accordance with MAKAUT examination pattern.

Q10Define Propagation Delay.

Ans: Concise point-wise definition/formula for Define Propagation Delay. in accordance with MAKAUT examination pattern.

Q11Define Transmission Delay.

Ans: Concise point-wise definition/formula for Define Transmission Delay. in accordance with MAKAUT examination pattern.

Q12What is Bandwidth-Delay Product?

Ans: Concise point-wise definition/formula for What is Bandwidth-Delay Product? in accordance with MAKAUT examination pattern.

Q13Define Simplex, Half-Duplex, and Full-Duplex.

Ans: Concise point-wise definition/formula for Define Simplex, Half-Duplex, and Full-Duplex. in accordance with MAKAUT examination pattern.

Q14What is Guided Transmission Media?

Ans: Concise point-wise definition/formula for What is Guided Transmission Media? in accordance with MAKAUT examination pattern.

Q15What is Unguided Transmission Media?

Ans: Concise point-wise definition/formula for What is Unguided Transmission Media? in accordance with MAKAUT examination pattern.

Q16Define Optical Fiber communication.

Ans: Concise point-wise definition/formula for Define Optical Fiber communication. in accordance with MAKAUT examination pattern.

Q17What is Bit Rate and Baud Rate?

Ans: Concise point-wise definition/formula for What is Bit Rate and Baud Rate? in accordance with MAKAUT examination pattern.

Q18Define Pulse Code Modulation (PCM).

Ans: Concise point-wise definition/formula for Define Pulse Code Modulation (PCM). in accordance with MAKAUT examination pattern.

Q19What is Framing in Data Link Layer?

Ans: Concise point-wise definition/formula for What is Framing in Data Link Layer? in accordance with MAKAUT examination pattern.

Q20Define Error Detection and Error Correction.

Ans: Concise point-wise definition/formula for Define Error Detection and Error Correction. in accordance with MAKAUT examination pattern.

Q21What is Parity Check?

Ans: Concise point-wise definition/formula for What is Parity Check? in accordance with MAKAUT examination pattern.

Q22What is Cyclic Redundancy Check (CRC)?

Ans: Concise point-wise definition/formula for What is Cyclic Redundancy Check (CRC)? in accordance with MAKAUT examination pattern.

Q23What is Hamming Code?

Ans: Concise point-wise definition/formula for What is Hamming Code? in accordance with MAKAUT examination pattern.

Q24Define Hamming Distance.

Ans: Concise point-wise definition/formula for Define Hamming Distance. in accordance with MAKAUT examination pattern.

Q25What is Flow Control?

Ans: Concise point-wise definition/formula for What is Flow Control? in accordance with MAKAUT examination pattern.

Q26What is Stop-and-Wait Protocol?

Ans: Concise point-wise definition/formula for What is Stop-and-Wait Protocol? in accordance with MAKAUT examination pattern.

Q27What is Sliding Window Protocol?

Ans: Concise point-wise definition/formula for What is Sliding Window Protocol? in accordance with MAKAUT examination pattern.

Q28What is Go-Back-N ARQ?

Ans: Concise point-wise definition/formula for What is Go-Back-N ARQ? in accordance with MAKAUT examination pattern.

Q29What is Selective Repeat ARQ?

Ans: Concise point-wise definition/formula for What is Selective Repeat ARQ? in accordance with MAKAUT examination pattern.

Q30Define Piggybacking.

Ans: Concise point-wise definition/formula for Define Piggybacking. in accordance with MAKAUT examination pattern.

Q31What is MAC Address?

Ans: Concise point-wise definition/formula for What is MAC Address? in accordance with MAKAUT examination pattern.

Q32Define CSMA/CD.

Ans: Concise point-wise definition/formula for Define CSMA/CD. in accordance with MAKAUT examination pattern.

Q33Define CSMA/CA.

Ans: Concise point-wise definition/formula for Define CSMA/CA. in accordance with MAKAUT examination pattern.

Q34What is Pure ALOHA? --- Page 2 ---

Ans: Concise point-wise definition/formula for What is Pure ALOHA? --- Page 2 --- in accordance with MAKAUT examination pattern.

Q35What is Slotted ALOHA?

Ans: Concise point-wise definition/formula for What is Slotted ALOHA? in accordance with MAKAUT examination pattern.

Q36What is IP Address?

Ans: Concise point-wise definition/formula for What is IP Address? in accordance with MAKAUT examination pattern.

Q37Define IPv4 Address structure.

Ans: Concise point-wise definition/formula for Define IPv4 Address structure. in accordance with MAKAUT examination pattern.

Q38Define IPv6 Address structure.

Ans: Concise point-wise definition/formula for Define IPv6 Address structure. in accordance with MAKAUT examination pattern.

Q39What is Subnetting?

Ans: Concise point-wise definition/formula for What is Subnetting? in accordance with MAKAUT examination pattern.

Q40What is CIDR?

Ans: Concise point-wise definition/formula for What is CIDR? in accordance with MAKAUT examination pattern.

Q41What is Network Address Translation (NAT)?

Ans: Concise point-wise definition/formula for What is Network Address Translation (NAT)? in accordance with MAKAUT examination pattern.

Q42What is ARP?

Ans: Concise point-wise definition/formula for What is ARP? in accordance with MAKAUT examination pattern.

Q43What is RARP?

Ans: Concise point-wise definition/formula for What is RARP? in accordance with MAKAUT examination pattern.

Q44What is ICMP?

Ans: Concise point-wise definition/formula for What is ICMP? in accordance with MAKAUT examination pattern.

Q45What is DHCP?

Ans: Concise point-wise definition/formula for What is DHCP? in accordance with MAKAUT examination pattern.

Q46What is Distance Vector Routing?

Ans: Concise point-wise definition/formula for What is Distance Vector Routing? in accordance with MAKAUT examination pattern.

Q47What is Link State Routing?

Ans: Concise point-wise definition/formula for What is Link State Routing? in accordance with MAKAUT examination pattern.

Q48Define Congestion Control.

Ans: Concise point-wise definition/formula for Define Congestion Control. in accordance with MAKAUT examination pattern.

Q49What is Leaky Bucket Algorithm?

Ans: Concise point-wise definition/formula for What is Leaky Bucket Algorithm? in accordance with MAKAUT examination pattern.

Q50What is Token Bucket Algorithm?

Ans: Concise point-wise definition/formula for What is Token Bucket Algorithm? in accordance with MAKAUT examination pattern.

Q51What is DNS?

Ans: Concise point-wise definition/formula for What is DNS? in accordance with MAKAUT examination pattern.

Q52What is HTTP and HTTPS?

Ans: Concise point-wise definition/formula for What is HTTP and HTTPS? in accordance with MAKAUT examination pattern.

Q53What is FTP?

Ans: Concise point-wise definition/formula for What is FTP? in accordance with MAKAUT examination pattern.

Group B — Medium / Descriptive Questions (5 Marks Each)

Q1Explain OSI 7 Layer Architecture with functions of each layer.

Ans: The OSI (Open Systems Interconnection) model is a 7-layer conceptual framework (ISO standard) that standardizes how data moves from one application on a source host to an application on a destination host across a network.

7. Application 6. Presentation 5. Session 4. Transport 3. Network 2. Data Link 1. Physical
OSI 7-layer stack — data flows down at sender, up at receiver
  • Physical: Transmits raw bits over a physical medium; deals with voltage, cabling, connectors, bit synchronization.
  • Data Link: Framing, physical (MAC) addressing, error detection, and flow control over a single link.
  • Network: Logical (IP) addressing and routing of packets across multiple networks.
  • Transport: End-to-end reliable/unreliable delivery, segmentation, flow and congestion control (TCP/UDP).
  • Session: Establishes, manages, and terminates sessions/dialogs between applications.
  • Presentation: Data translation, encryption, and compression (syntax layer).
  • Application: Provides network services directly to end-user applications (HTTP, FTP, SMTP).
Version (4b) IHL (4b) Type of Service (8b) Total Length (16b) Identification (16b) Flags (3b) Fragment Offset (13b) Time to Live TTL (8b) Protocol (8b) Header Checksum (16b) Source IPv4 Address (32 bits) Destination IPv4 Address (32 bits)
Figure: IPv4 Datagram 32-bit Header Structure
Q2Compare OSI Model vs TCP/IP Model.

Ans: The OSI model is a 7-layer theoretical reference model, while TCP/IP is a 4-layer practical protocol suite that actually runs the Internet.

BasisOSI ModelTCP/IP Model
Layers7 (Physical, Data Link, Network, Transport, Session, Presentation, Application)4 (Network Access/Link, Internet, Transport, Application)
DevelopmentReference model, protocol-independent, defined firstDeveloped along with the protocols (DoD project), defined after implementation
Session/PresentationSeparate dedicated layersMerged into Application layer
ReliabilityModel is generic — reliability not tied to a layerTransport layer explicitly offers both reliable (TCP) and unreliable (UDP) service
UsageUsed as a teaching/reference standardUsed in actual Internet implementation
ApproachHorizontal (layer-to-layer) approachVertical, protocol-driven approach

Both models use encapsulation/de-encapsulation and layered, modular design so each layer can evolve independently as long as the interface to adjacent layers is preserved.

Figure: Cyclic Redundancy Check (CRC) Error Detection Pipeline
Figure: Cyclic Redundancy Check (CRC) Error Detection Pipeline
Q3Explain Transmission Media: Twisted Pair, Coaxial, Fiber Optics.

Ans: Guided (wired) transmission media carry signals along a solid path; the three principal types differ in bandwidth, noise immunity, and cost.

MediumConstructionBandwidthNoise ImmunityTypical Use
Twisted Pair (UTP/STP)Two insulated copper wires twisted together to cancel electromagnetic interferenceUp to 10 Gbps (Cat6a) over short runsLow-Moderate (STP better than UTP)LAN/Ethernet, telephone lines
Coaxial CableCentral copper conductor, insulator, braided metallic shield, outer jacketUp to ~1 GbpsBetter than twisted pair (shielded)Cable TV, older Ethernet (10BASE2/5)
Optical FiberGlass/plastic core carrying light pulses via total internal reflectionTens of Gbps to TbpsImmune to EMI, very low attenuationBackbone links, long-haul, FTTH

Fiber offers the highest bandwidth and longest distance with lowest attenuation but is costlier to install and splice; twisted pair is cheapest and easiest to terminate; coaxial sits in between and is largely obsolete for new LAN deployments.

Transmission Time RTTs Congestion Window (cwnd) ssthresh threshold Slow Start (Exponential) Congestion Avoidance (Linear) Timeout Drop!
Figure: TCP Congestion Window (cwnd) Growth, ssthresh Threshold & Timeout Loss Drop
Q4Explain Switching Techniques: Circuit Switching vs Packet Switching.

Ans: Switching decides how data travels through intermediate nodes from source to destination.

Circuit Switching (dedicated path) A S1 S2 B Packet Switching (store-and-forward, independent routes) A R1 R2 B
Circuit switching reserves one fixed path; packet switching lets packets take independent routes
BasisCircuit SwitchingPacket Switching
PathDedicated physical path set up before data transferNo dedicated path; each packet routed independently
SetupRequires call setup/teardown phaseNo setup phase needed (connectionless) or virtual circuit for connection-oriented
Bandwidth useWasted if idle (reserved even when not sending)Efficient — bandwidth shared/statistically multiplexed
DelayConstant delay once connected, no queuing after setupVariable delay due to queuing at each router
ExampleTraditional PSTN telephone networkInternet (IP networks)
Q5Explain Error Detection using Cyclic Redundancy Check (CRC).

Ans: Cyclic Redundancy Check (CRC) is a polynomial-based error-detection technique used at the Data Link layer to detect burst errors with very high probability.

Mechanism:

  • Sender and receiver agree on a generator polynomial G(x) of degree r (represented as an (r+1)-bit pattern).
  • Sender appends r zero bits to the data (message M) and divides the resulting bit string by G using modulo-2 (XOR) binary division.
  • The remainder of this division is the CRC checksum/FCS; it replaces the appended zeros to form the transmitted frame T = M·2^r XOR remainder.
Sender: T = M appended with r zeros divide T by G (XOR/mod-2 division) CRC = remainder (r bits) Transmit frame = M followed by CRC Receiver: divide received frame by G remainder == 0 -> no error detected remainder != 0 -> error detected, discard/request retransmit

Analysis: CRC with an r-bit generator detects all single-bit errors, all double-bit errors (if G has ≥2 terms and is not divisible by x), all odd number of errors (if G has factor (x+1)), and all burst errors of length ≤ r. It is far stronger than simple parity and is widely used in Ethernet, HDLC, and USB frame trailers.

Figure: TCP 3-Way Handshake Connection & 4-Way Termination Protocol
Figure: TCP 3-Way Handshake Connection & 4-Way Termination Protocol
CLIENT SERVER 1. SYN (seq = x) 2. SYN-ACK (seq = y, ack = x+1) 3. ACK (seq = x+1, ack = y+1)
Figure: TCP 3-Way Handshake Connection Protocol
Q6Explain Error Correction using Hamming Code with an example.

Ans: Hamming Code adds redundant parity bits at positions that are powers of 2 so that not only can an error be detected, its exact bit position can also be located and corrected (single-error correction).

Example (4 data bits d1d2d3d4 = 1 0 1 1): Using 3 parity bits (p1,p2,p4) placed at positions 1,2,4 gives a 7-bit code p1 p2 d1 p4 d2 d3 d4 at positions 1-7.

Position1234567
Bitp1p2d1=1p4d2=0d3=1d4=1

Each parity bit covers positions whose binary index has that bit set:

  • p1 covers 1,3,5,7 → checks bits (p1),1,0,1 → p1 XOR 1 XOR 0 XOR 1 = 0 → p1 = 0
  • p2 covers 2,3,6,7 → checks (p2),1,1,1 → p2 XOR 1 XOR 1 XOR 1 = 0 → p2 = 1
  • p4 covers 4,5,6,7 → checks (p4),0,1,1 → p4 XOR 0 XOR 1 XOR 1 = 0 → p4 = 0

Final transmitted code = 0 1 1 0 0 1 1 (positions 1-7). At the receiver, the same three parity groups are recomputed; if all match, no error. If a mismatch pattern occurs, the binary value of the mismatched parity positions (c4 c2 c1) directly gives the erroneous bit's position, which is then flipped to correct it — e.g. if bit 3 flips, checks p1 and p2 fail (positions 1+2=3), pinpointing position 3.

Q7Explain Stop-and-Wait ARQ protocol and efficiency formula.

Ans: In Stop-and-Wait ARQ, the sender transmits one frame and then waits for the receiver's acknowledgement (ACK) before sending the next frame; a timer triggers retransmission if the ACK is lost or delayed.

Sender Receiver Frame 0 ACK 0 Frame 1 ACK 1
Stop-and-Wait: one frame in flight at a time, idle sender while waiting

Efficiency formula: Let Tt = transmission time, Tp = propagation delay, and a = Tp / Tt. One full cycle takes Tt + 2Tp, so:

Efficiency (Utilization) = Tt / (Tt + 2Tp) = 1 / (1 + 2a)

When propagation delay is large compared to transmission time (large a, e.g. satellite links), efficiency drops sharply because the sender remains idle for most of the round-trip time — this motivates sliding-window protocols (GBN, SR).

Q8Explain Go-Back-N ARQ protocol and window sizes.

Ans: Go-Back-N ARQ is a sliding-window protocol where the sender can transmit up to N frames without waiting for individual acknowledgements, but the receiver only accepts frames in strict order (cumulative ACK).

Sender Receiver F0 F1 F2 (lost) F3 F3 discarded (out of order) ACK1 (expects 2) Sender times out, goes back to F2 and resends F2,F3...
Go-Back-N: one lost frame forces retransmission of it and all following frames

Window sizes: with an m-bit sequence number field, sender window size = 2^m - 1 and receiver window size = 1 (receiver only buffers the next expected frame, discarding out-of-order arrivals). Cumulative ACKs mean one ACK confirms all frames up to that sequence number, but a single error forces re-sending the entire window from the lost frame onward, wasting bandwidth on high-error links.

Q9Explain Selective Repeat ARQ protocol and window sizes.

Ans: Selective Repeat ARQ improves on Go-Back-N by having the receiver individually buffer and acknowledge out-of-order frames, so only the specific corrupted/lost frame needs retransmission.

Sender Receiver F0 F1 F2 (lost) F3 F3 buffered (not discarded) Selective ACK/NAK for F2 Sender resends only F2; receiver reorders and delivers
Selective Repeat: only the missing frame is retransmitted, receiver reorders buffered frames

Window sizes: both sender and receiver maintain a window; to avoid ambiguity between new and retransmitted frames the maximum window size for both sender and receiver is restricted to 2^(m-1) (half of Go-Back-N's), where m is the sequence-number field width. Selective Repeat is more bandwidth-efficient on lossy/high-latency links but requires more receiver buffering and sequencing logic than Go-Back-N.

Plaintext (M) Public Key (e, n) C = M^e mod n Ciphertext (C) Private Key (d, n) M = C^d mod n
Figure: RSA Public Key Cryptography Encryption & Decryption Pipeline
Q10Explain Pure ALOHA vs Slotted ALOHA throughput analysis.

Ans: ALOHA is a random-access MAC protocol where stations transmit whenever they have data, risking collisions; throughput S is analyzed against offered load G (average number of transmission attempts per frame time).

SchemeVulnerable PeriodThroughput FormulaMax Throughput
Pure ALOHA2 × frame time (2Tf) — station can transmit any instantS = G·e^(-2G)18.4% at G = 0.5
Slotted ALOHA1 × frame time (Tf) — transmission confined to slot boundariesS = G·e^(-G)36.8% at G = 1.0

Why slotted is better: Time is divided into slots equal to one frame transmission time, and stations may only start transmitting at a slot boundary. This halves the vulnerable period compared to Pure ALOHA (where a frame can collide with any frame starting up to one frame-time before or after it), doubling the maximum achievable throughput (36.8% vs 18.4%). Both schemes still waste significant capacity to collisions compared to collision-avoidance/detection schemes like CSMA/CD or CSMA/CA, but ALOHA's simplicity (no carrier sensing needed) made it foundational for satellite and early packet radio networks.

Q11Explain CSMA/CD protocol and Binary Exponential Backoff algorithm.

Ans: CSMA/CD (Carrier Sense Multiple Access with Collision Detection) is used in classic wired Ethernet: a station listens ("carrier sense") before transmitting, and continues to listen while transmitting to detect collisions.

Sense channel Idle? Transmit frame Collision detected? Yes Send jam signal Binary Exponential Backoff, retry
CSMA/CD: sense, transmit, detect collision, jam, backoff and retry

Binary Exponential Backoff: After the n-th collision on the same frame, the station picks a random integer K from {0, 1, ..., 2^min(n,10) - 1} and waits K slot times before retrying (slot time = 512 bit times in classic Ethernet). This spreads out retransmission attempts, so as contention increases, the retry window grows exponentially, reducing repeated collisions. After 16 failed attempts the frame is dropped and reported as an error.

Q12Explain CSMA/CA protocol and Wireless LAN collision avoidance.

Ans: CSMA/CA (Collision Avoidance) is used in wireless LANs (IEEE 802.11) because collision detection is impractical over radio (a station cannot listen while transmitting due to its own strong signal drowning out weak received signals, and hidden-terminal effects).

Station A AP / Station B Sense idle -> DIFS wait RTS CTS (reserves medium) DATA ACK
CSMA/CA with RTS/CTS handshake reserves the medium before data transfer

Mechanism: A station senses the channel; if idle, it waits a fixed DIFS (DCF Interframe Space) period, then a random backoff counter (contention window) before transmitting — this avoidance-first approach reduces collision probability instead of reacting after the fact. Optionally, RTS/CTS (Request-to-Send / Clear-to-Send) frames are exchanged first: the CTS frame carries a duration field that instructs all other stations to set their NAV (Network Allocation Vector) and stay silent, solving the hidden-terminal problem. Every successfully received unicast frame is explicitly acknowledged with an ACK, since the sender cannot infer success by listening for collisions.

Q13Explain IPv4 Address Classes (A, B, C, D, E) and ranges.

Ans: Classful IPv4 addressing divides the 32-bit address space into 5 classes, identified by the leading bits of the first octet.

ClassLeading BitsFirst Octet RangeDefault MaskPurpose
A00 – 127255.0.0.0 (/8)Very large networks (few networks, many hosts)
B10128 – 191255.255.0.0 (/16)Medium-sized networks
C110192 – 223255.255.255.0 (/24)Small networks (many networks, few hosts)
D1110224 – 239N/AMulticast addressing
E1111240 – 255N/AReserved for experimental/research use

Class A supports ~16.7 million hosts per network (2^24−2), Class B ~65,534 hosts (2^16−2), and Class C 254 hosts (2^8−2) — the −2 accounts for the reserved network and broadcast addresses. This rigid classful scheme wastes address space (e.g. a company needing 300 hosts must take a wasteful Class B), which is why classless CIDR addressing later replaced it in practice.

Q14Explain Subnetting and Subnet Mask calculation.

Ans: Subnetting divides one large IP network into multiple smaller sub-networks by borrowing host bits to extend the network portion of the address (via the subnet mask), improving address utilization and isolating broadcast domains.

Worked example: Subnet 192.168.10.0/24 into 4 equal subnets.

  • Need 4 subnets → borrow n bits where 2^n ≥ 4 → n = 2 bits borrowed from the host portion.
  • New prefix = /24 + 2 = /26 → subnet mask = 255.255.255.192 (11000000 in last octet).
  • Block size = 2^(32-26) = 2^6 = 64 addresses per subnet.
SubnetNetwork AddressUsable Host RangeBroadcast Address
1192.168.10.0.1 – .62192.168.10.63
2192.168.10.64.65 – .126192.168.10.127
3192.168.10.128.129 – .190192.168.10.191
4192.168.10.192.193 – .254192.168.10.255

Each subnet provides 64−2 = 62 usable host addresses (excluding network and broadcast addresses), and the four blocks exactly partition the original /24 with no overlap.

Q15Explain CIDR (Classless Inter-Domain Routing) notation and prefix.

Ans: CIDR (Classless Inter-Domain Routing) replaces rigid classful addressing with a flexible "slash notation" address/prefix-length, where the prefix length explicitly states how many leading bits form the network portion, independent of class boundaries.

  • Notation: e.g. 203.0.113.0/26 means the first 26 bits are the network id, leaving 6 host bits (block size 64).
  • Variable Length Subnet Masking (VLSM): CIDR allows different-sized subnets to be carved from the same block, so a large ISP can allocate a /28 (16 addresses) to a small office and a /22 (1024 addresses) to a large enterprise from the same pool, minimising waste.
  • Route aggregation (supernetting): Multiple contiguous smaller blocks (e.g. four /24s) can be summarised into one larger route (a /22) in routing tables, reducing the size of global BGP routing tables.

Benefit over classful addressing: Classful addressing forced allocation in fixed chunks (/8, /16, /24) causing massive address waste (e.g., a 300-host organisation would need a full Class B of 65,534 addresses). CIDR allocates exactly the number of addresses needed and slowed IPv4 exhaustion while also shrinking core router routing tables through aggregation.

Q16Explain ARP (Address Resolution Protocol) request/reply workflow.

Ans: ARP (Address Resolution Protocol) maps a known IP (logical) address to its corresponding MAC (physical) address on a local network segment, since Data Link layer frames need MAC addresses for delivery.

A C B D ARP Request (Broadcast): "Who has IP of B?" ARP Reply (Unicast from B): "IP is at my MAC"
ARP request is broadcast to all hosts; only the owner (B) unicasts the reply

Workflow: (1) Host A checks its local ARP cache for the MAC of target IP; if absent, (2) A broadcasts an ARP Request frame (destination MAC = FF:FF:FF:FF:FF:FF) containing B's IP address to the whole LAN; (3) all hosts receive it but only host B, recognising its own IP, replies; (4) B sends a unicast ARP Reply containing its MAC address directly to A; (5) A caches this mapping (with a timeout) in its ARP table for future use, avoiding repeated broadcasts.

Q17Explain RARP, BOOTP, and DHCP protocols.

Ans: RARP, BOOTP, and DHCP are protocols that assist a host in obtaining IP configuration, evolving from RARP's minimal function to DHCP's fully automated configuration.

ProtocolFunctionLimitation / Improvement
RARP (Reverse ARP)Diskless workstation broadcasts its known MAC address to get its IP address from a RARP serverRequires a RARP server on every physical segment; provides only the IP, no subnet mask/gateway/DNS; operates at Data Link layer (needs new server per LAN)
BOOTP (Bootstrap Protocol)UDP/IP-based protocol providing IP address, subnet mask, gateway, and boot file location to diskless hosts at startupWorks across routers (uses UDP/IP), but configuration is static — mappings manually configured, no automatic lease/renewal
DHCP (Dynamic Host Config Protocol)Fully automatic, dynamic IP allocation with a lease time; also supplies subnet mask, default gateway, DNS serversSuperset of BOOTP (backward compatible); supports dynamic pools, lease renewal, and reclaiming unused addresses

DHCP operates via the well-known DORA sequence: Discover (client broadcasts) → Offer (server proposes an IP) → Request (client requests that IP) → Acknowledge (server confirms the lease), making it the modern standard for automatic network configuration.

Q18Explain Distance Vector Routing and Count-to-Infinity problem.

Ans: In Distance Vector Routing (e.g. RIP), each router maintains a vector of distances (hop counts) to every known destination and periodically shares this entire table with its directly connected neighbours only ("routing by rumour"), using the Bellman-Ford idea: D_x(y) = min_v { c(x,v) + D_v(y) }.

A B C 1 1
Chain A-B-C: if link B-C fails, count-to-infinity can occur

Count-to-Infinity problem: If link B–C fails, B initially sets its distance to C as infinite. But if A still (incorrectly, from stale info) advertises "I can reach C in 2 hops" (via B), B updates its own table to "reach C via A in 3 hops", A then updates to 4 hops via B, and so on — the two routers repeatedly increment the hop count toward infinity before converging, causing slow convergence and routing loops.

Solutions: Split Horizon (never advertise a route back to the neighbour it was learned from), Split Horizon with Poison Reverse (explicitly advertise that route as infinite/unreachable back to that neighbour), and setting a low maximum hop count (RIP uses 16 = infinity) to bound the problem.

Q19Explain Link State Routing and Dijkstra's Algorithm.

Ans: Link State Routing (e.g. OSPF) requires every router to know the complete network topology: each router floods "link-state advertisements" (its ID and the cost to each directly connected neighbour) to all other routers, so every router independently builds an identical topology graph and computes shortest paths using Dijkstra's algorithm.

Dijkstra(Graph, source s): for each vertex v: dist[v] = INFINITY, visited[v] = false dist[s] = 0 while there exists an unvisited vertex: u = unvisited vertex with minimum dist[u] mark u as visited for each neighbour v of u: if dist[u] + cost(u,v) < dist[v]: dist[v] = dist[u] + cost(u,v) prev[v] = u // dist[] now holds shortest cost from s to every vertex

Steps performed by each router: (1) Discover neighbours and measure link cost (HELLO protocol); (2) build a Link State Packet (LSP) describing its neighbours and costs; (3) flood the LSP reliably to all routers in the area; (4) each router uses received LSPs to construct the full topology graph; (5) run Dijkstra locally from itself as source to compute the shortest-path tree, from which the forwarding table is derived. Because every router computes routes independently from full topology knowledge (rather than second-hand distance vectors), link-state routing converges faster and avoids the count-to-infinity problem, at the cost of higher memory/CPU and flooding overhead.

Q20Explain ICMP protocol and Ping/Traceroute utility tools.

Ans: ICMP (Internet Control Message Protocol) is a Network-layer companion protocol to IP used to report errors and exchange diagnostic/control information (it does not carry user data); ICMP messages are themselves encapsulated inside IP packets.

Message TypePurpose
Echo Request / Echo ReplyUsed by Ping to test reachability and measure round-trip time
Destination UnreachableRouter/host cannot deliver the packet (network, host, port, or protocol unreachable)
Time ExceededTTL reached 0 before arrival — used by Traceroute
RedirectInforms host of a better next-hop route
Source Quench(Legacy) requests sender to slow down due to congestion

Ping sends ICMP Echo Request packets to a target; each Echo Reply confirms reachability and lets the sender compute round-trip time and packet loss.

Traceroute discovers the router path by sending packets with progressively increasing TTL (1, 2, 3, ...). Each router that decrements TTL to 0 discards the packet and returns an ICMP Time Exceeded message identifying itself; by incrementing TTL one hop at a time, traceroute reveals every intermediate router until the destination finally responds (or returns Port/Destination Unreachable for UDP-based traceroute), reconstructing the full path hop-by-hop.

Q21Explain TCP 3-Way Handshake connection establishment.

Ans: TCP establishes a reliable, full-duplex connection using a 3-way handshake before any application data flows, so both ends agree on initial sequence numbers.

Client Server SYN (seq=x) SYN+ACK (seq=y, ack=x+1) ACK (ack=y+1)
TCP 3-way handshake: SYN, SYN-ACK, ACK
  • Step 1 (SYN): Client sends a segment with the SYN flag set and an initial sequence number x, moving to the SYN_SENT state.
  • Step 2 (SYN+ACK): Server, in LISTEN state, replies with SYN and ACK flags set, its own initial sequence number y, and acknowledgement number x+1, moving to SYN_RCVD.
  • Step 3 (ACK): Client acknowledges with ACK flag and acknowledgement number y+1; both sides now move to ESTABLISHED and data transfer can begin.

This handshake synchronizes sequence numbers in both directions and confirms both endpoints are alive and willing to communicate, forming the basis of TCP's connection-oriented reliability.

Q22Explain TCP 4-Way Connection Termination.

Ans: TCP connection termination uses a 4-way handshake because TCP is full-duplex — each direction of the connection must be closed independently.

Client Server FIN ACK FIN ACK
TCP 4-way termination: FIN, ACK, FIN, ACK (independent close of each direction)
  • FIN (client→server): Client has no more data; sends FIN, moves to FIN_WAIT_1.
  • ACK (server→client): Server acknowledges the FIN; client moves to FIN_WAIT_2. Server can still send remaining data.
  • FIN (server→client): When server also finishes, it sends its own FIN; client moves to TIME_WAIT.
  • ACK (client→server): Client acknowledges; server moves to CLOSED. Client waits in TIME_WAIT (typically 2×MSL) before finally closing, to handle any delayed duplicate segments.
Q23Explain TCP Flow Control (Sliding Window) mechanism.

Ans: TCP uses a sliding window mechanism for flow control so a fast sender cannot overrun a slow receiver's buffer.

Sliding Window (rwnd) Sent & ACKed Sendable now Not yet sendable Window slides right as ACKs arrive
TCP sliding window: window size = receiver's advertised buffer space (rwnd)

Mechanism: Every ACK segment carries a receive window (rwnd) field advertising how many additional bytes the receiver's buffer can currently accept. The sender may transmit unacknowledged data up to this window size without waiting for individual ACKs (unlike Stop-and-Wait). As the receiver's application reads data out of the buffer, the receiver advertises a larger window in subsequent ACKs, "sliding" the window forward; if the receiver's buffer fills up, it advertises rwnd = 0 ("zero window"), pausing the sender until space frees up (checked later via window probes). This dynamically adapts the sending rate to the receiver's actual processing capacity — distinct from congestion control, which reacts to network capacity instead.

Q24Explain TCP Congestion Control: Slow Start, Congestion Avoidance.

Ans: TCP congestion control regulates how much data a sender injects into the network to avoid overwhelming routers, using a sender-side congestion window (cwnd), distinct from the receiver's flow-control window.

RTT rounds cwnd loss (ssthresh set) Slow Start (exponential) Congestion Avoidance (linear)
cwnd growth: exponential slow start, then linear (AIMD) congestion avoidance after loss
  • Slow Start: cwnd starts at 1 MSS and doubles every RTT (cwnd += MSS per ACK) — exponential growth — until it reaches ssthresh (slow-start threshold) or a loss occurs.
  • Congestion Avoidance: Once cwnd ≥ ssthresh, growth becomes additive — roughly +1 MSS per RTT (AIMD: Additive Increase) — to probe capacity cautiously.
  • On packet loss (timeout): ssthresh is set to cwnd/2, and cwnd resets to 1 MSS, restarting Slow Start (Multiplicative Decrease).
  • Fast Retransmit / Fast Recovery: On 3 duplicate ACKs (implying an isolated loss, network not fully congested), the sender retransmits immediately without waiting for a timeout, sets ssthresh = cwnd/2, and cwnd = ssthresh (skipping full Slow Start).
Q25Explain Leaky Bucket Algorithm for traffic shaping.

Ans: The Leaky Bucket algorithm shapes bursty traffic into a fixed-rate output stream, analogous to a bucket with a small hole: water (data) leaks out at a constant rate regardless of how fast it pours in.

Bursty input packets Queue (bucket) Constant-rate output
Leaky Bucket: irregular arrivals queued and released at a fixed rate; excess overflow is dropped

Working: Incoming packets are placed in a finite-size queue (the "bucket"). The network interface removes and transmits one packet (or a fixed number of bytes) from the queue at a constant, fixed output rate, irrespective of the input burst rate. If the bucket (queue) is full when a new packet arrives, that packet is discarded (or marked). This strictly smooths bursty traffic into a uniform stream, protecting downstream routers from congestion, but it is rigid — even if the network is idle, output cannot exceed the fixed rate, so brief legitimate bursts are needlessly delayed or dropped (a limitation solved by the Token Bucket algorithm).

Q26Explain Token Bucket Algorithm for bursty traffic.

Ans: The Token Bucket algorithm allows bursty transmission (unlike the rigid Leaky Bucket) by permitting a host to send as fast as it wants as long as it has accumulated "tokens" (permission credits).

Tokens generated at rate r Token bucket (capacity C) Packet sent only if enough tokens available consume tokens
Token Bucket: tokens accumulate at rate r up to capacity C, allowing controlled bursts

Working: Tokens are added to a bucket of capacity C at a fixed rate r tokens/sec. A packet (or byte) can only be transmitted if a matching token is available, in which case one token is removed; if the bucket has accumulated many tokens (during an idle period), a burst of packets can be sent back-to-back up to the bucket's capacity. If no tokens are available, the packet must wait (or is dropped/marked non-conforming). This allows the average rate to still be bounded by r while accommodating short bursts up to C — the maximum burst size for capacity C, arrival rate r, and output rate M is given by S = C / (M − r) seconds, making Token Bucket more flexible than Leaky Bucket for real, bursty network traffic.

Q27Explain Domain Name System (DNS) hierarchy and resolution.

Ans: DNS (Domain Name System) is a distributed, hierarchical, tree-structured naming system that translates human-readable domain names (e.g. www.example.com) into IP addresses.

Root (.) TLD .com TLD .org Authoritativeexample.com
DNS hierarchy: Root → TLD (.com/.org) → Authoritative name servers for each domain

Hierarchy: Root servers (13 logical root server clusters) know the addresses of all TLD (Top-Level Domain) servers (.com, .org, .in, etc.); each TLD server knows the authoritative name servers for domains registered under it (e.g. example.com); the authoritative server holds the actual resource records for that domain.

Resolution: A client's resolver (usually at the ISP) is queried recursively by the application; the resolver then queries root → TLD → authoritative servers iteratively (each referring it to the next level) until it obtains the final IP address, which is cached (per TTL) and returned to the client — combining a recursive query from client-to-resolver with iterative queries from resolver onward reduces load on upper-tier servers.

Q28Explain HTTP vs HTTPS protocols (Port 80 vs Port 443).

Ans: HTTP and HTTPS are Application-layer protocols for web communication; HTTPS is HTTP layered over TLS/SSL encryption.

BasisHTTPHTTPS
Full formHyperText Transfer ProtocolHTTP Secure (HTTP over TLS/SSL)
Port80443
SecurityPlaintext — data readable by any eavesdropperEncrypted using TLS — confidentiality, integrity, and server authentication
CertificateNot requiredRequires a digital certificate (issued by a CA) to establish trust
PerformanceSlightly faster (no encryption/handshake overhead)Marginal overhead from TLS handshake, negligible with modern session resumption/HTTP2
URL schemehttp://https:// (padlock icon shown by browsers)

HTTPS wraps every HTTP request/response inside a TLS record after a TLS handshake (certificate exchange, key negotiation) is completed, so intermediate routers/ISPs can see that a connection exists but cannot read the URL path, headers, or body content — essential for protecting logins, payments, and any sensitive data in transit.

Q29Explain FTP (File Transfer Protocol) dual connection (Data & Control).

Ans: FTP (File Transfer Protocol) is unusual among Application-layer protocols in that it uses two separate TCP connections — one for control (commands) and one for the actual data.

FTP Client FTP Server Control Conn. (Port 21) Data Conn. (Port 20 active)
FTP dual connections: persistent control channel + separate data channel per transfer
  • Control Connection (Port 21): Remains open for the entire session; carries commands (USER, PASS, LIST, RETR, STOR) and server replies (status codes).
  • Data Connection (Port 20 in Active mode, or negotiated port in Passive mode): Opened separately for each file transfer or directory listing, then closed once that transfer completes.
  • Active mode: Server initiates the data connection back to the client (can be blocked by client-side firewalls/NAT).
  • Passive mode: Client initiates both connections to the server, which is more NAT/firewall friendly and common in modern usage.

Separating control and data allows commands to be exchanged (e.g. aborting a transfer) even while a large file transfer is in progress on the data channel.

Q30Explain Email Protocols: SMTP, POP3, IMAP.

Ans: Email delivery uses different protocols for sending versus retrieving mail.

ProtocolRolePortKey Characteristic
SMTP (Simple Mail Transfer Protocol)Sends mail from client → mail server, and relays server → server25 (relay), 587 (submission)Push protocol; only used to send/relay, not to read mail
POP3 (Post Office Protocol v3)Retrieves mail from server to a single client110 (995 secure)Downloads and typically deletes mail from server; simple, no server-side folder sync
IMAP (Internet Message Access Protocol)Retrieves and manages mail while keeping it on the server143 (993 secure)Mail stays on server; supports folders, flags, and multi-device synchronization

A typical flow: sender's mail client uses SMTP to push a message to its outgoing mail server, which relays it (via further SMTP hops, possibly through MX-record lookups) to the recipient's mail server; the recipient's client then uses POP3 (download-and-delete, single-device) or IMAP (server-synced, multi-device) to fetch the message from the mailbox.

Q31Explain Network Devices: Hub, Switch, Router, Bridge, Gateway.

Ans: Network devices operate at different OSI layers and provide progressively more intelligent traffic handling.

DeviceOSI LayerFunction
HubPhysical (L1)Simply repeats/broadcasts incoming electrical signal to all ports; no addressing intelligence, creates one large collision domain
SwitchData Link (L2)Forwards frames based on learned MAC address table; each port is a separate collision domain, reduces unnecessary traffic vs a hub
BridgeData Link (L2)Connects two LAN segments, filters traffic by MAC address to reduce collision domain size (conceptually a 2-port switch)
RouterNetwork (L3)Forwards packets between different networks based on IP address, using a routing table; separates broadcast domains
GatewayAll layers (up to Application)Connects networks using different protocol stacks entirely (e.g. converts between different application protocols), performing protocol translation

Overall intelligence increases with layer: a Hub is "dumb" broadcast repetition, a Switch/Bridge make forwarding decisions using MAC addresses, a Router makes decisions using IP addresses and can connect dissimilar networks, and a Gateway can translate between entirely different protocol stacks (e.g. an email gateway between SMTP and a proprietary messaging system).

Q32Explain IPv6 Header format and benefits over IPv4.

Ans: IPv6 uses 128-bit addresses and a simplified, fixed 40-byte header (versus IPv4's variable 20-60 byte header) to speed up router processing.

FieldSizePurpose
Version4 bitsAlways 6
Traffic Class8 bitsQoS / DSCP marking (like IPv4 ToS)
Flow Label20 bitsIdentifies packets belonging to the same flow for special handling
Payload Length16 bitsLength of data following the header
Next Header8 bitsIdentifies the following extension header or upper-layer protocol (replaces IPv4's Protocol + Options)
Hop Limit8 bitsEquivalent to IPv4's TTL
Source / Destination Address128 bits eachVastly larger address space (2^128)

Benefits over IPv4: (1) Enormous address space (2^128 vs 2^32) solving exhaustion; (2) simplified fixed header speeds up router processing (no header checksum, no in-network fragmentation — routers no longer fragment, source must use Path MTU Discovery); (3) built-in support for auto-configuration (SLAAC) and IPsec; (4) extension headers (instead of IPv4 options) keep the base header simple while allowing optional features; (5) native multicast/anycast support, eliminating the need for broadcast.

Q33Explain Wireless LAN (IEEE 802.11) architecture.

Ans: IEEE 802.11 defines the architecture for Wireless LANs, built around the concept of a Basic Service Set.

BSS 1 AP STA STA BSS 2 AP STA DS
Two BSSs connected via a Distribution System form an ESS
  • Station (STA): Any device with a wireless network interface.
  • Access Point (AP): Bridges wireless stations to the wired network; base station of infrastructure mode.
  • BSS (Basic Service Set): A group of stations controlled by one AP (infrastructure BSS) or communicating directly (Independent BSS / ad-hoc).
  • DS (Distribution System): The backbone (usually wired Ethernet) connecting multiple APs.
  • ESS (Extended Service Set): Multiple BSSs connected via a DS, sharing the same SSID, enabling roaming between APs.
Q34Explain Bluetooth Architecture: Piconet and Scatternet.

Ans: Bluetooth (IEEE 802.15.1) is a short-range wireless technology organised around small ad-hoc networks called piconets.

Master Slave Slave Slave Piconet 1 Master Slave Piconet 2 shared node links piconets
A shared device (master of one, slave of another) links two piconets into a scatternet
  • Piconet: A small network of up to 8 active devices — 1 master and up to 7 slaves — all synchronized to the master's clock and frequency-hopping sequence. The master controls channel access and timing for all slaves.
  • Scatternet: Formed when a device participates in more than one piconet simultaneously (as a slave in one and master or slave in another), interconnecting multiple piconets into a larger, ad-hoc mesh-like network, extending coverage beyond a single piconet's range.
Q35Explain NAT (Network Address Translation) and PAT.

Ans: NAT (Network Address Translation) allows multiple devices on a private network to share a single public IP address when accessing the Internet, conserving scarce public IPv4 addresses.

10.0.0.2 10.0.0.3 10.0.0.4 NAT Router203.0.113.5 Public Internet
NAT/PAT: multiple private IPs mapped to one public IP, differentiated by port

NAT: Translates a private source IP address (e.g. 10.0.0.2) into the router's public IP (203.0.113.5) in outgoing packets, and reverses the mapping for return traffic, using a translation table.

PAT (Port Address Translation, "NAT overload"): Since one public IP alone cannot distinguish multiple internal hosts, PAT additionally rewrites the source port number for each connection, so the router's translation table maps (private-IP, private-port) ↔ (public-IP, unique-public-port). This lets hundreds of internal hosts share one public IP simultaneously, which is why PAT is the mechanism actually used in almost every home/office router today.

Q36Explain Symmetric vs Asymmetric Cryptography.

Ans: Cryptography secures data using either a shared secret key (symmetric) or a mathematically linked key pair (asymmetric).

BasisSymmetric CryptographyAsymmetric Cryptography
Keys usedSingle shared secret key for both encryption and decryptionKey pair — public key (encrypt/verify) and private key (decrypt/sign)
SpeedFast, low computational overheadMuch slower, computationally intensive (large modular exponentiations)
Key distributionHard — the secret key itself must be shared securely beforehandEasy — public key can be freely distributed; private key never leaves owner
Key count (n users)n(n−1)/2 keys needed for pairwise secure communicationOnly 2n keys (one pair per user)
ExamplesAES, DES, 3DES, RC4RSA, ECC, Diffie-Hellman
Typical useBulk data encryption (actual payload)Key exchange, digital signatures, certificates

In practice, protocols like TLS use a hybrid approach: asymmetric cryptography securely negotiates/exchanges a temporary symmetric session key during the handshake, then fast symmetric encryption (e.g. AES) protects the bulk of the actual data — combining asymmetric key-management convenience with symmetric encryption speed.

Q37Explain RSA Public Key Cryptography algorithm.

Ans: RSA is an asymmetric-key algorithm whose security rests on the practical difficulty of factoring the product of two large primes.

Key Generation: 1. Choose two large primes p, q 2. Compute n = p * q (modulus, part of both keys) 3. Compute phi(n) = (p-1)(q-1) (Euler's totient) 4. Choose e such that 1 < e < phi(n) and gcd(e, phi(n)) = 1 (public exponent) 5. Compute d such that (d * e) mod phi(n) = 1 (private exponent, modular inverse of e) 6. Public Key = (e, n) Private Key = (d, n) Encryption: C = M^e mod n (sender uses receiver's public key) Decryption: M = C^d mod n (receiver uses own private key)

Why it is secure: Given only the public key (e, n), an attacker would need to factor n back into p and q to derive phi(n) and hence the private key d — for sufficiently large primes (2048+ bits) this factorization is computationally infeasible with current classical computers, even though multiplying p×q to get n was trivial. RSA is also used for digital signatures (sign with private key: S = M^d mod n; verify with public key: M = S^e mod n), providing authentication and non-repudiation in addition to confidentiality.

Q38Explain Firewall types: Packet Filter, Stateful Inspection, Proxy.

Ans: A firewall enforces a security policy by controlling traffic between a trusted internal network and an untrusted external network; different types inspect traffic at different depths.

TypeOSI LayerInspection BasisLimitation
Packet Filtering FirewallNetwork/TransportStatic rules on source/destination IP, port, protocol per packet, independentlyNo memory of connection state; vulnerable to spoofing and cannot detect application-layer attacks
Stateful Inspection FirewallNetwork/TransportMaintains a connection-state table; only allows packets matching an established, legitimate sessionHigher resource usage than packet filters; still limited application-layer visibility
Proxy (Application-level) FirewallApplicationTerminates the client connection itself and opens a new connection to the destination on the client's behalf, fully inspecting application data (e.g. HTTP content)Highest overhead/latency; needs a separate proxy per application protocol

Modern deployments typically layer these: stateful packet filtering at the network perimeter for speed, combined with application-layer proxies/deep packet inspection for sensitive services (e.g. web application firewalls), balancing performance against depth of inspection.

Q39Explain Quality of Service (QoS) parameters and techniques.

Ans: Quality of Service (QoS) refers to a network's ability to provide differentiated, predictable performance guarantees for different traffic types (e.g. prioritising live video call packets over a background file download).

QoS ParameterMeaningSensitive Applications
Bandwidth (Throughput)Data rate available to a flowFile transfer, video streaming
Delay (Latency)Time for a packet to travel from source to destinationInteractive voice/video calls, gaming
JitterVariation in packet delayVoIP, live video (needs jitter buffers)
Packet LossFraction of packets that fail to arriveAll, especially real-time streams (no time to retransmit)

Techniques:

  • Traffic Shaping/Policing: Leaky Bucket / Token Bucket to smooth or bound traffic to agreed rates.
  • Scheduling: Priority Queuing, Weighted Fair Queuing (WFQ) to give preferential service to high-priority flows.
  • Admission Control: Reject/renegotiate new flows if resources cannot meet their requirements.
  • DiffServ / IntServ: DiffServ marks packets with a per-hop-behaviour class (DSCP field); IntServ (RSVP) reserves resources end-to-end per flow.
Q40Explain Socket Programming concepts (IP, Port, Socket API).

Ans: A socket is the Application layer's programming abstraction for a network communication endpoint, uniquely identified by the tuple (IP address, Port number, Protocol).

  • IP Address: Identifies the host on the network (Network layer address).
  • Port Number: A 16-bit number (0-65535) identifying the specific process/application on that host (e.g. port 80 for HTTP, port 443 for HTTPS); well-known ports (0-1023) are reserved for standard services.
  • Socket API: The set of system calls (originating from Berkeley/BSD sockets) that let applications create and use sockets over TCP (stream, connection-oriented) or UDP (datagram, connectionless).
// TCP Server (pseudocode) sock = socket(AF_INET, SOCK_STREAM) // create TCP socket bind(sock, IP, PORT) // bind to local address+port listen(sock, backlog) // mark socket as passive/listening conn = accept(sock) // block until a client connects data = recv(conn, buffer_size) // receive data send(conn, response) // send response close(conn) // TCP Client (pseudocode) sock = socket(AF_INET, SOCK_STREAM) connect(sock, SERVER_IP, SERVER_PORT) // 3-way handshake happens here send(sock, request) data = recv(sock, buffer_size) close(sock)

UDP sockets use SOCK_DGRAM instead, and skip connect()/listen()/accept() — data is exchanged directly using sendto()/recvfrom() since UDP is connectionless.

Group C — Long / Numerical Questions (15 Marks Each)

Q1a) Data bits = 1101011011, Generator polynomial G(x) = x^4 + x + 1 (10011). Calculate CRC checksum and transmitted frame. b) Explain Sliding Window Protocols efficiency: Stop-and-Wait vs Go-Back-N vs Selective Repeat.

Part (a): CRC Calculation

Data M = 1101011011 (10 bits). Generator G(x) = x^4+x+1 → bit pattern 10011 (5 bits, so degree r = 4). Append 4 zero bits to M and perform modulo-2 (XOR) division by G:

Dividend (M + 4 zeros): 11010110110000 1 1 0 1 0 1 1 0 1 1 0 0 0 0 1 0 0 1 1 ----------- 0 1 1 1 1 1 1 0 1 1 0 0 0 0 1 0 0 1 1 --------- 0 1 1 0 0 1 1 0 1 1 0 0 0 0 (shift, bring next bit; leading 0 skipped) 1 0 0 1 1 --------- 0 1 0 1 1 0 1 1 0 0 0 0 1 0 0 1 1 --------- 0 0 1 0 1 1 0 0 0 0 1 0 0 1 1 --------- 0 0 1 1 1 0 0 0 1 0 0 1 1 --------- 0 1 1 1 0 0 1 0 0 1 1 --------- Remainder = 1 1 1 0 CRC checksum = 1110 Transmitted frame = M + CRC = 1101011011 1110 = 11010110111110

Verification: dividing the full transmitted codeword 11010110111110 by G = 10011 gives remainder 0000, confirming the CRC is correct (the receiver performs exactly this check — a non-zero remainder signals a transmission error).

Part (b): Sliding Window Protocol Efficiency

Let Tt = transmission time, Tp = propagation delay, a = Tp/Tt, and m = sequence number field width.

ProtocolWindow SizeEfficiencyRemark
Stop-and-Wait11/(1+2a)Sender idle after every frame; very poor for large a (e.g. satellite links)
Go-Back-N2^m - 1min(1, N/(1+2a))Pipelines frames; one lost frame forces resending the whole window (bandwidth waste on lossy links)
Selective Repeat2^(m-1)min(1, N/(1+2a)) with smaller NOnly the lost frame is retransmitted; most bandwidth-efficient but needs more receiver buffering/logic

When window size N ≥ 1+2a, the sender never has to pause and efficiency approaches 100%. Go-Back-N and Selective Repeat both pipeline frames to overcome Stop-and-Wait's idle-time problem, but Selective Repeat degrades more gracefully under errors since it avoids needless retransmission of already-correctly-received frames.

Q2a) An IP block 192.168.1.0/24 is divided into 4 equal subnets. 1. Subnet mask. 2. Network address, Broadcast address, Usable Host IP range for each subnet. b) Explain Classless Inter-Domain Routing (CIDR) advantages.

Part (a): Subnetting 192.168.1.0/24 into 4 equal subnets

To create 4 equal subnets, borrow n host bits where 2^n ≥ 4 → n = 2. New prefix = /24 + 2 = /26.

1. Subnet mask: /26 → 255.255.255.192 (last octet = 11000000).

2. Block size = 2^(32-26) = 2^6 = 64 addresses per subnet.

SubnetNetwork AddressUsable Host RangeBroadcast Address
Subnet 1192.168.1.0192.168.1.1 – 192.168.1.62192.168.1.63
Subnet 2192.168.1.64192.168.1.65 – 192.168.1.126192.168.1.127
Subnet 3192.168.1.128192.168.1.129 – 192.168.1.190192.168.1.191
Subnet 4192.168.1.192192.168.1.193 – 192.168.1.254192.168.1.255

Verification: the four blocks (0-63, 64-127, 128-191, 192-255) exactly partition the original 256 addresses of the /24 with no overlap and no gap; each subnet gives 64−2 = 62 usable hosts after excluding the network and broadcast address.

Part (b): CIDR Advantages

  • Efficient address allocation: Blocks are sized to actual need (e.g. /26 for 62 hosts) instead of wasteful fixed classful sizes (/24 = 254 hosts minimum), slowing IPv4 exhaustion.
  • Route aggregation (supernetting): Multiple contiguous smaller blocks can be summarised into a single, larger routing table entry, reducing the size of core/BGP routing tables and speeding up lookups.
  • VLSM support: Different subnets within the same organisation can have different sizes matched to their host counts, unlike classful addressing.
  • Simplified, class-independent design: Removes the rigid class A/B/C boundary, giving ISPs and administrators full flexibility in prefix length choice.
Q3a) Apply Dijkstra's Algorithm to find shortest path from node A to all other nodes in a given 6-node weighted network graph. b) Compare Distance Vector Routing vs Link State Routing.

Part (a): Dijkstra's Shortest Path from A

Since the exact edge weights are not reproduced in this extracted question, a representative 6-node weighted graph (A–F) is used to fully demonstrate the algorithm, with edges: A-B=4, A-C=2, B-C=1, B-D=5, C-D=8, C-E=10, D-E=2, D-F=6, E-F=3.

A C B D E F 4 2 1 5 8 10 2 6 3
Assumed 6-node weighted graph used for the Dijkstra trace
StepVertex Selecteddist[A]dist[B]dist[C]dist[D]dist[E]dist[F]
0 (init)0
1A (0)042
2C (2)03 (via C)21012
3B (3)0328 (via B)12
4D (8)032810 (via D)14
5E (10)03281013 (via E)
6F (13)All vertices settled

Final shortest distances from A: A=0, C=2, B=3, D=8, E=10, F=13, with shortest-path tree edges A-C, C-B, B-D, D-E, E-F (each relaxation step only updates a distance when a shorter path is found, verified consistent since every non-source node's final distance equals its parent's distance plus the connecting edge weight).

Part (b): Distance Vector vs Link State Routing

BasisDistance VectorLink State
Information sharedEntire distance table, shared only with neighboursOwn link costs only, flooded to all routers in the area
Topology knowledgeOnly knows distance to destinations, not full topologyEvery router builds the complete network topology
AlgorithmDistributed Bellman-FordDijkstra's shortest path (run locally by each router)
ConvergenceSlow; prone to count-to-infinity / routing loopsFast; loop-free by construction
OverheadLower CPU/memory, but slower convergenceHigher CPU/memory (full topology + Dijkstra), but converges quickly
Example protocolRIPOSPF, IS-IS
Q4a) Explain TCP Congestion Control Algorithms in detail: Slow Start, Congestion Avoidance, Fast Retransmit, Fast Recovery. b) Draw Congestion Window Size graph over transmission rounds.

Part (a): TCP Congestion Control Algorithms

  • Slow Start: cwnd initialised to 1 MSS; for every ACK received, cwnd increases by 1 MSS, which doubles cwnd every RTT (exponential growth) — a deliberately fast ramp-up from a cold start. Continues until cwnd reaches ssthresh or a loss is detected.
  • Congestion Avoidance: Once cwnd ≥ ssthresh, growth switches to additive: cwnd increases by roughly 1 MSS per RTT (approximated as +MSS×MSS/cwnd per ACK), cautiously probing for more available capacity — the "Additive Increase" half of AIMD.
  • Fast Retransmit: On receiving 3 duplicate ACKs (a strong signal that a single segment was lost but later segments are arriving fine, i.e. no full congestion collapse), the sender retransmits the missing segment immediately without waiting for the retransmission timer to expire.
  • Fast Recovery: After fast retransmit, instead of dropping cwnd all the way to 1 MSS (as on a timeout), ssthresh is set to cwnd/2 and cwnd is set to ssthresh (+3 MSS for the duplicate ACKs already received), resuming congestion avoidance directly — avoiding an unnecessary return to slow start.
  • Timeout (severe loss): ssthresh = cwnd/2, cwnd resets to 1 MSS, and Slow Start restarts from scratch ("Multiplicative Decrease").

Part (b): Congestion Window Graph

Round (RTT) cwnd ssthresh Slow Start Congestion Avoidance loss (3 dup ACKs) Fast Recovery
cwnd vs transmission round: exponential Slow Start, linear Congestion Avoidance, dip and quick recovery after a fast-retransmit event

The graph shows cwnd doubling every round during slow start (exponential curve) up to ssthresh, then growing linearly (~+1 MSS/RTT) during congestion avoidance (a classic "sawtooth" pattern seen repeatedly over the connection's life), with a sharp halving (not a full reset to 1) followed by linear growth when loss is detected via duplicate ACKs (fast recovery) — versus a full drop to cwnd=1 and restart of slow start after a timeout.

Q5a) Explain RSA Asymmetric Encryption Algorithm with a numerical example (p=61, q=53, e=17). b) Explain Digital Signatures and SSL/TLS Handshake Protocol.

Part (a): RSA Numerical Example (p=61, q=53, e=17)

Step 1: n = p * q = 61 * 53 = 3233 Step 2: phi(n) = (p-1)(q-1) = 60 * 52 = 3120 Step 3: Given e = 17. Check gcd(17, 3120) = 1 -> valid public exponent Step 4: Find d = e^-1 mod phi(n), i.e. (17 * d) mod 3120 = 1 Using Extended Euclidean Algorithm: d = 2753 Check: 17 * 2753 = 46801 = 15*3120 + 1 -> remainder 1 (correct) Public Key = (e, n) = (17, 3233) Private Key = (d, n) = (2753, 3233) Encryption example, Plaintext M = 65: C = M^e mod n = 65^17 mod 3233 = 2790 Decryption: M = C^d mod n = 2790^2753 mod 3233 = 65 (original message recovered)

This confirms the key pair is mathematically consistent: encrypting with the public key (17, 3233) and decrypting with the private key (2753, 3233) recovers the exact original plaintext, and the security relies on the fact that recovering d from the public (e, n) alone requires factoring n = 3233 back into 61 × 53, which becomes computationally infeasible for realistic (2048-bit+) primes.

Part (b): Digital Signatures and SSL/TLS Handshake

Digital Signature: The sender computes a hash of the message, then encrypts the hash with their private key (S = Hash(M)^d mod n) to produce a signature. The receiver decrypts the signature with the sender's public key and compares it against an independently computed hash of the received message; a match proves authenticity (only the private-key holder could have produced it) and integrity (any tampering changes the hash), and non-repudiation (the sender cannot later deny signing it).

SSL/TLS Handshake (simplified):

  1. ClientHello: Client sends supported TLS versions, cipher suites, and a random nonce.
  2. ServerHello + Certificate: Server responds with chosen cipher suite, its own nonce, and its digital certificate (containing its public key, signed by a trusted CA).
  3. Key Exchange: Client verifies the certificate against trusted CAs, then generates a pre-master secret, encrypts it with the server's public key (or uses Diffie-Hellman) and sends it over.
  4. Session Keys Derived: Both sides independently derive the same symmetric session keys from the pre-master secret and exchanged nonces.
  5. Finished: Both sides send a Finished message (MAC-protected) to confirm the handshake succeeded; all further application data is encrypted using the fast symmetric session key (a hybrid cryptosystem — asymmetric for key exchange, symmetric for bulk data).
Q6a) Construct 7-bit Hamming Code for 4-bit data 1011. b) Show error detection and correction if 3rd bit is flipped during transmission.

Part (a): 7-bit Hamming Code for data 1011

4 data bits d1d2d3d4 = 1,0,1,1 need 3 parity bits (r) satisfying 2^r ≥ m+r+1 → r=3 (2^3=8 ≥ 4+3+1=8). Parity bits p1,p2,p4 are placed at positions 1,2,4; data bits occupy positions 3,5,6,7.

Position1234567
Bitp1p2d1=1p4d2=0d3=1d4=1
p1 (covers 1,3,5,7) = d1 XOR d2 XOR d4 = 1 XOR 0 XOR 1 = 0 p2 (covers 2,3,6,7) = d1 XOR d3 XOR d4 = 1 XOR 1 XOR 1 = 1 p4 (covers 4,5,6,7) = d2 XOR d3 XOR d4 = 0 XOR 1 XOR 1 = 0 Transmitted 7-bit Hamming code (positions 1-7) = 0 1 1 0 0 1 1

Part (b): Error Detection and Correction (3rd bit flipped)

Transmitted code: 0 1 1 0 0 1 1. Bit at position 3 (originally d1=1) is flipped to 0 during transmission, so the received code is: 0 1 0 0 0 1 1.

Receiver recomputes 3 check bits (syndrome): c1 = pos1 XOR pos3 XOR pos5 XOR pos7 = 0 XOR 0 XOR 0 XOR 1 = 1 c2 = pos2 XOR pos3 XOR pos6 XOR pos7 = 1 XOR 0 XOR 1 XOR 1 = 1 c4 = pos4 XOR pos5 XOR pos6 XOR pos7 = 0 XOR 0 XOR 1 XOR 1 = 0 Syndrome = c4 c2 c1 = 0 1 1 (binary) = 3 (decimal)

The syndrome value 3 directly points to position 3 as the erroneous bit. The receiver flips position 3 back (0 → 1), recovering the original transmitted code 0110011, from which the original data bits (positions 3,5,6,7) = 1,0,1,1 are correctly extracted — demonstrating Hamming code's single-bit error correction capability without needing retransmission.

Q7a) Explain CSMA/CD protocol timing constraint formula `T_frame >= 2 * T_prop`. b) Derive minimum frame size requirement for 1Gbps Ethernet over 1km link.

Part (a): CSMA/CD Timing Constraint

For a transmitting station to reliably detect a collision, it must still be transmitting when the collision signal (from the farthest station) propagates back to it. This gives the constraint:

T_frame >= 2 * T_prop where: T_frame = time to transmit the minimum-size frame = FrameSize / DataRate T_prop = one-way propagation delay between the two most distant stations 2*T_prop = worst-case round-trip time for the collision signal to return

If a frame is transmitted in less time than 2*T_prop, the sender could finish transmitting and assume success before a collision signal (created near the far end of the cable, just as the frame was arriving there) has time to propagate back — the sender would never detect it. This is why Ethernet mandates a minimum frame size (64 bytes for classic 10/100 Mbps Ethernet) for a given cable length/data rate.

Part (b): Minimum Frame Size for 1 Gbps Ethernet over 1 km

Assume signal propagation speed v ≈ 2 × 10^8 m/s (typical for copper/fiber, about 2/3 the speed of light).

One-way propagation delay: T_prop = distance / speed = 1000 m / (2 x 10^8 m/s) = 5 x 10^-6 s = 5 microseconds Round-trip (worst case): 2 * T_prop = 10 microseconds = 10 x 10^-6 s Minimum frame transmission time required: T_frame(min) = 2 * T_prop = 10 x 10^-6 s Minimum frame size: Size(min) = Data Rate * T_frame(min) = (1 x 10^9 bits/s) * (10 x 10^-6 s) = 10,000 bits = 1250 bytes

Result: for a 1 Gbps link over a 1 km span, the minimum Ethernet frame size must be at least 10,000 bits (1250 bytes) — dramatically larger than the 64-byte minimum used at 10 Mbps, which is exactly why Gigabit Ethernet over shared/half-duplex media required "carrier extension" padding, and why virtually all modern Gigabit+ Ethernet instead runs full-duplex (switched, point-to-point), making CSMA/CD's collision-detection constraint obsolete in practice.

Q8a) Explain Subnetting and Supernetting with numerical examples. b) Aggregate 4 class C networks 200.10.0.0/24, 200.10.1.0/24, 200.10.2.0/24, 200.10.3.0/24 into a single CIDR block.

Part (a): Subnetting and Supernetting with Numerical Examples

Subnetting divides one large network into smaller sub-networks by extending the network prefix (borrowing host bits) — e.g. splitting 192.168.1.0/24 into four /26 subnets of 64 addresses each (see worked example in Q2), used when an organisation needs to segment a large block into smaller, isolated broadcast domains.

Supernetting (Route Aggregation) is the reverse: combining multiple contiguous smaller network blocks into a single larger block with a shorter prefix, so they can be advertised as one routing table entry — used by ISPs to keep backbone routing tables small.

Part (b): Aggregating 4 Class C Networks into a Single CIDR Block

Given: 200.10.0.0/24, 200.10.1.0/24, 200.10.2.0/24, 200.10.3.0/24.

Third octet in binary: 0 = 00000000 1 = 00000001 2 = 00000010 3 = 00000011 ^^^^^^-- these leading 6 bits (000000) are common to all four Common prefix length = 24 (first 3 octets fully shared: 200.10) + 6 bits of the third octet = 22 bits total. Aggregated block: 200.10.0.0/22 Subnet mask: 255.255.252.0 Total addresses: 2^(32-22) = 2^10 = 1024 (= 4 x 256, matches the 4 merged /24s) Address range: 200.10.0.0 - 200.10.3.255

Verification: the four original /24 blocks (200.10.0.x, .1.x, .2.x, .3.x) are contiguous and power-of-2 aligned (starting at a multiple of 4 in the third octet), so they aggregate exactly and losslessly into 200.10.0.0/22 with no address left out and no overlap with adjacent blocks (e.g. 200.10.4.0/24 remains outside this supernet) — this route summarisation lets a single BGP/OSPF advertisement replace 4 separate ones.

Q9a) Explain Distance Vector Routing Bellman-Ford algorithm. b) Illustrate Count-to-Infinity problem and solutions: Split Horizon and Poison Reverse.

Part (a): Distance Vector Routing — Bellman-Ford Algorithm

Each router x maintains a distance vector D_x giving its current best-known distance to every destination. It periodically exchanges this entire vector with directly connected neighbours only, and updates using the Bellman-Ford relation:

D_x(y) = min over all neighbours v of { c(x,v) + D_v(y) } Algorithm (run continuously at each node x): 1. Initialize D_x(x) = 0; D_x(y) = infinity for all other y 2. Send D_x to all directly connected neighbours 3. On receiving neighbour v's vector D_v: for each destination y: if c(x,v) + D_v(y) < D_x(y): D_x(y) = c(x,v) + D_v(y) next_hop(y) = v 4. If D_x changed, re-advertise D_x to all neighbours 5. Repeat until no further changes (convergence)

This is a fully distributed, asynchronous, iterative algorithm — no router needs global topology knowledge, only what its immediate neighbours tell it, which is computationally cheap but slow to converge and prone to routing loops during transients.

Part (b): Count-to-Infinity Problem, Split Horizon, Poison Reverse

Consider a chain A—B—C where the link B–C fails. B correctly sets D_B(C)=∞. But if A still advertises its stale route "D_A(C)=2 (via B)" before learning of the failure, B (seeing a route to C via A) updates D_B(C) = c(B,A)+D_A(C) = 1+2 = 3. B re-advertises this to A, which now updates D_A(C) = 1+3 = 4, and so on — both routers keep incrementing the hop count toward infinity in small steps, taking many exchange rounds to finally stabilize (RIP defines 16 as "infinity" to bound this).

  • Split Horizon: A router never advertises a route back to the same neighbour it learned that route from (since B learned about C via nobody else, A should never have re-advertised its route to C back toward B in the first place if it originally learned it through B).
  • Split Horizon with Poison Reverse: Stronger version — instead of simply omitting the route, the router explicitly advertises that destination as unreachable (distance = ∞) back to the neighbour it was learned from, actively breaking the loop rather than passively hiding it, which converges faster.

These heuristics solve two-node loops effectively but do not fully eliminate looping in more complex topologies (3+ node loops), which is one reason link-state protocols are preferred in larger networks.

Q10a) Explain Border Gateway Protocol (BGP) Path Vector routing. b) Differentiate Interior Gateway Protocols (RIP, OSPF) vs Exterior Gateway Protocols (BGP).

Part (a): BGP Path Vector Routing

BGP (Border Gateway Protocol) is the exterior routing protocol that connects autonomous systems (AS) across the Internet. Unlike distance vector (which shares only a cost) or link state (which floods full topology), BGP is a Path Vector protocol: each route advertisement carries the complete ordered list of AS numbers (the "AS-PATH") that must be traversed to reach the destination, not just a metric.

  • A BGP router advertises reachable prefixes to its peers along with the AS-PATH attribute (its own AS number prepended to the path it received).
  • Loop prevention is trivial and robust: if a router sees its own AS number already present in an incoming AS-PATH, it rejects that route outright (avoids routing loops without needing complex distance computations).
  • Route selection uses policy (not just shortest path) — preferring routes based on local preference, AS-PATH length, origin type, and other administratively configured attributes, allowing ISPs to enforce business/peering agreements rather than pure cost minimization.
  • BGP runs over a reliable TCP connection (port 179) between peers and only sends incremental updates, not periodic full-table dumps.

Part (b): IGP (RIP, OSPF) vs EGP (BGP)

BasisInterior Gateway Protocol (RIP/OSPF)Exterior Gateway Protocol (BGP)
ScopeRoutes within a single Autonomous System (AS)Routes between different Autonomous Systems (the Internet backbone)
GoalFind the technically shortest/fastest path (metric-based)Enforce administrative/business policy, not just shortest path
Algorithm typeDistance Vector (RIP) or Link State (OSPF)Path Vector
Convergence speedFast (seconds, small trusted network)Slower (large scale, policy-based decisions, dampening)
Trust modelAll routers within one organisation's controlRouters belong to different, mutually untrusting organisations — must be policy-driven and loop-safe
Table sizeSmall (one organisation's network)Very large (entire global Internet routing table, 900k+ prefixes)
Q11a) Explain IPv4 Header fields in detail. b) Explain IPv4 Packet Fragmentation and Reassembly parameters (Identification, Flags, Fragment Offset) with an example.

Part (a): IPv4 Header Fields

FieldSizePurpose
Version4 bitsIP version (4)
IHL4 bitsHeader length in 32-bit words (min 5 = 20 bytes)
Type of Service (DSCP/ECN)8 bitsPriority/QoS marking
Total Length16 bitsEntire packet size (header+data) in bytes, max 65535
Identification16 bitsUniquely identifies fragments of the same original packet
Flags3 bitsDF (Don't Fragment), MF (More Fragments)
Fragment Offset13 bitsPosition of this fragment (in 8-byte units) within the original packet
TTL8 bitsHop limit; decremented by every router, packet discarded at 0 (prevents infinite loops)
Protocol8 bitsIdentifies next-layer protocol (6=TCP, 17=UDP, 1=ICMP)
Header Checksum16 bitsError-checks the header only (recomputed at every hop since TTL changes)
Source / Destination Address32 bits eachSender and receiver IP addresses
Options + PaddingvariableOptional fields (rarely used); padded to a multiple of 32 bits

Part (b): Fragmentation and Reassembly Example

Consider an IP packet with 4000 bytes of data that must traverse a link with MTU = 1500 bytes. Usable data per fragment (excluding 20-byte header) = 1480 bytes, which must also be a multiple of 8 for the Fragment Offset field (1480 is already a multiple of 8).

FragmentData SizeIdentificationMF FlagFragment Offset (in 8-byte units)
11480 bytes (bytes 0-1479)same ID (e.g. 111)1 (more fragments follow)0
21480 bytes (bytes 1480-2959)11111480/8 = 185
31040 bytes (bytes 2960-3999, last fragment)1110 (last fragment)2960/8 = 370

All fragments share the same Identification field so the destination knows they belong together; the Fragment Offset tells the receiver where each fragment's data belongs in the reassembled packet; MF=1 on all but the last fragment tells the receiver more pieces are coming, while MF=0 on the final fragment signals reassembly can complete once all offsets 0 to (offset+length) are received. If any single fragment is lost, the entire original packet must be discarded and retransmitted (IP itself has no per-fragment retransmission).

Q12a) Explain TCP Header format fields in detail. b) Explain TCP Connection Management State Transition Diagram (LISTEN, SYN_SENT, ESTABLISHED, FIN_WAIT).

Part (a): TCP Header Format Fields

FieldSizePurpose
Source / Destination Port16 bits eachIdentifies sending/receiving application (socket endpoint)
Sequence Number32 bitsByte-stream position of the first data byte in this segment
Acknowledgement Number32 bitsNext byte the receiver expects (valid if ACK flag set)
Header Length (Data Offset)4 bitsTCP header length in 32-bit words (accounts for options)
Flags (Control Bits)SYN,ACK,FIN,RST,PSH,URG (1 bit each)Connection control: establish (SYN), acknowledge (ACK), terminate (FIN), abort (RST), push data immediately (PSH), urgent data (URG)
Window Size16 bitsReceiver's advertised flow-control window (rwnd)
Checksum16 bitsError-checks header + data + pseudo-header
Urgent Pointer16 bitsOffset to urgent data, valid if URG flag set
OptionsvariableMSS, Window Scale, SACK, Timestamps, etc.

Part (b): TCP Connection State Transition Diagram

CLOSED LISTEN SYN_SENT SYN_RCVD ESTABLISHED FIN_WAIT_1/2 passive open recv SYN,ACK recv SYN recv ACK app close, send FIN
Simplified TCP state diagram: CLOSED → LISTEN/SYN_SENT → SYN_RCVD → ESTABLISHED → FIN_WAIT → CLOSED

Key states: LISTEN — server waiting for a connection request; SYN_SENT — client has sent SYN, awaiting SYN-ACK; SYN_RCVD — server received SYN, sent SYN-ACK, awaiting final ACK; ESTABLISHED — handshake complete, data transfer possible in both directions; FIN_WAIT_1/2, CLOSE_WAIT, LAST_ACK, TIME_WAIT — the various stages of the 4-way graceful termination, ending in CLOSED.

Q13a) Explain Traffic Shaping: Leaky Bucket vs Token Bucket. b) Calculate maximum burst duration for Token Bucket with capacity 1MB, token arrival rate 2MB/s, transmission rate 10MB/s.

Part (a): Leaky Bucket vs Token Bucket

BasisLeaky BucketToken Bucket
Output rateStrictly constant, regardless of input burstinessCan vary — allows bursts up to bucket capacity
Bursty trafficFully smooths out bursts (rigid)Permits controlled bursts when tokens have accumulated
Idle capacityUnused output capacity during idle periods is wasted (cannot be "saved up")Unused tokens accumulate (up to capacity C), usable for a later burst
ImplementationFIFO queue + constant-rate serverToken counter incremented at rate r, packet sent only if a token is available
Best suited forStrict, non-negotiable rate shapingRealistic bursty traffic (e.g. compressed video, web traffic) needing average-rate policing with flexibility

Part (b): Maximum Burst Duration Calculation

Given: Token bucket capacity C = 1 MB, token arrival (fill) rate r = 2 MB/s, maximum transmission (output) rate M = 10 MB/s.

During a burst, tokens both drain (at rate M, the transmit rate) and refill (at rate r) simultaneously, so the bucket empties at net rate (M - r). Maximum burst duration: S = C / (M - r) = 1 MB / (10 MB/s - 2 MB/s) = 1 / 8 s = 0.125 s = 125 ms Verification (total data sent during the burst): Data sent = M * S = 10 MB/s * 0.125 s = 1.25 MB Data available = initial bucket (C=1MB) + tokens arriving during S (r*S = 2*0.125 = 0.25MB) = 1 MB + 0.25 MB = 1.25 MB (matches data sent -- consistent)

Result: the host can transmit at the full 10 MB/s peak rate for at most 125 milliseconds before the bucket is drained and the sending rate must fall back to the sustainable arrival rate of 2 MB/s.

Q14a) Explain Domain Name System (DNS) Iterative vs Recursive resolution. b) Detail DNS Resource Records (A, AAAA, CNAME, MX, NS, PTR).

Part (a): DNS Iterative vs Recursive Resolution

BasisRecursive ResolutionIterative Resolution
Who does the workThe queried server takes full responsibility for obtaining the final answer, querying further servers itselfThe queried server returns its best current answer or a referral (pointer to another server) — the client must ask again itself
Typical usageUsed between the client (stub resolver) and its local/ISP recursive resolverUsed between the recursive resolver and the root/TLD/authoritative servers
LoadHigher load on the server doing recursion (must chase down the answer)Lower load on root/TLD servers — they just redirect, not resolve
Caching benefitRecursive resolver caches full answers for reuse by many clientsEach referral can also be cached independently

In practice a client sends one recursive query to its configured DNS resolver; that resolver then performs a chain of iterative queries — root → TLD → authoritative — following referrals at each step, and finally returns the complete answer to the client in a single response.

Part (b): DNS Resource Records

Record TypePurpose
AMaps a hostname to an IPv4 address
AAAAMaps a hostname to an IPv6 address
CNAMECanonical Name — aliases one hostname to another (e.g. www → the real server name)
MXMail Exchanger — specifies the mail server(s) responsible for accepting email for the domain, with priority values
NSName Server — delegates a domain/subdomain to a specific authoritative name server
PTRPointer — used for reverse DNS lookup, mapping an IP address back to a hostname
Q15a) Explain HTTP 1.0 vs HTTP 1.1 vs HTTP 2.0 vs HTTP 3.0 protocols. b) Detail Persistent Connections, Pipelining, Multiplexing, and QUIC protocol.

Part (a): HTTP 1.0 vs 1.1 vs 2.0 vs 3.0

VersionConnection ModelKey Feature
HTTP/1.0New TCP connection per request (no reuse)Simple but very high connection-setup overhead for pages with many objects
HTTP/1.1Persistent connections by default (Connection: keep-alive)Pipelining allowed (rarely used in practice due to head-of-line blocking); chunked transfer encoding
HTTP/2.0Single persistent TCP connection, multiplexed streamsBinary framing, true multiplexing (parallel requests without head-of-line blocking at the HTTP layer), header compression (HPACK), server push
HTTP/3.0Runs over QUIC (UDP-based), not TCPEliminates TCP-level head-of-line blocking entirely, faster connection establishment (0-RTT/1-RTT), built-in TLS 1.3 encryption

Part (b): Persistent Connections, Pipelining, Multiplexing, and QUIC

  • Persistent Connections (HTTP/1.1): The same TCP connection is reused for multiple sequential requests/responses, avoiding the cost of a new TCP handshake for every object on a page.
  • Pipelining (HTTP/1.1): Client sends multiple requests back-to-back without waiting for each response, but responses must still return strictly in order — one slow response blocks all later ones (head-of-line blocking), which limited real-world adoption.
  • Multiplexing (HTTP/2): Multiple independent request/response "streams" share a single TCP connection simultaneously, interleaved as small frames; a slow response no longer blocks others at the HTTP layer, solving HTTP-level head-of-line blocking (though TCP-level HOL blocking on packet loss remains).
  • QUIC (HTTP/3): A transport protocol built on UDP that combines connection setup and TLS encryption into a faster handshake, and multiplexes independent streams at the transport layer itself so a lost packet only stalls the one stream it belongs to — fully eliminating head-of-line blocking, which is HTTP/2's remaining weakness over TCP.
Q16a) Explain Cryptographic Hash Functions (MD5, SHA-256) and Digital Certificates. b) Detail Public Key Infrastructure (PKI) and Certificate Authority (CA) verification.

Part (a): Cryptographic Hash Functions and Digital Certificates

A cryptographic hash function maps arbitrary-length input to a fixed-length digest, with three key properties: pre-image resistance (cannot reverse hash to input), second pre-image resistance (cannot find a different input with the same hash), and collision resistance (cannot find any two inputs with the same hash).

  • MD5: Produces a 128-bit digest; now considered cryptographically broken (practical collisions demonstrated) and unsuitable for security purposes, though still used for non-security checksums.
  • SHA-256: Part of the SHA-2 family, produces a 256-bit digest; currently considered secure and is the standard choice for TLS certificates, blockchain, and password hashing (with salting).

A Digital Certificate (X.509 format) binds a public key to an identity (e.g. a domain name or organisation), digitally signed by a trusted Certificate Authority (CA), containing the subject's public key, validity period, issuer details, and the CA's signature over a hash of the certificate contents.

Part (b): PKI and Certificate Authority Verification

Public Key Infrastructure (PKI) is the overall system of hardware, software, policies, and roles needed to create, distribute, manage, and revoke digital certificates.

  • Certificate Authority (CA): A trusted third party that verifies an applicant's identity and issues a signed certificate binding their public key to that identity.
  • Chain of Trust: Certificates form a chain from a Root CA (self-signed, pre-installed as trusted in browsers/OS) → Intermediate CA → End-entity (server) certificate; a client verifies the chain by checking each certificate's signature using the issuer's public key, up to a trusted root.
  • Verification steps: (1) Check the certificate's validity period, (2) verify the signature chain up to a trusted root CA, (3) check the certificate has not been revoked (via CRL or OCSP), (4) confirm the domain name matches the certificate's subject/SAN field.
  • Revocation: If a private key is compromised, the CA can revoke the certificate; clients check Certificate Revocation Lists (CRL) or use the Online Certificate Status Protocol (OCSP) to detect this.
Q17a) Explain IPsec Protocol Suite Architecture (AH, ESP, IKE). b) Differentiate IPsec Transport Mode vs Tunnel Mode.

Part (a): IPsec Protocol Suite Architecture

IPsec is a suite of protocols that secures IP traffic at the Network layer, providing confidentiality, integrity, and authentication transparently to applications above it.

  • AH (Authentication Header): Provides data integrity and origin authentication for the entire IP packet (including parts of the header), but no encryption — protects against tampering and spoofing, not eavesdropping.
  • ESP (Encapsulating Security Payload): Provides confidentiality (encryption) as well as optional integrity/authentication of the payload — the more commonly used protocol since it covers both secrecy and integrity.
  • IKE (Internet Key Exchange): Handles the negotiation of security associations (SAs) — the agreed algorithms and shared secret keys — between two IPsec endpoints, typically using Diffie-Hellman key exchange, so AH/ESP do not need manual key configuration.

Part (b): Transport Mode vs Tunnel Mode

BasisTransport ModeTunnel Mode
What is protectedOnly the payload (transport-layer segment); original IP header stays exposedThe entire original IP packet (header + payload) is encapsulated and protected inside a new IP packet
HeaderOriginal IP header retained, IPsec header inserted after itNew outer IP header added; original header hidden inside the encrypted payload
Typical useEnd-to-end host-to-host secure communicationSite-to-site VPNs (gateway to gateway), where original source/destination addresses must remain hidden
OverheadLower (no extra IP header)Higher (extra IP header added)
Q18a) Explain IEEE 802.11 Wireless LAN MAC layer CSMA/CA protocol. b) Detail RTS/CTS handshake solving Hidden Terminal and Exposed Terminal problems.

Part (a): IEEE 802.11 MAC Layer CSMA/CA

802.11 uses CSMA/CA (not CD) because a wireless station cannot reliably transmit and simultaneously sense the medium for collisions on the same frequency. The DCF (Distributed Coordination Function) works as follows: a station wanting to transmit senses the channel; if idle for a DIFS (Distributed Inter-Frame Space) period, it picks a random backoff counter from its contention window and counts down (pausing the countdown whenever the channel becomes busy); when the counter reaches zero, it transmits. Every unicast frame must be positively acknowledged by an ACK from the receiver (sent after a shorter SIFS gap) since the sender has no other way to know whether the frame collided/was corrupted over the air.

Part (b): RTS/CTS and the Hidden/Exposed Terminal Problems

A B C A's range C's range
A and C are both in range of B but out of range of each other — the hidden terminal problem
  • Hidden Terminal Problem: A and C are both within range of B but out of range of each other. If A senses the channel, it finds it idle (cannot hear C) and transmits to B; if C also senses idle and transmits to B simultaneously, a collision occurs at B that neither A nor C can detect — carrier sensing alone fails.
  • Exposed Terminal Problem: If B is transmitting to A, and C (in range of B but not A) wants to transmit to a distant D, C senses the channel busy (hears B) and unnecessarily refrains from transmitting, even though its transmission to D would not actually interfere with A's reception — wasting available capacity.
  • RTS/CTS solution: Before sending data, the sender transmits a short RTS (Request to Send) frame; the receiver replies with CTS (Clear to Send). Both RTS and CTS carry a duration field specifying how long the upcoming data transfer will occupy the medium. Any station that hears either the RTS or the CTS sets its NAV (Network Allocation Vector) timer and defers transmission for that duration — since C hears B's CTS (even though it may not hear A's RTS), it correctly defers, solving the hidden terminal problem.
Q19a) Explain Software Defined Networking (SDN) Architecture. b) Detail Separation of Control Plane and Data Plane, OpenFlow protocol, and SDN Controller.

Part (a): Software Defined Networking (SDN) Architecture

Application Plane (apps, policies) Control Plane (SDN Controller) Switch (Data Plane) Switch (Data Plane) Switch (Data Plane) Northbound API Southbound API (OpenFlow)
SDN architecture: centralized controller (control plane) programs distributed switches (data plane) via OpenFlow

SDN centralizes network intelligence into a software-based SDN Controller, which maintains a global view of the network and programs the behaviour of simple, "dumb" forwarding switches — a sharp departure from traditional networking where every router/switch independently runs its own control-plane logic (routing protocols, etc.).

Part (b): Control/Data Plane Separation, OpenFlow, and Controller

  • Data Plane: The switches/routers that simply forward packets at high speed according to flow rules installed by the controller — they no longer make independent routing decisions.
  • Control Plane: Centralized in the SDN Controller, which computes routing/forwarding logic for the entire network and pushes flow rules down to switches — decoupling "what to do" (control) from "doing it fast" (data forwarding).
  • OpenFlow: The standard southbound protocol/API through which the controller communicates with switches — it lets the controller install, modify, and remove flow-table entries (match fields → actions) in each switch, and lets switches forward unmatched packets to the controller for a decision.
  • SDN Controller: The centralized "brain" (e.g. ONOS, OpenDaylight) that runs network applications (routing, load balancing, firewalling) via a northbound API, translates their intent into OpenFlow rules, and pushes them to switches via the southbound interface — enabling centralized, programmable, vendor-independent network management.
Q20a) Complete Computer Networks Case Study: Trace packet travel when user enters `https://www.google.com` in web browser. b) Detail DNS query, ARP resolution, TCP 3-way handshake, TLS handshake, HTTP GET, IP routing, and Ethernet framing.

Part (a) & (b): Complete Trace — Entering https://www.google.com in a Browser

Browser DNS Resolver Default Gateway Google Web Server
End-to-end path: browser → DNS resolver (name lookup) and gateway/router path (data delivery) → server
  1. DNS Query: Browser checks its cache; if absent, the OS resolver sends a recursive DNS query (typically via UDP port 53) to the configured DNS server, which iteratively resolves www.google.com through root → .com TLD → Google's authoritative servers, returning an IP address (e.g. 142.250.x.x), cached per its TTL.
  2. ARP Resolution: To send the first IP packet, the host needs the MAC address of its default gateway (since Google's server is off-link). It checks its ARP cache; if absent, it broadcasts an ARP Request ("who has gateway IP?") and receives an ARP Reply with the gateway's MAC address.
  3. TCP 3-Way Handshake: The browser opens a TCP connection to the server on port 443: SYN → SYN-ACK → ACK, establishing a reliable connection with synchronized sequence numbers.
  4. TLS Handshake: Over the established TCP connection, a TLS handshake negotiates the cipher suite, the server presents its certificate (verified against a trusted CA), and both sides derive a shared symmetric session key (via ECDHE or similar) for encrypting subsequent traffic — securing the HTTPS session.
  5. HTTP GET Request: The browser sends an encrypted HTTP GET / request over the TLS-protected TCP connection; the server responds with the HTML document (status 200 OK) plus further resource references.
  6. IP Routing: Each IP packet is routed hop-by-hop: the local host sends it to the default gateway (using the ARP-resolved MAC), which consults its routing table to forward it toward the next router, and so on across ISP backbone routers (each decrementing TTL) until it reaches Google's edge network and finally the serving datacenter.
  7. Ethernet Framing: At each hop, the IP packet is wrapped in a Data Link (Ethernet, at least on the LAN segments) frame with the appropriate source/destination MAC addresses for that specific link, stripped and re-framed at every router along the path (MAC addresses are link-local, unlike IP addresses which stay constant end-to-end).

This trace illustrates the full protocol stack working together: Application (HTTP) → Security (TLS) → Transport (TCP, reliability) → Network (IP, routing, using ARP for local delivery and DNS for name resolution) → Data Link/Physical (Ethernet framing, actual bit transmission) — each layer adding its own header via encapsulation on the way down, and removing it via de-encapsulation on the way up at the receiver.

Q21a) Calculate maximum throughput for Pure ALOHA and Slotted ALOHA mathematically. b) Plot throughput S vs offered load G.

Part (a): Maximum Throughput Derivation

Let G = average number of transmission attempts (new + retransmitted) per frame time (offered load), and S = throughput (successfully transmitted frames per frame time).

Pure ALOHA — a frame collides if any other station transmits within the vulnerable period of 2 frame-times (one frame-time before and one after). Probability of zero other arrivals in 2 frame-times (Poisson) = e^(-2G), so:

S = G * e^(-2G) Maximize: dS/dG = e^(-2G) * (1 - 2G) = 0 => G = 0.5 S_max = 0.5 * e^(-1) = 0.5 / 2.71828 = 0.1839 ~= 18.4%

Slotted ALOHA — transmissions confined to slot boundaries, halving the vulnerable period to 1 frame-time:

S = G * e^(-G) Maximize: dS/dG = e^(-G) * (1 - G) = 0 => G = 1 S_max = 1 * e^(-1) = 1 / 2.71828 = 0.3679 ~= 36.8%

Result: maximum throughput is 18.4% for Pure ALOHA (at G=0.5) and 36.8% for Slotted ALOHA (at G=1) — slotted ALOHA doubles the maximum achievable throughput by halving the vulnerable collision period.

Part (b): Throughput S vs Offered Load G

GS (Pure ALOHA)S (Slotted ALOHA)
0.10.0820.090
0.50.184 (peak)0.303
1.00.1350.368 (peak)
2.00.0370.271
3.00.0070.149
G S Slotted (peak 0.368 @ G=1) Pure (peak 0.184 @ G=0.5)
S vs G: both curves rise then fall as retransmissions dominate at high load; slotted ALOHA's curve is always higher

Both curves rise to a peak and then decline because beyond the optimal G, increasing offered load causes more collisions than successful transmissions, reducing net throughput — an inherent instability of pure random-access schemes under overload.

Q22a) Explain Optical Fiber communication principles (Total Internal Reflection, Single-mode vs Multi-mode). b) Calculate attenuation and dispersion limitations on fiber links.

Part (a): Optical Fiber Principles — TIR, Single-mode vs Multi-mode

Total Internal Reflection (TIR): An optical fiber consists of a glass core (higher refractive index n1) surrounded by a cladding (lower refractive index n2 < n1). When light traveling inside the core strikes the core-cladding boundary at an angle greater than the critical angle theta_c = sin^-1(n2/n1), it is completely reflected back into the core rather than refracting out — this principle lets light bounce along the fiber over long distances with minimal loss, effectively guiding it like a "pipe for light".

BasisSingle-Mode Fiber (SMF)Multi-Mode Fiber (MMF)
Core diameterVery narrow (~8-10 microns)Wider (~50-62.5 microns)
Light pathsOnly one path (mode) — light travels nearly straight down the axisMultiple paths/modes bounce at different angles
Modal dispersionNegligible (single path)Significant (different modes arrive at different times, spreading the pulse)
Distance / BandwidthVery long distance, very high bandwidth (backbone/long-haul)Shorter distance, lower bandwidth (LAN/campus)
CostHigher (requires laser source, precise alignment)Lower (can use cheaper LED sources)

Part (b): Attenuation and Dispersion Calculation

Attenuation is expressed logarithmically in dB: Loss(dB) = 10 * log10(Pin/Pout), with typical single-mode fiber attenuation around 0.2-0.35 dB/km at 1550/1310 nm.

Example: a 100 km single-mode link with attenuation 0.25 dB/km and input power 0 dBm (1 mW): Total attenuation = 0.25 dB/km * 100 km = 25 dB Output power (dBm) = Input power (dBm) - Total attenuation = 0 - 25 = -25 dBm Output power (mW) = 10^(-25/10) = 10^-2.5 ~= 0.00316 mW (3.16 microwatts) If the receiver's sensitivity threshold is -28 dBm, this link (with -25 dBm arriving) still has a 3 dB margin and remains usable without amplification/repeaters.

Dispersion limitation: Chromatic and modal dispersion cause transmitted pulses to spread in time as they travel; if pulse spreading approaches the bit period, adjacent bits smear into each other (inter-symbol interference), capping the maximum usable bit rate × distance product for a given fiber — this is why long multi-mode links are bandwidth-limited compared to single-mode, and why single-mode fiber (negligible modal dispersion) is preferred for high-speed, long-haul backbone links, with chromatic dispersion managed via dispersion-compensating fiber or operating near the fiber's zero-dispersion wavelength.

Q23a) Explain Data Link Layer Framing methods: Byte Count, Byte Stuffing, Bit Stuffing. b) Perform bit stuffing on frame `011111101111110`.

Part (a): Data Link Layer Framing Methods

MethodMechanismDrawback
Byte/Character CountA length field at the start of the frame tells the receiver exactly how many bytes followIf the count field itself is corrupted, frame boundary is completely lost (no resynchronization method) — rarely used alone today
Byte Stuffing (Character Stuffing)Special flag bytes (e.g. 0x7E) mark frame start/end; if the flag byte pattern appears in the data itself, an escape byte (e.g. 0x7D) is inserted before it so the receiver can distinguish real data from a frame delimiterAdds variable, data-dependent overhead; requires byte-aligned data
Bit StuffingA specific bit pattern (e.g. 01111110, used by HDLC) marks frame boundaries; whenever 5 consecutive 1s occur in the actual data, a 0 is automatically inserted after them so the flag pattern never accidentally appears mid-frameSlight, data-dependent overhead; works at the bit level so is protocol-independent of byte boundaries

Part (b): Bit Stuffing on Frame 011111101111110

Rule: insert a 0 immediately after every 5 consecutive 1s encountered in the original data (regardless of what follows), so the flag pattern 01111110 can never occur naturally inside stuffed data.

Original data: 0 1 1 1 1 1 1 0 1 1 1 1 1 1 0 ^-----------^ ^-----------^ run of six 1s run of six 1s (positions 2-7) (positions 9-14) Processing (left to right), inserting a 0 after the 5th consecutive 1: 0 -> 0 1,1,1,1,1 (5th one) -> 1 1 1 1 1 + stuffed 0 1 (6th one, run resets) -> 1 0 (real bit) -> 0 1,1,1,1,1 (5th one) -> 1 1 1 1 1 + stuffed 0 1 (6th one, run resets) -> 1 0 (real bit) -> 0 Stuffed output: 0 1 1 1 1 1 [0] 1 0 1 1 1 1 1 [0] 1 0 = 01111101011111010 (17 bits; 2 stuffed 0s added to the original 15)

At the receiver, whenever 5 consecutive 1s are seen followed by a 0, that 0 is automatically removed (destuffed) if it is not part of the actual 01111110 flag context, correctly reconstructing the original 15-bit data frame.

Q24a) Explain Network Management Protocol SNMP (v1, v2, v3) Architecture. b) Detail Management Information Base (MIB) and SMI structure.

Part (a): SNMP Architecture (v1, v2, v3)

SNMP (Simple Network Management Protocol) lets a central manager monitor and control network devices (routers, switches, servers) through software agents running on each device.

VersionKey Characteristics
SNMPv1Original version; uses simple, plaintext "community strings" (like a password) for access control — weak security; basic GET/SET/TRAP operations
SNMPv2 (v2c)Adds GETBULK (efficient retrieval of large tables) and improved error handling; still uses weak community-string security (v2c = "community-based")
SNMPv3Adds robust security: authentication (verifying the message sender), encryption (privacy of data), and access control (View-based Access Control Model) — the current recommended standard

Core components: a central Network Management Station (NMS/Manager) polls or receives unsolicited Trap messages from Agents on managed devices, using operations GET (read a value), SET (write a value), GETNEXT/GETBULK (walk a table), and TRAP (agent-initiated alert, e.g. link down).

Part (b): Management Information Base (MIB) and SMI

  • MIB (Management Information Base): A structured, hierarchical (tree-like) database of manageable objects on a device (e.g. interface counters, CPU load, routing table entries), each identified by a unique Object Identifier (OID) such as 1.3.6.1.2.1.1.3.0 (a dotted path through the tree).
  • SMI (Structure of Management Information): Defines the rules for naming objects in the MIB tree and specifying their data types (INTEGER, OCTET STRING, Counter, Gauge, etc.), ensuring different vendors' devices describe manageable data in a common, unambiguous format so any SNMP manager can interpret any agent's MIB.

Together, SMI provides the "grammar" and MIB provides the "dictionary" that lets SNMP managers query standardized as well as vendor-specific ("private enterprise") data from heterogeneous network devices.

Q25a) Explain Mobile IP Architecture. b) Detail Home Agent, Foreign Agent, Care-of Address, and Tunneling mechanism.

Part (a): Mobile IP Architecture

Mobile IP allows a mobile device to stay reachable at a single, permanent IP address (its Home Address) even as it physically moves to different networks, without breaking ongoing higher-layer (TCP) connections.

Correspondent Node Home Agent Foreign Agent Mobile Node Tunnel
Traffic to the mobile node's home address is intercepted by the Home Agent and tunneled to its current Care-of Address

Part (b): Home Agent, Foreign Agent, Care-of Address, Tunneling

  • Home Agent (HA): A router on the mobile node's home network that maintains a record of the node's current location and intercepts packets addressed to the node's permanent home address whenever it is away.
  • Foreign Agent (FA): A router on the network the mobile node is currently visiting; it registers the visiting node's presence with the Home Agent and forwards received tunneled packets to the mobile node locally.
  • Care-of Address (CoA): A temporary IP address associated with the mobile node's current location on the foreign network (either the Foreign Agent's address, or a co-located address obtained by the node itself, e.g. via DHCP) — used as the tunnel endpoint.
  • Tunneling: The Home Agent encapsulates each packet destined for the mobile node's home address inside a new IP packet addressed to the Care-of Address (IP-in-IP encapsulation) and sends it across the network to the Foreign Agent, which de-encapsulates it and delivers the original packet to the mobile node — this way the mobile node's permanent home address remains unchanged and usable by correspondents, hiding all the physical mobility beneath the tunnel.
Q26a) Explain Network Security Threats: Denial of Service (DoS), Distributed DoS (DDoS), Man-in-the-Middle (MitM), SQL Injection. b) Detail SYN Flood attack and SYN Cookies defense.

Part (a): Network Security Threats

ThreatDescription
DoS (Denial of Service)An attacker floods a target with excessive traffic or requests, exhausting its resources (bandwidth, CPU, connection table) so legitimate users cannot be served
DDoS (Distributed DoS)Same goal as DoS but launched simultaneously from a large number of compromised hosts (a botnet), making the traffic volume far larger and the sources harder to block individually
Man-in-the-Middle (MitM)An attacker secretly intercepts (and possibly alters) communication between two parties who believe they are communicating directly with each other, e.g. via ARP spoofing or rogue Wi-Fi access points
SQL InjectionAn attacker inserts malicious SQL code into an application's input fields, causing the backend database to execute unintended commands — extracting, modifying, or deleting data

Part (b): SYN Flood Attack and SYN Cookies

SYN Flood: An attacker exploits the TCP 3-way handshake by sending a large volume of SYN segments (often with spoofed source IPs) to a target server, which allocates connection state (in the SYN_RCVD state, in its backlog queue) and replies with SYN-ACK for each, waiting for the final ACK that never arrives. Once the connection backlog queue fills up with these half-open connections, the server can no longer accept genuine new connections — a classic resource-exhaustion DoS attack.

SYN Cookies defense: Instead of allocating state for each SYN, the server encodes essential connection information (a hash of source/destination IP+port, a timestamp, and a secret) into the initial sequence number of its SYN-ACK reply, without storing anything in memory. Only when the final ACK arrives (with the acknowledgement number = cookie + 1) does the server recompute and verify the cookie and, if valid, reconstruct the connection state — completely eliminating the need to hold half-open connection state for spoofed/never-completed handshakes, defeating the resource-exhaustion attack.

Q27a) Explain Peer-to-Peer (P2P) Architecture vs Client-Server Architecture. b) Detail BitTorrent protocol, DHT (Distributed Hash Table), and Choking algorithm.

Part (a): P2P vs Client-Server Architecture

BasisClient-ServerPeer-to-Peer (P2P)
RolesFixed roles — dedicated server(s) provide resources, clients only consumeEvery node (peer) can act as both client and server simultaneously
ScalabilityLimited by server capacity; server becomes a bottleneck as clients growScales naturally — each new peer adds both demand and supply capacity
Single point of failureYes — server outage takes down the whole serviceNo single point of failure — network degrades gracefully as peers leave
ManagementCentralized, easier to secure/administer/updateDecentralized, harder to enforce consistent policy/security
ExampleWeb browsing (HTTP), email, database applicationsBitTorrent, blockchain networks, Skype (early versions)

Part (b): BitTorrent Protocol, DHT, and Choking Algorithm

  • BitTorrent protocol: A large file is split into many fixed-size pieces; a .torrent file (or magnet link) describes the pieces (via hashes) and points to a tracker (or DHT) that helps peers discover each other; peers download different pieces from different peers in parallel and simultaneously upload pieces they already have to others ("swarming"), dramatically improving download speed and eliminating a single distribution bottleneck.
  • DHT (Distributed Hash Table): A fully decentralized, distributed key-value lookup structure (e.g. Kademlia) that lets peers find other peers sharing a given file without relying on a central tracker — each peer stores routing information about a subset of other peers, and lookups are resolved by successively querying peers "closer" (in the DHT's XOR/ID-distance metric) to the target key.
  • Choking Algorithm: Each peer uploads to only a limited number of other peers at a time ("unchoked" peers) to conserve its own upload bandwidth, typically favoring peers that reciprocate with good upload rates back to it ("tit-for-tat"), while periodically "optimistically unchoking" a random peer to discover potentially better trading partners — this incentivizes fair sharing and discourages free-riding (leeching without uploading).
Q28a) Explain Virtual Local Area Networks (VLAN) IEEE 802.1Q tagging. b) Detail VLAN configuration and Inter-VLAN routing.

Part (a): VLAN IEEE 802.1Q Tagging

A VLAN (Virtual LAN) logically partitions a single physical switched network into multiple separate broadcast domains, as if they were on physically separate switches, without needing separate physical hardware.

Dest MAC Src MAC 802.1Q Tag(TPID+VLAN ID) EtherType Payload + FCS
802.1Q inserts a 4-byte tag (containing a 12-bit VLAN ID) between the source MAC and EtherType fields

The 802.1Q tag is a 4-byte field inserted into the Ethernet frame containing a Tag Protocol Identifier (0x8100) and a 12-bit VLAN ID (supporting up to 4094 usable VLANs), allowing a switch to identify which VLAN each frame belongs to and enforce that broadcasts/traffic stay confined within that VLAN, even across multiple switches connected by a shared "trunk" link carrying multiple VLANs' traffic simultaneously.

Part (b): VLAN Configuration and Inter-VLAN Routing

  • Access ports: Connect to end devices (PCs); carry traffic for exactly one VLAN, untagged from the device's perspective (the switch adds/removes the tag).
  • Trunk ports: Connect switches to each other (or to a router); carry tagged traffic for multiple VLANs over a single physical link, using 802.1Q tags to distinguish which VLAN each frame belongs to.
  • Inter-VLAN Routing: Since VLANs are separate broadcast/IP subnets, a Layer-3 device (router, or a Layer-3 switch) is required to route traffic between them. A common setup is "router-on-a-stick": a single physical router interface (or switch trunk port) is subdivided into logical sub-interfaces, one per VLAN, each tagged and configured with that VLAN's gateway IP, allowing the router to forward packets between VLANs despite them being logically isolated at Layer 2.
Q29a) Explain Overlay Networks and Content Delivery Networks (CDN). b) Detail Anycast routing and Edge Caching strategies.

Part (a): Overlay Networks and Content Delivery Networks (CDN)

An Overlay Network is a virtual network built as a layer on top of an existing physical network, where nodes are connected by logical (virtual) links that may span multiple physical hops — enabling new topologies, routing behavior, or services (e.g. P2P overlays, VPN tunnels, SDN control overlays) without modifying the underlying physical infrastructure.

A CDN (Content Delivery Network) is a geographically distributed network of proxy/cache servers (edge servers) that store copies of content (web pages, videos, images) close to end users, reducing latency and origin-server load by serving requests from a nearby edge location rather than a single, potentially distant, origin server.

Part (b): Anycast Routing and Edge Caching Strategies

  • Anycast Routing: The same IP address is announced from multiple geographically distributed locations; standard BGP/IGP routing (which naturally selects the topologically "shortest"/lowest-cost path) automatically directs each client's request to its nearest (in terms of network cost) instance of that address — used heavily by CDNs and root DNS servers to route users to the nearest edge server transparently, without any client-side configuration.
  • Edge Caching strategies:
    • Pull (Cache-on-demand): An edge server fetches and caches content from the origin only on the first request (cache miss), serving subsequent requests directly from cache until it expires (TTL).
    • Push (Pre-positioning): Popular/predicted content is proactively pushed to edge servers ahead of demand (e.g. before a scheduled high-traffic event).
    • Cache eviction policies (e.g. LRU — Least Recently Used) decide which cached objects to discard when storage is full, to keep the most popular/relevant content available at the edge.

Together, anycast gets the user's request to a nearby edge node with minimal latency, and edge caching ensures that node can usually answer immediately from local storage rather than forwarding the request all the way back to the origin server.

Q30a) Explain Real-time Audio/Video Streaming protocols: RTP, RTCP, RTSP, HLS. b) Detail Jitter buffering and Packet Loss concealment techniques.

Part (a): Real-time Audio/Video Streaming Protocols

ProtocolRole
RTP (Real-time Transport Protocol)Carries the actual encoded audio/video payload over UDP, adding sequence numbers (for reordering/loss detection) and timestamps (for correct playback timing/synchronization); does not itself guarantee delivery
RTCP (RTP Control Protocol)Runs alongside RTP to periodically report QoS statistics (packet loss, jitter, round-trip time) between participants, allowing senders to adapt (e.g. change codec/bitrate) based on network conditions
RTSP (Real-Time Streaming Protocol)An out-of-band "remote control" protocol for streaming sessions — provides VCR-like commands (PLAY, PAUSE, SETUP, TEARDOWN) to control media delivery, typically setting up the underlying RTP session
HLS (HTTP Live Streaming)Splits video into small segments (e.g. 2-10 sec chunks) described by a playlist (.m3u8) manifest, delivered over ordinary HTTP; supports adaptive bitrate streaming by offering multiple quality-level playlists and letting the client switch based on measured bandwidth

Part (b): Jitter Buffering and Packet Loss Concealment

  • Jitter: Because packets travel through a shared, best-effort network, consecutive packets arrive with varying delay (not evenly spaced as they were sent) — direct playback would cause audible/visible stutter.
  • Jitter Buffer: The receiver intentionally holds incoming packets in a small buffer for a short, adaptive delay before playback, re-ordering them by their RTP timestamps and releasing them to the decoder at a smooth, constant rate — absorbing network delay variation at the cost of added end-to-end latency. Adaptive jitter buffers dynamically resize based on observed jitter (reported via RTCP) to balance latency against smoothness.
  • Packet Loss Concealment (PLC): When a packet is lost or arrives too late to be useful, instead of leaving a gap (silence/frozen frame), the decoder synthesizes a plausible replacement — e.g. for audio, repeating/interpolating the previous waveform pattern; for video, using motion-compensated frame interpolation or simply repeating the last good frame — minimizing perceptible quality degradation from the loss, which is essential since RTP/UDP does not retransmit lost packets (retransmission would arrive too late for a real-time stream anyway).