FIELD REFERENCE INDEX
Help ?

Cheat Sheets
Interview Ready, Fast Refresh

quick-scan references for interviews and refreshers — networking, security, tooling
00 Certification — Fortinet NSE
NC

Fortinet NSE Track

210 practice questions across NSE 1–4, with a level-by-level progress tracker. Start here.

OPEN →
N1

NSE 1 — Security Awareness

25 questions — threat landscape, social engineering, security hygiene basics.

OPEN →
N2

NSE 2 — Technical Intro

25 questions — SIEM, sandbox, NGFW, SD-WAN, cloud/endpoint security, Fortinet ecosystem.

OPEN →
N3

NSE 3 — FortiGate Operator

60 questions — interfaces, policies, NAT, security profiles, basic VPN, logging, GUI ops.

OPEN →
N4

NSE 4 — FortiOS Administrator

100 questions, weighted toward policy/NAT, VPN, security profiles, routing, SD-WAN, HA, FSSO.

OPEN →
01 Practice Plans — Pick Your Track
FT

Full Target-Role Track

30 sheets, ordered for the specific Senior Network & Security Engineer role — start here if that's your interview.

OPEN →
NE

Network Engineer

18 sheets — OSI foundations, switching, routing/WAN, wireless, role interview prep, and a mock interview drill.

OPEN →
FS

Firewall / Security Engineer

13 sheets — firewall internals, VPN, WAN path, the protocols a perimeter engineer lives in daily, role interview prep, and a mock interview drill.

OPEN →
SA

SOC / Security Ops Analyst

11 sheets — detection and response, vulnerability management, wireless security, alert-triage context, role interview prep, and a mock interview drill.

OPEN →
DO

DevOps Engineer

16 sheets — Git, Python, Ansible, Terraform, and Kubernetes reference and mechanism sheets, plus role interview prep and a mock interview drill.

OPEN →
02 Networking — OSI Model
L1

Layer 1 — Physical

PC to switch connectivity: cabling, signaling, ports, link lights.

OPEN →
L2

Layer 2 — Data Link

Switching, VLANs, and Spanning Tree Protocol.

OPEN →
L3

Layer 3 — Network

IP addressing, routing, and subnetting.

OPEN →
L4

Layer 4 — Transport

TCP, UDP, ports, and the handshake/teardown flow.

OPEN →
L5

Layer 5 — Session

Sessions and dialog control between hosts.

OPEN →
L6

Layer 6 — Presentation

Data representation, encoding, and TLS.

OPEN →
L7

Layer 7 — Application

HTTP, DNS, and application-layer protocols.

OPEN →
BG

BGP-4

Cisco IOS-XE & Arista EOS BGP config and troubleshooting.

OPEN →
OS

OSPF

Neighbor FSM, DR/BDR election, area types, LSAs, cost, and adjacency troubleshooting.

OPEN →
MP

MPLS

Label push/swap/pop, LDP, PHP, label header, and BGP/MPLS L3VPN (RD/RT) walkthrough.

OPEN →
03 Security
FW

Firewall

Concepts, interview Q&A, and vendor notes.

OPEN →
PT

Pentest & Vuln Assessment

Authorized-testing lifecycle — scope/RoE, recon, nmap, enumeration, exploitation, post-ex, OWASP web, CVSS, and reporting.

OPEN →
04 Tooling
GT

Git

Local workflow, branching, and remote sync — one page, every day.

OPEN →
AN

Ansible

Inventory, playbooks, modules, and Vault — one page, every day.

OPEN →
PY

Python

Scripting and automation — envs, syntax, files/OS, requests, and data handling.

OPEN →
K8

Kubernetes

kubectl, workloads, debugging, services, and config — one page, every day.

OPEN →
TF

Terraform

HCL, workflow, state management, modules, and workspaces — one page, every day.

OPEN →
MK

MikroTik

RouterOS on RB4011, RB5009 & L009UiGS-RM — interfaces, routing, firewall, VPN, backup.

OPEN →
CS

Cisco IOS / IOS-XE

CBS350, Catalyst 1000, Catalyst 9300 & ISR routers — VLANs, routing, STP, ACLs, stacking, backup.

OPEN →
MA

MikroTik Automation

RouterOS API/REST, Python/Ansible libraries, guardrails, and 10 project blueprints — backup manager to AI assistant.

OPEN →
WS

Wireshark

Capture/display filters, following streams, TCP analysis, statistics, tshark, and TLS decryption — one page, practical.

OPEN →
ED

EDR

Telemetry, IOC vs IOA, MITRE ATT&CK map, investigation workflow, KQL/FQL/osquery hunt queries, and response actions.

OPEN →
TS

General Troubleshooting

Universal method, OSI symptom map, cross-platform network toolkit, Windows/Linux essentials, HTTP & network error codes.

OPEN →
LX

Linux Server Commands

Day-to-day sysadmin toolkit — files, users/permissions, processes, systemd, networking, firewall, storage, packages, SSH, and troubleshooting.

OPEN →
05 AI / LLM
AI

AI & LLM Field Guide

Core concepts, request lifecycle, provider landscape, prompt engineering, RAG, embeddings, agents/MCP, fine-tuning vs RAG, API essentials, evaluation, and the OWASP Top 10 for LLM apps.

OPEN →
06 Interview Prep — Target Role
NW

Network & Firewall Ownership

Why they'll ask, likely questions & scenarios for the branch network, firewall estate, and DR programme you'd inherit.

OPEN →
SO

Security Operations & Vendor Mgmt

SOC/EDR triage, vulnerability & patch management, wireless estate, and vendor governance interview prep.

OPEN →
NR

Network Engineer — Role Interview

Troubleshooting scenarios, design/ops Q&A, STAR behavioral prep, red flags, and questions to ask them.

OPEN →
FR

Firewall / Security Engineer — Role Interview

Policy design and incident-response scenarios, STAR behavioral prep, red flags, and questions to ask them.

OPEN →
SR

SOC Analyst — Role Interview

Alert-triage and escalation scenarios, STAR behavioral prep, red flags, and questions to ask them.

OPEN →
DR

DevOps Engineer — Role Interview

CI/CD and IaC scenarios, STAR behavioral prep, red flags, and questions to ask them.

OPEN →
07 Interview Simulations — Mock Interview Drills
NS

Network Engineer — Mock Interview

Random-draw troubleshooting, design/ops, and behavioral questions, self-rated, with a per-category weak-spot breakdown.

OPEN →
FS

Firewall / Security Engineer — Mock Interview

Random-draw policy design, incident response, and behavioral questions, self-rated, with a per-category weak-spot breakdown.

OPEN →
SS

SOC Analyst — Mock Interview

Random-draw alert-triage, escalation, and behavioral questions, self-rated, with a per-category weak-spot breakdown.

OPEN →
DS

DevOps Engineer — Mock Interview

Random-draw CI/CD, IaC, and behavioral questions, self-rated, with a per-category weak-spot breakdown.

OPEN →
08 Fundamentals — End-to-End Connectivity
PI

PC to Internet

What really happens, step by step, from cable-in to a page loading — link, DHCP, ARP, routing, NAT, firewall, and back.

OPEN →
UP

URL to Page Load

DNS, TCP handshake, TLS handshake, HTTP request/response, and browser render — in the order they actually happen.

OPEN →
SV

Same VLAN, Same Switch

ARP resolution and the first ping, purely at Layer 2 — no gateway, no routing, no firewall involved.

OPEN →
PP

Two PCs, Four Topologies

Direct cable → one switch → one router → two routers + firewall — when MAC addresses actually change, when they don't, and why.

OPEN →
IV

Different VLANs, Same Switch

What changes when the destination isn't local — 802.1Q tagging, router-on-a-stick / SVI, and re-framing between VLANs.

OPEN →
09 Fundamentals — Switching / Layer 2 Mechanics
UF

Unknown Unicast Flooding

What a switch does with a MAC it's never learned or has aged out — learning, flooding, and the CAM table lifecycle.

OPEN →
PS

STP Port States on Plug-In

Why a fresh port takes ~30-50s to pass traffic — Blocking, Listening, Learning, Forwarding, and the PortFast shortcut.

OPEN →
LP

A Loop Forms — STP Stops It

Root bridge election, root/designated ports, and why exactly one port gets blocked — physical loop, logical tree.

OPEN →
10 Fundamentals — Routing / WAN / Firewall Path
BW

Branch to Public Website

The multi-site version — SD-WAN path selection, centralized breakout at HQ, and why NAT happens far from the branch.

OPEN →
FP

Inside the Firewall

Session lookup, fast path vs. slow path, policy match, NAT, and security profiles — one packet's full internal journey.

OPEN →
CF

Metro Fiber Circuit Down

Gray failures vs. hard failures, BFD detection, and automatic reroute — from fiber cut to (maybe) failback.

OPEN →
11 Fundamentals — DNS / TLS / TCP
DT

DNS to First Encrypted Byte

The resolver hierarchy and the TLS handshake, message by message — recursive vs. iterative, SNI, OCSP stapling, 1-RTT.

OPEN →
TH

TCP Three-Way Handshake

SYN, SYN-ACK, ACK, the half-open state in between, and exactly what happens if the final ACK never arrives.

OPEN →
SD

Split DNS

Why internal and external resolution diverge — separate authoritative zones, split-horizon design, and how to diagnose which.

OPEN →
12 Fundamentals — VPN
VP

Site-to-Site VPN

IKE Phase 1, Phase 2, SAs, and SPIs — from interesting traffic triggering negotiation to ESP passing real data.

OPEN →
13 Fundamentals — Wireless
WE

WPA2-Enterprise Wi-Fi

802.1X roles, EAP/RADIUS mutual auth, and the 4-way handshake — from association to a fully open, encrypted port.

OPEN →
WR

Wi-Fi Roaming Mid-Call

802.11r/k/v — neighbor reports, Fast BSS Transition, and why the roam decision is always the client's, not the network's.

OPEN →
14 Fundamentals — Security / SOC
EI

Malicious Process to Isolation

Behavioral IOA detection, process-tree lineage, and host-level network containment — how EDR actually responds.

OPEN →
VS

Vulnerability Scanner Flags a Host

Discovery, fingerprinting, credentialed enumeration, and CVSS scoring — and why a finding isn't proof of exploitability.

OPEN →
15 Fundamentals — DR / Failover
DR

DR Failover

RTO/RPO, database promotion as the riskiest step, DNS/GSLB cutover, validation, and why failback is never rushed.

OPEN →
16 Fundamentals — DevOps / Automation Mechanics
AP

Ansible Playbook Run

From ansible-playbook to a host actually changing — parse, inventory, connect, facts, module push, execute, handlers.

OPEN →
AI

Ansible Changed vs OK

How idempotency actually works — module inspects current state, compares to desired, and decides changed or ok.

OPEN →
PS

Running a Python Script

Parsing, bytecode compilation, the import system, the GIL, and the exit code — from python script.py to done.

OPEN →
PP

pip install Inside a Virtualenv

Why the same command installs somewhere completely different depending on one thing — whether a venv is active.

OPEN →
KA

kubectl apply to Running Pod

From a YAML manifest to a container serving traffic — API server, etcd, scheduler, kubelet, and the readiness gate.

OPEN →
CB

Pod Stuck in CrashLoopBackOff

The exponential-backoff restart mechanism behind the status message, and exactly where to look to diagnose it.

OPEN →
SR

Kubernetes Service to Pod

Why a ClusterIP isn't a real address — the kube-proxy/iptables DNAT mechanism that makes it work anyway.

OPEN →
TA

terraform apply

Refresh, dependency graph, plan, confirmation, and incremental state writes — from HCL to real infrastructure.

OPEN →
TL

Two Engineers Run terraform apply

The state-locking mechanism — DynamoDB conditional writes — that stops two concurrent applies from corrupting state.

OPEN →
No topics match that filter.