HomeSubjectsUniversityBlogAbout

NSCT Networks and Cloud Revision: Concepts and Worked MCQs

By Published

Networking questions look like recall, but many hide a small calculation or a single word that changes the answer. "Segment" or "packet"? "Usable hosts" or "addresses"? "Service model" or "deployment model"? This guide revises the networking and cloud topics most worth your time, with worked MCQs that show the reasoning and explain why each distractor fails.

Computer Networks & Cloud Computing is one of the NSCT competency areas. HEC runs the test, and Virtual University of Pakistan is the testing body. The weightage published for the NSCT syllabus lists this area at 10%; confirm it in the official student guide on nsct.hec.gov.pk. The NSCT syllabus page maps each competency area to practice topics.

OSI vs TCP/IP

The OSI model has seven layers and is mainly a teaching and reference model. The TCP/IP model has four layers and describes how the internet actually works. A useful mnemonic for OSI, bottom to top: Please Do Not Throw Sausage Pizza Away (Physical, Data Link, Network, Transport, Session, Presentation, Application).

OSI layer Main job TCP/IP layer PDU name Examples
7 Application Network services for applications Application Data HTTP, DNS, SMTP, FTP
6 Presentation Encoding, compression, encryption Application Data Data formats such as JPEG, ASCII
5 Session Opening, managing and closing sessions Application Data RPC, NetBIOS
4 Transport Process-to-process delivery, ports Transport Segment (TCP) / datagram (UDP) TCP, UDP
3 Network Logical addressing and routing Internet Packet IP, ICMP; routers
2 Data Link Framing, MAC addressing, error detection Link Frame Ethernet, 802.11; switches
1 Physical Transmitting raw bits Link Bits Cables, signals; hubs, repeaters

Remember the devices: a hub works at layer 1, a switch at layer 2 (MAC addresses) and a router at layer 3 (IP addresses). An IPv4 address is 32 bits; an IPv6 address is 128 bits; a MAC address is 48 bits.

TCP vs UDP

Feature TCP UDP
Connection Connection-oriented (handshake first) Connectionless
Reliability Acknowledgements and retransmission No delivery guarantee
Ordering In-order delivery No ordering
Flow and congestion control Yes No
Header size 20 to 60 bytes 8 bytes
Typical use Web, email, file transfer, SSH DNS queries, streaming, VoIP, online games, DHCP

Common ports: FTP 20/21, SSH 22, Telnet 23, SMTP 25, DNS 53, DHCP 67/68, HTTP 80, HTTPS 443.

The Three-Way Handshake

  1. The client sends SYN with its initial sequence number (ISN), say x.
  2. The server replies SYN-ACK with its own ISN y and acknowledgement number x + 1.
  3. The client sends ACK with acknowledgement number y + 1.

A SYN consumes one sequence number even though it carries no data, which is why the acknowledgement is ISN + 1. Connection teardown normally uses FIN and ACK in each direction (four segments).

Worked Example 1: Handshake Numbers

Question: A client starts a TCP connection with ISN 1000. The server's ISN is 5000. What acknowledgement number does the server's SYN-ACK carry?

  • A) 1000
  • B) 1001
  • C) 5000
  • D) 5001

Answer: B. The server acknowledges the client's SYN, which consumed sequence number 1000. The next byte it expects is 1001.

Why the others are wrong: 1000 forgets that SYN consumes a sequence number. 5000 is the server's own sequence number in the same segment, not its acknowledgement. 5001 is the acknowledgement number the client sends in the final ACK. More questions like this are in Transport Layer.

DNS, HTTP and HTTPS

DNS translates domain names into IP addresses. It uses port 53, mostly over UDP; TCP is used for zone transfers and for responses too large for UDP. A typical lookup goes from your device to a recursive resolver, which queries a root server, then the TLD server (such as .pk), then the domain's authoritative server.

Record types to know: A (IPv4 address), AAAA (IPv6 address), CNAME (alias), MX (mail server), NS (name server), PTR (reverse lookup).

HTTP is a stateless request-response protocol. Cookies and sessions add state on top of it. Know the methods (GET, POST, PUT, DELETE, PATCH) and the status classes: 2xx success, 3xx redirection, 4xx client error, 5xx server error. GET, PUT and DELETE are idempotent; POST is not.

HTTPS is HTTP over TLS, usually on port 443. TLS gives confidentiality, integrity and server authentication through certificates. Asymmetric cryptography is used during the handshake to authenticate and agree on keys; the bulk data is then encrypted with faster symmetric encryption. Revise these under Application Layer.

Subnetting

The prefix length says how many bits identify the network. The remaining h host bits give 2^h addresses per subnet, of which 2^h − 2 are usable, because the first address is the network address and the last is the broadcast address.

Worked Example 2: Splitting a /24 into /26 Subnets

Take 192.168.10.0/24 and subnet it with a /26 prefix.

  • Mask: /26 = 255.255.255.192 (the last octet borrows 2 bits: 128 + 64).
  • Host bits: 32 − 26 = 6, so 2^6 = 64 addresses per subnet and 62 usable hosts.
  • Number of subnets: 2^2 = 4, with a block size of 256 − 192 = 64.
Subnet Network address Usable host range Broadcast
1 192.168.10.0 .1 to .62 192.168.10.63
2 192.168.10.64 .65 to .126 192.168.10.127
3 192.168.10.128 .129 to .190 192.168.10.191
4 192.168.10.192 .193 to .254 192.168.10.255

MCQ: What is the broadcast address of the subnet containing host 192.168.10.150/26?

  • A) 192.168.10.127
  • B) 192.168.10.191
  • C) 192.168.10.255
  • D) 192.168.10.150

Answer: B. Blocks of 64 start at 0, 64, 128 and 192. 150 falls in the 128 block, which runs from 128 to 191, so the broadcast is .191.

Why the others are wrong: .127 is the broadcast of the previous block. .255 is the broadcast of the whole /24, the answer you get if you ignore the /26. .150 is the host itself.

Quick checks:

  • A /27 has 32 − 2 = 30 usable hosts; a /30 has 2, which suits point-to-point links.
  • For a LAN of 50 hosts, you need 2^h − 2 ≥ 50, so h = 6 and the prefix is /26. Five host bits give only 30 usable hosts, which is too few.
  • Private IPv4 ranges: 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16.

Worked Example 3: Route Summarisation

Question: Which single prefix summarises 200.10.0.0/24, 200.10.1.0/24, 200.10.2.0/24 and 200.10.3.0/24 with no extra addresses?

  • A) 200.10.0.0/16
  • B) 200.10.0.0/22
  • C) 200.10.0.0/23
  • D) 200.10.0.0/24

Answer: B. The third octets 0 to 3 are 00000000 to 00000011 in binary. The first 6 bits of the third octet match, so the common prefix is 8 + 8 + 6 = 22 bits. A /22 covers exactly 4 × 256 = 1,024 addresses.

Why the others are wrong: /16 covers 256 /24 networks, far more than needed. /23 covers only two of them. /24 covers one. This kind of aggregation is what CIDR was designed for; see RFC 4632.

Routing Basics

A router forwards each packet using its routing table and the longest prefix match rule: when several entries match, the most specific one wins.

  • Static routing is configured by hand; dynamic routing uses protocols to learn routes.
  • Distance vector (for example RIP): routers share tables with neighbours and use Bellman-Ford. RIP uses hop count, and 16 hops means unreachable.
  • Link state (for example OSPF): each router builds a full topology map and runs Dijkstra's algorithm.
  • Path vector (BGP): routes traffic between autonomous systems on the internet.
  • IPv4's TTL field is decremented at each router. When it reaches zero, the packet is discarded, which stops routing loops.

Worked Example 4: Longest Prefix Match

Question: A router's table has these entries: 10.0.0.0/8 goes to interface A, 10.1.0.0/16 to B, 10.1.2.0/24 to C, and a default route 0.0.0.0/0 to D. Where does a packet to 10.1.2.77 go?

  • A) Interface A
  • B) Interface B
  • C) Interface C
  • D) Interface D

Answer: C. All four entries match, but /24 is the longest prefix. For comparison, 10.1.9.5 goes to B (it matches /8 and /16 but not the /24), and 11.0.0.1 goes to D.

Why the others are wrong: A is the tempting choice because it is the first entry, but table order does not decide. B matches but is less specific than C. D is used only when nothing more specific matches. Practise more under Network Layer.

Wireless Basics

Wi-Fi is defined by the IEEE 802.11 family and commonly uses the 2.4 GHz and 5 GHz bands. Wired Ethernet historically used CSMA/CD (collision detection). Wi-Fi uses CSMA/CA (collision avoidance) instead, because a radio cannot reliably detect a collision while it is transmitting.

The hidden terminal problem happens when two stations can both reach the access point but cannot hear each other. The optional RTS/CTS exchange reduces it. Other terms to know: SSID (network name), infrastructure mode (clients talk through an access point) versus ad hoc mode (devices talk directly). For security, WEP is broken and should not be used; WPA2 uses AES-based encryption, and WPA3 is the newer standard. See Wireless Networks for practice.

Cloud Computing per NIST

NIST SP 800-145 is the definition most textbooks follow. It lists five essential characteristics: on-demand self-service, broad network access, resource pooling, rapid elasticity and measured service.

It defines three service models. The main difference is who manages each layer:

Layer IaaS PaaS SaaS
Application Customer Customer Provider
Runtime and middleware Customer Provider Provider
Operating system Customer Provider Provider
Servers, storage, networking Provider Provider Provider
Examples Amazon EC2, Azure Virtual Machines Google App Engine, Azure App Service Gmail, Microsoft 365

In SaaS, the customer still controls its own data and limited user-specific settings. Serverless platforms such as AWS Lambda are often grouped close to PaaS, but NIST SP 800-145 does not define a separate serverless model.

It also defines four deployment models:

  • Private cloud: used by a single organisation.
  • Community cloud: shared by organisations with common concerns, such as a group of universities.
  • Public cloud: open to the general public, owned by a cloud provider.
  • Hybrid cloud: two or more distinct clouds bound together, allowing data and application portability (for example, bursting from private to public during peak load).

Virtualisation underpins all of this. A Type 1 hypervisor runs directly on the hardware (VMware ESXi, Microsoft Hyper-V). A Type 2 hypervisor runs on a host OS (VirtualBox, VMware Workstation). Containers share the host kernel, so they are lighter than virtual machines.

Worked Example 5: Service Model

Question: A startup uploads its code to a platform that handles the operating system, runtime, patching and scaling. The startup manages only its application and data. Which model is this?

  • A) IaaS
  • B) PaaS
  • C) SaaS
  • D) Community cloud

Answer: B. The provider manages everything below the application, while the customer deploys and manages its own code. That matches NIST's definition of PaaS.

Why the others are wrong: In IaaS, the startup would manage the OS and runtime itself. In SaaS, it would use finished software rather than deploy its own code. Community cloud is a deployment model, not a service model, so it answers a different question. This service-versus-deployment mix-up is a frequent trap. The NIST definition is only a few pages long and worth reading once. Then practise with Cloud Computing MCQs.

Quick Revision Checklist

  • PDUs: bits, frames, packets, segments (TCP) or datagrams (UDP).
  • The SYN-ACK acknowledges the client's ISN + 1.
  • DNS uses port 53, mostly UDP; HTTPS is HTTP over TLS on port 443.
  • Usable hosts = 2^h − 2; find the block size with 256 minus the last non-zero mask octet.
  • Longest prefix match beats table order.
  • Wi-Fi uses CSMA/CA; classic Ethernet used CSMA/CD.
  • NIST gives 5 characteristics, 3 service models and 4 deployment models.

When you can explain each worked example without looking, move on to timed practice. The Computer Networks & Cloud practice area is part of NSCT Prep's 33,808+ free MCQs with explanations. Redo every subnetting question you miss until the block-size method is automatic.