An audit lists every bridge in a backbone: how do you decide which new spans to fund?
answer
- only a cycle clears a bridge
- the new span must cross the cut
- rank by what each split isolates
- no bridges still allows cut vertices
- one span at a site caps everything
basics
~20 sFund the spans that put bridges on cycles, ranked by what each bridge separates. A span only helps if it creates a second route across the cut; clearing every bridge still leaves cut vertices, which is a separate exposure to price.
solid answer
~50 sA bridge is a span lying on no cycle, so the only way to clear one is a new span that creates a cycle across it — a genuinely diverse second route between the two sides, not another link inside one side. Rank the list by **blast radius**: the sizes and importance of the two components each bridge would leave behind, since the goal is not a tidy list but bounded damage. Then be honest about two limits. Clearing every bridge gives a network where no single span cut splits anything, but **cut vertices can survive that**, so site-level exposure needs its own decision. And a site with a single span can never be protected without a second span reaching it, because no site can tolerate more span failures than it has spans. Some bridges — a spur to one remote site — are worth keeping deliberately.
go deeper
Recall the mechanism the decision rests on: a span stops being a bridge only once it lies on a cycle, so a useful new span must cross the split.
Explain which additions clear which bridges, including why one span across a chain of bridges clears all of them at once.
Rank the list by blast radius and route diversity, and say what remains exposed after the spend rather than reporting the list as cleared.
Own the trade: decide which bridges are deliberately kept, separate span-level from site-level exposure, and state the limit that single-span sites impose on any promise you make.
## What the list is, and what it is not The audit's list contains every span that lies on no cycle: cut it, and the two sides can no longer reach each other. It is an exact, complete statement about single-span failures, and it is silent about everything else — traffic, capacity, site failures, and how bad each split would be. The engineering decision is made by combining the list with the things it does not contain. ## The only structural move that clears a bridge Because a span stops being a bridge exactly when it lies on a cycle, a new span clears a given bridge **if and only if** it joins a site on one side of that bridge to a site on the other. That single rule disposes of most proposals: - a new span between two sites already on the same side clears nothing, however expensive or fast it is; - a new span across the cut clears that bridge, and clears **every other bridge** on the route it closes, since all of them now sit on the same cycle; - physical diversity matters as much as the graph: two spans in one trench are one edge as far as a single failure is concerned, and modelling them as two is how a network looks 2-connected on paper and behaves as a chain in the field. The second point is where the money is: one well-placed span across a long chain of bridges can clear the whole chain, so the list should be read as chains to be closed rather than as independent items. ## Ranking what to fund No real budget clears every bridge, so the list needs an order. The things worth ranking on: 1. **Blast radius** — how many sites, and which, end up on the smaller side. A bridge splitting the network in half is not comparable to one isolating a single remote site. 2. **Chain closure** — whether one new span clears several bridges at once, which is usually the best value on the list. 3. **Diversity of the proposed route** — whether the new span shares a trench, a duct or a single building with the span it is meant to back up. 4. **What remains after the spend** — clearing a bridge whose two sides still hang off a single shared site converts a span exposure into a site exposure rather than removing it. ## Two limits to state out loud **Spans are not sites.** A network with no bridges survives any single span cut. It can still have a **cut vertex** — two rings sharing one site have no bridge at all, yet losing the shared site splits the network. Span-level and site-level resilience are separate targets, and money spent on one does not automatically buy the other. Which one to buy is a judgment about the failure modes you actually see: duct cuts and fibre breaks are span failures, while power, fire and building access are site failures. **No site tolerates more failures than it has spans.** A site with one span is separable by that one cut, full stop — the network's tolerance to span failures can never exceed the smallest number of spans at any site. So a plan that promises single-failure survival while leaving single-homed sites in place is promising something the graph forbids, and the only fix for such a site is a second span reaching it. | target | what it means | what it does not buy | |---|---|---| | no bridges | every span lies on a cycle; any one cut leaves the network whole | nothing about losing a **site** | | no cut vertices | any one site can be lost and the rest stay joined | nothing about capacity after rerouting | | second span to every site | the smallest degree stops being the limit | diversity, if both spans share a trench | Note the direction of one implication: on a connected network of three or more sites, no cut vertices does imply no bridges, but the reverse is false. Site-level resilience is the stronger property. ## Deciding to keep a bridge This is the part that makes the question a judgment call rather than an exercise. Some bridges should stay: - a spur to one low-value site, where a second route costs more than the outage it prevents; - a span whose only realistic second route shares the same physical path, so the spend buys a diagram and not resilience; - a leg due for decommissioning, where the right answer is to move the dependants rather than to arm the link. The defensible output of the review is therefore not "clear the list" but a short document: which bridges are funded and what each new span closes, which are accepted with the blast radius written down, and which exposures are site-level rather than span-level and so are not addressed by span spend at all. The graph gives an exact answer to *what is exposed*; it does not decide *what is worth paying for*, and pretending otherwise is how a redundancy programme runs out of money halfway down the list.
- Does clearing every bridge mean the network survives any single failure?Only any single span failure. Cut vertices can survive a bridge-free design — two rings sharing one site have no bridge, yet losing that site splits the network. Site-level resilience is a stronger and separately funded property.
- Why can a site with one span never be made single-failure tolerant?Because cutting that one span always isolates it, so the network's tolerance to span failures is capped by the smallest number of spans at any site. Raising that cap means physically adding a second, diverse span to the site; no topology elsewhere substitutes for it.
saying these in an interview costs you the question
- Funding a new span that joins two sites on the same side
- Assuming a bridge-free network has no single point of failure
- Counting two spans in one trench as diverse routes
- Treating every bridge as equally urgent regardless of what it isolates
- Promising single-failure survival while leaving single-span sites