Answers ReadyQuestionsSign in

Interview questions

Cybersecurity interview questions

Blue-team interviews — triage, detection, and the certification-adjacent theory that comes up in SOC screening.

24 questions, and for 9 of them what a good answer has to cover. This is the bank Answers Ready practises you against — the same questions, marked on the same points.

introduction

Tell me about yourself.

What a good answer covers

  • A shape, not a life story: what they do now, one thing they are good at, why this role.
  • Under two minutes.
  • Ends pointed at the job rather than trailing off.

fundamentals

What is the CIA triad?

What a good answer covers

  • Confidentiality, integrity, availability.
  • A real example of each, not just the expansion.
  • Ideally: notes that they trade off against each other.

What is the difference between a vulnerability, a threat and a risk?

What a good answer covers

  • Vulnerability: the weakness. Threat: what could exploit it. Risk: likelihood times impact.
  • One worked example carried through all three.
  • Does not use the words interchangeably.

What does defence in depth mean in practice?

What a good answer covers

  • Layers, so a single control failing is not a breach.
  • A worked example following one attack through several controls.
  • Not just a list of products.

What is zero trust, and what does adopting it actually involve?

Senior. Marked against your own answer in the app.

triage

You get an alert for a successful login from a country the user has never logged in from. Walk me through what you do.

What a good answer covers

  • First action is concrete: check whether there is a session from the usual location at the same time.
  • Was MFA satisfied, and how — push, SMS, token?
  • VPN or travel is a real explanation and should be ruled out, not assumed.
  • What happened after the login — mail rules, downloads, privilege changes.
  • Says when they would disable the account or force a reset, and who they would tell.

A user reports a suspicious email. What do you do with it?

What a good answer covers

  • Headers: sender, return path, SPF/DKIM/DMARC.
  • Detonate links and attachments somewhere safe, not on their own machine.
  • Ask who else received it, and whether anyone clicked.
  • Contain: pull it from mailboxes, block the sender or domain.
  • Tells the user they did the right thing by reporting it.

How do you decide an alert is a false positive?

Mid-level. Marked against your own answer in the app.

Your queue has four hundred alerts in it. How do you work through them?

Mid-level. Marked against your own answer in the app.

incident response

Talk me through the incident response lifecycle.

What a good answer covers

  • Preparation, detection and analysis, containment, eradication, recovery, lessons learned.
  • Says something real about at least one phase rather than reciting the list.
  • Knows containment can be short-term and long-term.
  • Lessons learned is not skipped.

Ransomware is detected on a workstation. What happens in the first hour?

Mid-level. Marked against your own answer in the app.

When would you not immediately isolate a compromised host?

Senior. Marked against your own answer in the app.

tooling

How do you use a SIEM day to day?

What a good answer covers

  • What is actually fed into it, and why log sources matter.
  • Writing or reading a query, not only clicking dashboards.
  • Correlation across sources is the point.
  • Names one they have used and something specific about it.

What does EDR give you that antivirus does not?

Mid-level. Marked against your own answer in the app.

investigation

You are investigating a possible compromise on a Windows machine. Which logs do you want?

Mid-level. Marked against your own answer in the app.

What would lateral movement look like in your logs?

Senior. Marked against your own answer in the app.

An account suddenly has domain admin. How do you work out whether that is legitimate?

Mid-level. Marked against your own answer in the app.

frameworks

How do you use MITRE ATT&CK?

Mid-level. Marked against your own answer in the app.

What is the difference between an IOC and a TTP, and which is more useful?

Mid-level. Marked against your own answer in the app.

vulnerability management

Your scanner reports two thousand vulnerabilities. Where do you start?

Mid-level. Marked against your own answer in the app.

networking

What actually happens when you connect to an HTTPS site?

Mid-level. Marked against your own answer in the app.

How would you spot data being exfiltrated over DNS?

Senior. Marked against your own answer in the app.

communication

Explain to a non-technical manager why we need MFA.

Mid-level. Marked against your own answer in the app.

How do you keep up with what is happening in security?

What a good answer covers

  • Specific sources, named.
  • Something they read recently and what they made of it.
  • A hands-on habit — a lab, a CTF, a homelab — beats a reading list alone.

Practise these out loud

Reading a question is not the same as answering one. You answer these out loud and each answer gets a score, what was missing, and how it could have sounded — against the points above, not against a general impression.

Start free

60 credits when you sign up. No card needed.

Other disciplines