CyberHire

30 Cyber Security Interview Questions (With Strong Answers)

30 cyber security interview questions for hiring managers, with what each one tests and what a strong answer includes. Plus a free scorecard to rate candidates.

These 30 cyber security interview questions are for the person running the interview: a hiring manager, SOC lead or Head of Security. They are grouped into fundamentals, scenarios and hands-on tasks, and each one comes with what it tests and what a strong answer includes, so you can score candidates against the same bar.

Most lists of cyber security interview questions stop at definitions. Definitions are the easiest thing for a candidate to rehearse and the least useful thing for you to hear. The questions below lean towards judgement and real work, because that is what separates the candidate who has done the job from the one who has read about it.

How to use these cyber security interview questions

Pick five to eight questions that match the role, and ask every candidate the same ones in the same order. Decide what a strong answer looks like before the first interview, not after. Consistency matters more than the questions themselves: an interview where every candidate gets a different conversation produces impressions, not evidence. The research on this is clear, and it is summarised in work samples vs interviews.

Use the three groups for different jobs:

  • Fundamentals check that the foundations are there. Use two or three, not ten.
  • Scenarios show judgement: what the candidate does first, what they check, and when they escalate.
  • Hands-on tasks give the candidate something real to work on in the interview: a log, a query, a header, a piece of code.

Hiring for a specific role? Start with the role’s own set, then add general questions from below:

Fundamentals: questions that check the foundations

QuestionWhat it testsWhat a strong answer includes
1. What happens when you type a URL into a browser and press Enter?Networking depthDNS resolution, the TCP handshake, the TLS handshake and certificate check, then the HTTP request. Strong candidates also say where security controls sit along the way, such as DNS filtering, a proxy or TLS inspection.
2. What is the difference between encryption, hashing and encoding?Core concepts, used correctlyEncryption is reversible with a key. Hashing is one-way and is used for integrity and, with a salt and a slow algorithm such as bcrypt or Argon2, for passwords. Encoding, such as Base64, is a format with no security value.
3. Explain confidentiality, integrity and availability using a real incident.Applying a framework, not reciting itMaps an incident to all three. Ransomware with data theft hits availability and confidentiality at once. A weak answer gives three textbook definitions.
4. What does TLS protect, and what does it not protect?Understanding limitsProtects data in transit and authenticates the server. Does not protect the endpoints, data at rest, or metadata such as IP addresses and, usually, the domain being visited.
5. What is least privilege, and where have you seen it broken?Experience behind the principleA concrete example: standing admin rights, a service account with domain admin, or a cloud role with wildcard permissions. Then the fix, such as just-in-time access or regular access reviews.
6. What is the difference between authentication and authorisation, and which MFA methods would you trust?Identity basics, current threatsAuthentication proves who you are; authorisation decides what you can do. Prefers phishing-resistant MFA (FIDO2 security keys or passkeys) over SMS or push, and knows why: push fatigue and adversary-in-the-middle phishing.
7. Where are symmetric and asymmetric encryption each used?Practical cryptographyTLS uses both: asymmetric cryptography to authenticate and agree a key, symmetric encryption for the data itself, because it is much faster.
8. What is the difference between a vulnerability, a threat and a risk?Risk thinkingA vulnerability is a weakness, a threat is something that could exploit it, and risk is the likelihood and impact of that happening. Gives an example that shows why one vulnerability can be high risk in one place and low risk in another.
9. How would you explain lateral movement to a non-technical manager?CommunicationA plain-language analogy and why it matters: the first compromised machine is rarely the target. No jargon.
10. Which Windows logs would you want from an endpoint during an investigation, and why?Practical logging knowledgeSecurity log events such as 4624 and 4625 (logons), 4688 (process creation, with command line), 4720 (account created) and 4769 (Kerberos service tickets), plus PowerShell script block logging (4104) and Sysmon.

Scenario-based cyber security interview questions

Scenarios are where interviews earn their keep. Listen for the order of actions: what the candidate contains first, what they check before acting, and when they bring other people in.

QuestionWhat it testsWhat a strong answer includes
11. A user clicked a link in an email and entered their password. What do you do in the first 30 minutes?Incident triageReset the password and revoke active sessions, because session tokens can survive a reset. Check sign-in logs for new locations, new MFA methods and new inbox forwarding rules. Find and purge the email for other recipients. Resetting the password alone is a red flag.
12. One IP address fails to log in to 200 accounts in an hour, then one login succeeds. What is happening, and what do you do?Recognising an attack patternIdentifies password spraying. Prioritises the account that succeeded: what it did next and what it can access. Then blocks the source and checks for the same pattern elsewhere.
13. An EDR alert fires on a suspicious PowerShell command. The user says IT asked them to run a script. How do you decide?Verification, not trustDecodes the command, checks the parent process and network connections, and confirms with IT through a separate channel, such as a change ticket, rather than taking the user’s word. Contains the machine if in doubt.
14. A critical vulnerability with a public exploit is announced on a Friday afternoon and affects an internet-facing system. What do you do?Prioritisation under pressureConfirms which systems are actually exposed, checks whether it is being exploited in the wild (for example on CISA’s Known Exploited Vulnerabilities list), applies the patch or a mitigation, adds monitoring, and makes sure the right person signs off any accepted risk.
15. You find a service account with domain admin rights and a password that has not changed in six years. What do you do?Fixing without breaking thingsDoes not just reset it and break production. Finds what depends on it, reduces its privileges, moves it to a managed service account where possible, and monitors it meanwhile. Mentions the Kerberoasting risk of old service account passwords.
16. Your CEO asks whether the company is safe from a ransomware group in the news. How do you answer?Honest, threat-led reasoningAvoids a yes or no. Maps the group’s known techniques to MITRE ATT&CK, checks which ones you can prevent or detect, and reports the gaps plainly.
17. A developer has pushed an API key to a public GitHub repository. What now?Correct order of responseRevokes and rotates the key first: deleting the commit is not enough, because history and automated scrapers keep it. Checks the key’s usage logs for abuse, scans for other exposed secrets, then adds secret scanning to prevent a repeat.
18. You are on call and get an alert at 2am that you are not sure is real. How do you decide whether to wake someone?Escalation judgementWeighs potential impact against confidence, follows the playbook, and escalates when the impact could be high even if confidence is low. Writes down what they saw and why they decided.
19. HR suspects a leaver is taking customer data to a competitor. What do you do?Investigation with legal careInvolves HR and legal before acting, preserves evidence, avoids tipping off the employee, reviews data loss prevention and cloud audit logs, and keeps the investigation proportionate and lawful.
20. A user signs in from London and then from Singapore 20 minutes later. Is that an incident?Context before conclusionsChecks for VPNs, corporate egress points and cloud proxies first. If those do not explain it, treats it as possible session token theft, checks the device and MFA details, and revokes sessions.
21. Your SIEM has shown no alerts at all for six hours. Is that good news?Healthy scepticismSuspects a broken log pipeline before a quiet network. Checks log source health and ingestion volumes.
22. A supplier you use announces a data breach. What do you do on day one?Third-party riskEstablishes what data and access the supplier holds, rotates any shared credentials and API keys, checks logs for the supplier’s access into your systems, and checks contractual and regulatory notification duties.

Hands-on interview tasks: give them something real

These are short tasks to do in the interview itself. Prepare the material in advance: a log excerpt, a policy, a code snippet. Watching a candidate work for ten minutes tells you more than an hour of answers.

TaskWhat it testsWhat a strong answer includes
23. Here are 15 lines of authentication logs. Tell me what happened.Reading raw dataSeparates normal activity from the suspicious lines, builds a timeline, and states how confident they are.
24. Write a query that finds accounts with more than 10 failed logins and at least one success in the last hour.SIEM querying (KQL or SPL)A working query grouped by account and source, and an explanation of its false positives, such as a user with an expired password saved on a phone.
25. Here are the headers from a suspicious email. Is it legitimate?Email analysisReads the SPF, DKIM and DMARC results and compares the From and Return-Path domains. Knows that passing every check does not make an email safe: lookalike domains, compromised genuine senders and OAuth consent phishing all pass.
26. Here is a firewall rule set. What is wrong with it?Configuration reviewSpots any-to-any rules, rules shadowed by earlier ones, overly broad sources and missing logging on deny rules.
27. Decode this encoded PowerShell command and tell me what it does.Endpoint investigationKnows -EncodedCommand takes Base64 of UTF-16LE text, decodes it, and recognises patterns such as a download cradle using DownloadString and IEX.
28. Here are 20 lines of code that query a database. Find the security flaw.Secure code reviewFinds the SQL injection from string concatenation and fixes it with parameterised queries, not input filtering.
29. Here is a cloud IAM policy. What can this identity do?Cloud permissionsSpots wildcards in actions and resources, and permissions that allow privilege escalation, such as letting the identity attach policies to itself or pass a role to a new resource.
30. Write this incident up for an executive in five sentences.Communication under constraintWhat happened, the business impact, what has been done, what happens next, and what decision is needed from the reader. No jargon.

For task 24, a reasonable starting point in Microsoft Sentinel looks like this:

SigninLogs
| where TimeGenerated > ago(1h)
| summarize Failures = countif(ResultType != "0"), Successes = countif(ResultType == "0")
    by UserPrincipalName, IPAddress
| where Failures > 10 and Successes > 0

A strong candidate will point out that this does not check whether the success came after the failures, and say how they would add that.

What are the red flags in a cyber security interview?

  • Definitions with no example. The candidate can define least privilege but cannot describe a time they saw it broken.
  • Acting before scoping. “Block the IP” as the first and only step, without asking what else that IP touched.
  • Never saying “I don’t know”. Confident guessing in an interview becomes confident guessing during an incident.
  • Not knowing the tools on their own CV. If Splunk is on the CV, they should be able to describe a search they wrote.

How should you score cyber security interview answers?

Score each answer against the strong answer you agreed before the interview, not against the other candidates. A simple scale works: Excellent, Good, Poor or Incorrect. Weight harder questions more, so a strong answer to a hard scenario counts for more than a perfect definition.

Write the score down straight after each answer, while it is fresh. Compare candidates only once every interview is finished. The free Cyber Interview Runbook does this arithmetic for you, for up to five candidates, and shows each candidate’s strengths by category.

Why a hands-on task tells you more than any of these questions

Even the best interview question has a weakness: the candidate is describing the work, not doing it. A well-prepared candidate can talk through a phishing investigation fluently without being able to run one. The hands-on tasks above close some of that gap, but they are short, and they depend on the interviewer preparing good material.

A proper hands-on assessment goes further. The candidate works in a real environment, on realistic data with the noise left in, and the answer only exists in the data in front of them.

portal.cyber-hire.com/challenge/email Inbox Cyber security interview task alternative: an email analysis challenge showing a phishing message in a mail client with Email, Headers and Raw Source tabs. The message impersonates Microsoft SharePoint, passes SPF, DKIM and DMARC, and its link points to a genuine login.microsoftonline.com OAuth authorise URL.
SPF, DKIM and DMARC all pass, and the link genuinely goes to login.microsoftonline.com. Every check a candidate learns to recite comes back clean, and it is still an attack. This is question 25, done for real.

Used before the interview, a task like this tells you who can do the work. The interview can then spend its time on judgement, communication and the gaps the assessment found. For how to choose one, see how to choose a cyber hiring assessment.

Frequently asked questions

What questions should I ask in a cyber security interview?

Ask a few fundamentals to check the foundations, then spend most of the time on scenarios and short hands-on tasks matched to the role. Ask every candidate the same questions in the same order, and agree what a strong answer looks like before you start.

How many questions should a cyber security interview include?

Five to eight well-chosen questions in an hour is usually enough. A short hands-on task is worth several verbal questions, because it shows the work rather than a description of it.

Should a cyber security interview include a practical test?

Yes. Talking about an investigation and running one are different skills. A short practical task in the interview, or a hands-on assessment before it, shows you whether the candidate can actually do what they describe.

How do you assess a cyber security candidate without a technical background?

Use questions with agreed strong answers, like the tables above, and score against those answers rather than against how confident the candidate sounds. A hands-on assessment that scores the work automatically removes most of the need for technical judgement on the interview panel.

How CyberHire tests candidates before the interview

CyberHire is cyber technical screening built to answer one question before anyone books an interview: can this candidate do the work? Hiring teams pick a ready-made assessment from a library of 270+ hands-on challenges, or paste a job specification and generate one. Candidates then work in real environments: KQL workspaces, Windows event logs, Linux terminals, email analysis and code review.

Every candidate is scored the same way, with integrity signals next to each score. The hiring team sees a ranked cohort, each candidate’s actual answers, and what to probe in the interview. Your interview then confirms what the evidence already shows, instead of trying to find it. That is the approach behind hands-on technical interviews.

If you would rather not build the assessment yourself, our team will build it with you.

Interviewing for a cyber role?

See what candidates can do before you ask a single question.

Send us the job spec. Within 48 hours we send you a hands-on assessment built around it, in your branding, free. Interview only the people who can do the work.

Get a free assessment Request a sample report