CyberHire

25 Incident Response Interview Questions and Answers

25 incident response interview questions with what each one tests and what a strong answer includes, grouped by phase from first alert to post-incident review.

These 25 incident response interview questions are for the person hiring: an incident response lead, security manager or Head of Security. They cover fundamentals, high-pressure scenarios and short hands-on tasks, and each comes with what it tests and what a strong answer includes. A table further down groups them by phase, from the first alert to the post-incident review.

Incident response is judged in the first hour, when the facts are incomplete and every decision has a cost. That is almost impossible to see in a normal interview, so the questions below ask candidates to make decisions, not recite frameworks. For questions that apply to every cyber role, see the main list of cyber security interview questions.

Incident response interview questions on the fundamentals

Use two or three to check the foundations. The scenarios tell you much more about how a candidate behaves when it matters.

QuestionWhat it testsWhat a strong answer includes
1. Walk me through the phases of incident response.StructurePreparation, detection and analysis, containment, eradication, recovery and lessons learned, and an understanding that real incidents loop back through them. A bonus if they know NIST’s 2025 revision of SP 800-61 maps incident response onto the Cybersecurity Framework 2.0 functions.
2. What is the difference between containment and eradication, and why does the order matter?Sequencing under pressureContainment stops the spread; eradication removes the attacker. Eradicating before the full scope is known tips the attacker off, and they come back through a route you missed.
3. What is the order of volatility, and why does it matter?Evidence handlingCollect the most short-lived evidence first: memory and network state before disk, and disk before logs and backups, as set out in RFC 3227. Pulling the plug destroys memory evidence.
4. What is chain of custody, and when does it matter?Legal awarenessA record of who handled each piece of evidence, when and how, backed by hashes. It matters whenever the incident could lead to legal action, an employment case or a regulator’s questions, which is more often than teams expect.
5. What is the difference between an indicator of compromise and an indicator of attack?Detection thinkingAn indicator of compromise is an artefact such as a hash, IP address or domain. An indicator of attack is a behaviour, such as credential dumping. Behaviours survive the attacker changing their infrastructure; artefacts do not.
6. Where do attackers commonly set up persistence on Windows?Practical forensicsRegistry Run keys, scheduled tasks, new services, WMI event subscriptions, Image File Execution Options, startup folders and new accounts. Knows how to check each one.
7. What should an incident response playbook contain?PreparationWhat triggers it, roles, severity criteria, the steps and decision points, who to contact, how evidence is handled, how to communicate, and when the incident can be closed.

Scenario-based incident response interview questions

This is where incident responders separate. Listen for what they do first, what they refuse to do in a hurry, and who they bring in.

QuestionWhat it testsWhat a strong answer includes
8. It is hour one of a ransomware incident. What are your first decisions?Leading under pressureStarts the incident plan, isolates affected network segments without powering machines off, protects and checks the backups, preserves evidence, works out scope and the first infected machine, and moves communication to a separate channel in case email is compromised. Brings in leadership, legal and the insurer early.
9. An urgent email from the “CFO” asked for a wire transfer, and the payment went out 20 minutes ago. What do you do?Business email compromise responseContacts the bank immediately to try to recall the payment, because time decides whether the money comes back. Reports it to the police (Action Fraud in the UK), checks whether the CFO’s mailbox was compromised or just spoofed, preserves the email and looks for other targets.
10. You think the attacker is still in the network. Do you contain now, or watch first?Weighing trade-offsExplains both sides: watching gathers scope but risks more damage, and containing early tips the attacker off. Decides based on what the attacker can reach, and plans a single coordinated removal rather than piecemeal fixes.
11. Legal says the incident may involve personal data. What changes?Regulatory awarenessUnder UK GDPR, a breach likely to risk people’s rights must be reported to the ICO within 72 hours of becoming aware of it, and people must be told directly if the risk is high. Documents decisions and works through legal counsel.
12. The attacker had domain admin rights. How do you know you have got them out?Thorough eradicationResets the krbtgt account twice, resets all privileged accounts, hunts for persistence and backdoor accounts, considers rebuilding domain controllers, and monitors closely afterwards. Is honest about how confident anyone can be.
13. The CEO wants hourly updates during the incident. How do you run communications?Stakeholder managementA named communications lead, a fixed update rhythm, a clear split between facts and unknowns, no speculation, and executive updates kept separate from the technical working calls.
14. You find evidence an employee caused the incident deliberately. What changes?Investigation with careHR and legal take the lead on the employment side, evidence is handled to a legal standard, knowledge is limited to those who need it, and the employee is not tipped off.
15. The backups were encrypted too. What are your options?Recovery under pressureChecks for offline or immutable copies and other sources of the data, rebuilds from clean images, checks for a public decryptor, and prioritises recovery by business impact. Knows that paying is a board, legal and insurer decision, with sanctions to consider, not the responder’s.
16. Your EDR shows the attacker deleting logs on several servers. What does that tell you?Reading attacker behaviourThe attacker knows they may be seen, or is preparing a bigger action. Secures central log copies, assumes more systems are affected, captures memory and speeds up containment.
17. Three weeks later, how do you run the post-incident review?LearningBlameless, built on an agreed timeline, covering what worked, what did not and why. Ends with actions that have owners and dates, updated playbooks and detections, and follow-up until they are done.

Hands-on incident response interview tasks

Short tasks to run in the interview. Prepare the material in advance with demo data. Ten minutes of watching a candidate work through evidence tells you more than an hour of war stories.

TaskWhat it testsWhat a strong answer includes
18. Here are 15 events from three systems. Put them in order and tell me what happened.Timeline buildingNormalises time zones to UTC first, notices clock differences between systems, and tells a clear story with the gaps marked.
19. Here are the registry Run key entries from an infected laptop. Which one is the persistence?Registry forensicsSpots entries running from unusual paths such as AppData or Temp, random or lookalike names, and encoded commands, and explains how they would confirm it.
20. Here is a Windows event log export from one machine. What happened?Reconstructing an intrusionReads the sequence: a logon, privileges assigned, PowerShell started with an execution-policy bypass, a new account added to Administrators, a scheduled task created, then sensitive files accessed.
21. Here is a chain of custody form for a seized laptop. What is wrong with it?Evidence handlingFinds gaps in handling, transfers that were not recorded, missing hashes, times or signatures, and explains why each one could get the evidence thrown out.
22. Here is an email asking HR to change an employee’s bank details. What do you check, and who do you tell?Payroll diversionChecks the sender domain and reply-to address, notices the change request and urgency, insists on verifying with the employee through a known phone number, and warns HR and finance.
23. Write a query to find every machine that ran this malicious file in the last 30 days.Scoping with KQLA working query on process events by file hash, summarised by device and account, with first and last seen times.
24. Here is a process list from a memory capture. Which process is suspicious?Memory analysisSpots a system process name running from the wrong folder or with the wrong parent, unexpected access to the LSASS process, or an unsigned binary posing as a Windows component.
25. Write the first executive update for this incident in five sentences.CommunicationWhat is known, the business impact, what is being done, when the next update will come, and any decision needed from the reader. No jargon, no guessing.

For task 23, a reasonable answer in Microsoft Defender or Sentinel looks like this:

DeviceProcessEvents
| where Timestamp > ago(30d)
| where SHA256 == "<hash from the investigation>"
| summarize FirstSeen = min(Timestamp), LastSeen = max(Timestamp), Runs = count() by DeviceName, AccountName

A strong candidate will add that the file may have been present without running, and check file events as well.

Which incident response questions for which phase?

Incident response roles vary in where they focus. Some own the technical investigation, others lead the response and the people around it. Pick questions from the phases the person will own.

PhaseWhat it coversQuestions to use
PreparationPlaybooks, evidence handling, readiness1, 3, 4, 7
Detection and analysisScoping, forensics, reading attacker behaviour5, 6, 16, 18, 19, 20, 23, 24
Containment, eradication and recoveryStopping the spread, removing the attacker, restoring service2, 8, 10, 12, 15
Communication, legal and reviewExecutives, regulators, HR and lessons learned9, 11, 13, 14, 17, 21, 22, 25

For candidates moving up from a SOC, combine these with the SOC analyst interview questions, which focus on triage and escalation.

What are the red flags in an incident response interview?

  • Wiping and rebuilding first. Destroys the evidence needed to understand scope, and the attacker returns.
  • Powering machines off. Loses memory, which often holds the only trace of what ran.
  • Working alone. No mention of leadership, legal, communications or the wider team.
  • Certainty without evidence. Declares the incident over before the attacker’s access is understood.
  • War stories with no detail. Describes big incidents but cannot say what they personally did, or what they would do differently.

Why a hands-on task beats any incident response interview question

Every answer above is a description of what the candidate would do. Under real pressure, with incomplete evidence, people do something else. The hands-on tasks help, but a short task in an interview is still a long way from a real investigation.

A hands-on assessment puts the candidate in front of real evidence and makes them reach a conclusion.

portal.cyber-hire.com/challenge/powershell Windows PowerShell Incident response interview alternative: a PowerShell forensics challenge with a live terminal showing Get-WinEvent output, including a 4624 logon, 4672 special privileges, PowerShell launched with an execution-policy bypass and a hidden window, a new account created and added to Administrators, a scheduled task named WindowsUpdate, and access to an HR spreadsheet and a backup archive.
A complete intrusion in ten log lines. The candidate has to reconstruct what happened from the events themselves. This is task 20, done for real.

Used before the interview, this shows you who can work an incident. The interview then focuses on leadership, communication and the calls they would make.

Frequently asked questions

What questions are asked in an incident response interview?

Expect questions on the phases of incident response, evidence handling and persistence, followed by scenarios such as ransomware, business email compromise or an insider. Good interviews also include a hands-on task, such as building a timeline from logs or reviewing a chain of custody form.

What does an incident responder do?

An incident responder investigates confirmed or suspected security incidents, works out their scope, contains and removes the attacker, and helps restore normal operations. Senior responders also lead the response: coordinating teams, advising leadership and handling legal and regulatory duties.

What are the phases of incident response?

The classic model is preparation, detection and analysis, containment, eradication and recovery, and post-incident activity. NIST’s current guidance, SP 800-61 Revision 3, maps the same work onto the Cybersecurity Framework 2.0 functions.

What skills does an incident responder need?

Technical skills in forensics, log analysis and attacker techniques, plus judgement under pressure and clear communication. The second set is harder to find and harder to interview for, which is why scenarios matter more than definitions.

How CyberHire tests incident responders before the interview

CyberHire is cyber technical screening that shows you who makes the right call before you book an interview. Pick the ready-made incident response assessment or paste your job specification and generate one. Candidates make real decisions and work real evidence: hour-one ransomware containment, the first 30 minutes of a CFO wire request, chain of custody review, registry and PowerShell forensics, and a payroll diversion email.

Every candidate is scored the same way, with integrity signals next to each score, and you see their reasoning, not just a number. See how it works for incident response hiring. If you would rather not build the assessment yourself, our team will build it with you.

Hiring an incident responder?

See who makes the right call before you interview anyone.

Send us the job spec. Within 48 hours we send you a hands-on assessment built around it, in your branding, free. Real containment decisions and real forensic evidence, scored the same way for every candidate.

Get a free assessment Request a sample report