CyberHire

Pre-Employment Cyber Security Tests: Which Kind Works?

Multiple-choice or hands-on? What a pre-employment cyber security test should measure, where each format fails, how long it should be and how to stop gaming.

A pre-employment cyber security test checks whether a candidate has the skills a role needs before you invest interview time in them. There are two main kinds: multiple-choice knowledge tests, which are quick and cheap but measure recall, and hands-on tests, where the candidate works on a real task such as investigating logs or reviewing code. Multiple choice is fine as a quick knowledge gate. It cannot show whether someone can do the job.

This guide explains what each kind measures, where each one fails, how long a test should be, and how to stop candidates gaming it.

What should a pre-employment cyber security test measure?

The skills the person will use in their first months, at the level you are hiring. For a SOC analyst that means triaging alerts and reading logs. For a security engineer, reviewing configuration. For an AppSec engineer, reading code. For a GRC analyst, reviewing vendor reports and risk registers.

A useful test measures three things:

  1. Knowledge: does the candidate know the concepts the role depends on?
  2. Application: can they use that knowledge on real evidence, with the noise left in?
  3. Judgement: when the answer is not obvious, do they reach a sound conclusion and explain it?

Most tests measure the first well. Fewer measure the second. Very few measure the third, and the third is what separates a good hire from an expensive mistake.

Where multiple choice works and where it fails

Multiple-choice test libraries are easy to buy, quick to sit and simple to score. They work in a narrow set of cases.

Multiple choice works forMultiple choice fails at
Checking prerequisite knowledge quicklyShowing whether someone can apply it
Early filtering of a very large poolTelling a strong practitioner from a good test-taker
Roles where knowledge really is the jobInvestigation, configuration and code review
Low-stakes, entry-level gatesSenior roles, where judgement matters most

The core problem is that recall questions have answers that exist outside the test. A candidate can search for them, ask an AI assistant, or simply recognise the right option without being able to produce it. The options themselves give hints that real work never does.

Here is the difference in practice. A typical multiple-choice question:

What is Kerberoasting? A) Brute-forcing Kerberos pre-authentication B) Requesting service tickets to crack service account passwords offline C) Forging a ticket-granting ticket with the krbtgt hash D) Relaying NTLM authentication to a domain controller

Anyone with a search engine gets that right in seconds. Now the hands-on version of the same skill:

portal.cyber-hire.com/challenge/events Event Viewer Pre-employment cyber security test, hands-on version: a Windows Event Log investigation in a real Event Viewer with 146 Security events, asking which account is Kerberoasting when several legitimate sources of RC4 service ticket activity exist.
The same topic as the multiple-choice question, tested as the job. Several accounts legitimately request RC4 service tickets; the candidate has to find the one that is an attack. The answer exists only in this data.

The first question tells you the candidate knows the definition. The second tells you whether they would catch the attack in your environment.

What does a hands-on cyber security test look like?

The candidate works in an environment that resembles the job, on realistic data, and has to find or decide something:

  • SOC and incident response: investigate alerts, sign-ins and endpoint events in a SIEM or event viewer.
  • Email security: triage a phishing email with full headers and raw source.
  • Security engineering: review a firewall rule set, Group Policy or a Linux host.
  • Application security: review code and find the vulnerability.
  • GRC: review a vendor’s assurance report or a risk register.

Good hands-on tests include legitimate activity alongside the malicious kind, because separating the two is the real skill, and use free-text answers where possible so there is nothing to guess between. To see the actual challenges by role, browse the cyber security skills tests. For how to judge a test before you buy, see how to choose a cyber hiring assessment.

Should you combine multiple choice and hands-on tests?

Sometimes. A short knowledge gate before a hands-on task can make sense when you have a very large pool and a role where some knowledge is a hard prerequisite. Keep it brief and set the pass mark low: its job is to remove people who clearly lack the basics, not to rank anyone. Rank on the hands-on results.

For most roles, a well-designed hands-on task does both jobs at once: a candidate without the basic knowledge cannot complete it.

How long should a pre-employment cyber security test be?

Long enough to test the skills that matter, and no longer. As a rule of thumb:

  • Early screening: short and focused on the two or three core skills. Strong candidates with jobs and families will not spend an evening on a first-round test.
  • Later stages: deeper, for a smaller group, when both sides are more invested.

Tell candidates up front how long it takes and what they will do. Clear expectations raise completion rates, especially among the busy, experienced candidates you most want.

How do you stop candidates gaming a cyber security test?

Different formats are vulnerable to different tricks.

RiskMultiple choiceHands-on
Searching for answersHigh: answers exist publiclyLow: answers exist only in the data
Asking an AI assistantHigh: recall questions are easy for AILower: AI cannot see the candidate’s environment
Sharing questionsHigh: fixed banks leakLower: tasks depend on specific data
Someone else sitting itPossiblePossible

Task design does most of the work. Beyond that, use integrity monitoring: time away from the test, pasting from outside, fullscreen exits, second screens, location, and webcam proctoring where the role justifies it. Treat signals as evidence to review, not automatic rejections, and use the interview to confirm the candidate understands their own answers.

Frequently asked questions

What is a pre-employment cyber security test?

It is an assessment candidates complete before or early in the interview process, to check they have the skills a cyber security role needs. It can be a multiple-choice knowledge test, a hands-on task in a realistic environment, or a mix of both.

Are multiple-choice cyber security tests reliable?

They are reliable at measuring recall of facts, and useful as a quick knowledge gate. They are not reliable at measuring whether someone can apply that knowledge to real evidence, which is what most security roles need.

Can candidates use AI to pass a cyber security test?

On recall-based questions, easily. On well-designed hands-on tasks, much less so, because the answer depends on data only the candidate can see. Integrity monitoring adds signals such as pasting from outside the test.

Is it fair to give candidates a test before interviewing them?

Yes, if it is relevant to the job, proportionate in length, explained clearly and scored consistently. A fair test gives every candidate the same chance to show what they can do, including those whose CVs would not have been picked.

How CyberHire runs pre-employment cyber security tests

CyberHire is cyber technical screening built on hands-on tasks. Pick from a library of 270+ challenges or paste your job specification and generate an assessment for the role. Candidates work in real environments, such as KQL workspaces, Windows event logs, Linux terminals, email analysis and code review, and are scored the same way, with integrity signals next to every score.

You see each candidate’s actual answers, not just a number. If you would rather not build the assessment yourself, our team will build it with you.

Choosing a pre-employment test?

Try a hands-on cyber test built for your role, free.

Send us the job spec. Within 48 hours we send you a hands-on assessment built around it, in your branding, so you can judge the format for yourself before you choose a vendor.

Get a free assessment Request a sample report