CyberHire

25 SOC Analyst Interview Questions (With Strong Answers)

25 SOC analyst interview questions with what each one tests and what a strong answer includes, plus which to use for Tier 1, Tier 2 and Tier 3 hires.

These 25 SOC analyst interview questions are for the person hiring: a SOC lead, SOC manager or Head of Security. They cover fundamentals, real alert scenarios and short hands-on tasks, and each comes with what it tests and what a strong answer includes. A table further down shows which questions suit a Tier 1, Tier 2 or Tier 3 hire.

A SOC analyst spends most of a shift deciding which alerts matter and proving it with evidence. That is hard to judge from a conversation, so the questions below lean on judgement and real data rather than definitions. For questions that apply to every cyber role, see the main list of cyber security interview questions.

SOC analyst interview questions on the fundamentals

Use two or three of these to check the foundations, then move on. A candidate who can recite all seven but struggles with the scenarios is the profile this list is designed to catch.

QuestionWhat it testsWhat a strong answer includes
1. What does a SOC analyst actually do on a typical shift?Understanding of the jobWorking the alert queue, triage, investigation, escalation and documentation. Knows that most alerts turn out to be benign and that proving it, quickly and with evidence, is the core skill.
2. What is the difference between an event, an alert and an incident?Core vocabulary, used preciselyAn event is anything logged. An alert is an event or pattern that matched detection logic. An incident is confirmed or likely malicious activity that needs a response.
3. What is the difference between a false positive and a benign true positive?Nuance in triageA false positive is a detection that fired on the wrong thing. A benign true positive is a detection that correctly spotted the activity, but the activity was authorised, such as an admin using a remote tool. The fix for each is different.
4. How do a SIEM and an EDR differ, and when would you use each?Tooling knowledgeA SIEM collects and correlates logs from many sources. An EDR records detailed endpoint activity and can act on the device, for example isolating it or killing a process. Investigations usually need both.
5. How do you use MITRE ATT&CK when you triage an alert?Framework applied to real workMaps the alert to a technique in MITRE ATT&CK, then uses that to ask what would normally come before and after it, and checks for those too.
6. Which Windows event IDs do you look at most, and why?Practical log knowledge4624 and 4625 (successful and failed logons, including the logon type, such as 3 for network and 10 for RDP), 4648 (explicit credentials), 4672 (special privileges), 4688 (process creation), 4769 (Kerberos service tickets) and 1102 (audit log cleared).
7. What makes a good escalation ticket?Communication with the next tierWhat was seen, the evidence (times, hosts, users, indicators), what has already been checked, what is still unknown, a severity with the reasoning behind it, and a recommended next step.

Scenario-based SOC analyst interview questions

These are where you learn the most. Listen for the order of actions, what the candidate checks before deciding, and whether they can separate a noisy alert from a real one.

QuestionWhat it testsWhat a strong answer includes
8. You start a shift with 40 open alerts. How do you decide what to work first?PrioritisationNot first-in, first-out. Weighs severity, how critical the asset is, how reliable the detection is, and age. Groups related alerts, because ten alerts on one host may be one incident.
9. An alert says a user downloaded and ran an executable from the internet. What do you check?Endpoint triageThe parent process, the file’s hash and signature, its reputation, what it did next (child processes, network connections, persistence), and whether the same file appears on other machines. Avoids uploading sensitive files to public sandboxes.
10. A user’s mailbox has a new rule forwarding all mail to an external address. What do you do?Business email compromiseRecognises a classic sign of account compromise. Checks when the rule was created and from where, reviews sign-ins and MFA, removes the rule, revokes sessions, resets credentials, and works out what was forwarded.
11. A server connects to the same external IP every 60 seconds. Is that a problem?Spotting beaconing, without jumping to conclusionsIdentifies possible command-and-control beaconing, then checks which process makes the connection and the destination’s reputation. Knows update checks and monitoring agents can look the same, and confirms before escalating.
12. A detection fires for a remote admin tool on a server, and the admin says it was them. What now?Verifying, then tuningConfirms against a change ticket or with the admin’s manager rather than taking their word. If it was authorised, suggests a narrow exception for that account and host, not switching the rule off.
13. Antivirus quarantined malware on a laptop. Is the incident closed?Thinking beyond the alertNo. Asks how it arrived, whether anything ran before quarantine, whether persistence or credential theft happened, and whether other machines received the same file.
14. One detection fires hundreds of times a day and has never caught anything real. What do you do?Detection tuningWorks out why it fires, proposes precise exclusions, tests them, and documents the change. Raises it with whoever owns detections rather than quietly ignoring the alert.
15. A user reports that their files have strange new extensions and will not open. What do you do?Ransomware responseIsolates the machine from the network straight away, without powering it off, so memory evidence survives. Escalates immediately, checks which shares and other machines are affected, and leaves decisions about the attacker’s demands to the incident leads.
16. You discover that an alert you closed last week as a false positive was part of a real incident. What do you do?Honesty and learningReports it straight away, adds what they know to the incident, and looks at why it was missed so the detection or playbook can improve. Covering it up is the real red flag.
17. The threat intelligence team sends you 500 indicators from a new campaign. What do you do with them?Using intelligence wellSearches historical logs for them first, prioritises high-confidence indicators such as file hashes and specific domains over shared hosting IPs, adds them to watchlists with an expiry date, and knows that hunting for the campaign’s techniques lasts longer than its indicators.

Hands-on SOC analyst interview tasks

Short tasks to run in the interview itself. Prepare the material in advance with demo data. Ten minutes of watching a candidate work tells you more than any answer on this page.

TaskWhat it testsWhat a strong answer includes
18. Here are 20 lines of Windows Security log. Tell me what happened.Reading raw logsBuilds the sequence, for example a run of 4625 failures, a 4624 network logon, a 4672 privilege event, then a 4688 showing reconnaissance commands, and says how confident they are.
19. Write a query that finds Office applications launching command shells or scripts.KQLA working query on process events with the Office apps as the parent, and an explanation of why it matters: it is a common sign of a malicious document.
20. Here is a reported phishing email. Walk me through your triage.Email investigationReads the headers and authentication results, expands links without clicking them, checks attachments safely, finds every recipient, and purges the email.
21. Here are 30 DNS queries from one host. Which ones worry you, and why?Network judgementPicks out randomly generated domains, unusually long subdomains that suggest DNS tunnelling, and newly registered domains, and explains what they would check next.
22. Here is an EDR process tree. Is this malicious?Endpoint investigationReads each step, for example an email client opening a document that starts PowerShell, which then starts rundll32, and explains why that chain is suspicious.
23. Write a Splunk search for accounts with more than 10 failed logins in the last hour.SPLA working search grouped by account and source, and awareness that field names depend on how Windows logs are ingested.
24. Here is an alert we closed as a false positive, with our notes. Do you agree?Independent reviewChecks the evidence for themselves rather than trusting the earlier notes, and says what they would have done differently, if anything.
25. Write the escalation note for the incident in task 18.Written communicationUses the structure from question 7: what happened, evidence, what was checked, what is unknown, severity and next step. Short and clear.

For task 19, a reasonable answer in Microsoft Defender or Sentinel looks like this:

DeviceProcessEvents
| where Timestamp > ago(7d)
| where InitiatingProcessFileName in~ ("winword.exe", "excel.exe", "powerpnt.exe", "outlook.exe")
| where FileName in~ ("powershell.exe", "cmd.exe", "wscript.exe", "cscript.exe", "mshta.exe", "rundll32.exe")
| project Timestamp, DeviceName, AccountName, InitiatingProcessFileName, FileName, ProcessCommandLine

For task 23, a starting point in Splunk is below. The field names vary with the Windows add-on you use, and a strong candidate will say so.

index=wineventlog EventCode=4625 earliest=-1h
| stats count AS failures BY TargetUserName, IpAddress
| where failures > 10

Which questions suit Tier 1, Tier 2 and Tier 3 analysts?

The same question can be too hard for one tier and too easy for another. Pick from the row that matches what the person will own on their first day.

TierWhat they ownQuestions to use
Tier 1Working the queue, first triage and clean escalation1, 2, 3, 7, 8, 9, 13, 18, 20, 25
Tier 2Deeper investigation and containment4, 5, 6, 10, 11, 12, 15, 19, 22, 23
Tier 3Hunting, detection tuning and threat intelligence5, 14, 16, 17, 21, 24

Calibration matters more than most teams expect. Screening Tier 1 candidates against Tier 3 questions makes every candidate look weak and makes the market look empty. The full method is in our guide to the technical assessment for SOC analyst candidates.

What are the red flags in a SOC analyst interview?

  • Closing alerts on instinct. “It’s probably a false positive” without saying what evidence would prove it.
  • Only one action. “Block the IP” or “reset the password” as the whole response, with nothing about scope.
  • No sense of when to escalate. Either escalates everything or would sit on a likely incident until they were certain.
  • Tools without understanding. Can name five SIEMs but cannot describe a search they wrote in one.
  • Guessing instead of saying “I would check”. Confident guessing in an interview becomes confident guessing during an incident.

Why a hands-on task beats any SOC interview question

Every question above has the same weakness: the candidate describes triage instead of doing it. A well-prepared candidate can talk fluently through an investigation they have never run. The hands-on tasks close some of that gap, but they are short and depend on someone preparing good material.

A hands-on assessment goes further. The candidate works in a real environment, on realistic data with legitimate activity mixed in, and the answer only exists in that data.

portal.cyber-hire.com/challenge/kql Microsoft Sentinel SOC analyst interview alternative: a KQL investigation in a Microsoft Sentinel-style query editor over SigninLogs, DeviceEvents and AuditLogs tables, with 405 sign-in records returned and a free-text question asking which account was the initial point of compromise.
Three tables to correlate and nothing labelled as suspicious. The candidate has to find the account that was compromised first and type it in, so there is nothing to guess between.

Used before the interview, a task like this tells you who can triage. The interview then spends its time on escalation judgement, communication and the gaps the assessment found.

Frequently asked questions

What questions are asked in a SOC analyst interview?

Expect a mix of fundamentals (alerts and incidents, SIEM and EDR, Windows event IDs), scenarios such as a phishing report or a suspicious login, and increasingly a short practical task like reading logs or writing a query. The questions above cover all three.

What are the tiers of SOC analyst?

Tier 1 analysts work the alert queue, triage and escalate. Tier 2 analysts investigate escalated alerts in depth and contain incidents. Tier 3 analysts hunt for threats, tune detections and work with threat intelligence. The names vary between organisations, but the split is common.

Is a SOC analyst interview technical?

It should be. A SOC analyst’s job is reading data and making decisions under pressure, so the interview should include at least one task where the candidate works with real logs or a real alert, not only questions about them.

How long should a SOC analyst interview be?

An hour is usually enough for five or six questions and one short practical task. If you run a hands-on assessment before the interview, the interview itself can focus on the candidate’s results and their judgement.

How CyberHire tests SOC analysts before the interview

CyberHire is cyber technical screening that shows you who can triage before you book an interview. Pick the ready-made SOC analyst assessment, calibrated to Tier 1, 2 or 3, or paste your job specification and generate one. Candidates work in real environments: KQL hunting in a Sentinel-style workspace, Windows event logs, phishing emails with full headers and raw log files in a live shell.

Every candidate is scored the same way, with integrity signals next to each score, and you see their actual answers, not just a number. See how it works for SOC analyst hiring. If you would rather not build the assessment yourself, our team will build it with you.

Hiring a SOC analyst?

See who can triage before you interview anyone.

Send us the job spec. Within 48 hours we send you a hands-on SOC assessment built around it, in your branding, free. Real alerts, real logs, scored the same way for every candidate.

Get a free assessment Request a sample report