CyberHire

25 Threat Intelligence Analyst Interview Questions

25 threat intelligence analyst interview questions with what each one tests and what a strong answer includes, from the intelligence cycle to CISO briefings.

These 25 threat intelligence analyst interview questions are for the person hiring: a CTI lead, SOC manager or Head of Security. They cover fundamentals, real scenarios from serving stakeholders, and short hands-on tasks, and each comes with what it tests and what a strong answer includes. A table further down groups them by who the intelligence is for, from the board to the SOC.

Threat intelligence is only worth what it changes. A strong analyst turns noisy, contradictory information into a clear judgement someone can act on, and says how confident they are. The questions below test that, rather than how many threat actor names a candidate can recall. For questions that apply to every cyber role, see the main list of cyber security interview questions.

Threat intelligence analyst interview questions on the fundamentals

Use two or three to check the foundations. Strong candidates tie every answer back to a decision someone has to make.

QuestionWhat it testsWhat a strong answer includes
1. What are the types of threat intelligence, and who uses each?Audience awarenessStrategic for executives and risk owners, operational about specific campaigns and actors for defenders and responders, tactical on attacker techniques for the SOC and detection teams, and technical indicators for tools.
2. Walk me through the intelligence lifecycle.ProcessDirection (requirements), collection, processing, analysis, dissemination and feedback. Stresses that it starts with what stakeholders need to decide, not with what data is available.
3. What is the difference between information and intelligence?Core conceptIntelligence is information that has been analysed, put in context and made relevant to a decision. A list of indicators is information.
4. How do you assess how reliable a source is?Analytic rigourSeparates the source’s track record from how credible the specific piece of information is, for example using the Admiralty Code, and corroborates with independent sources.
5. What is the Diamond Model, and how does it relate to MITRE ATT&CK?Analytic frameworksThe Diamond Model links adversary, capability, infrastructure and victim to support pivoting and clustering. MITRE ATT&CK describes the techniques used. They work together.
6. What makes an indicator of compromise useful, and why do indicators age?Practical judgementContext, confidence and an expiry date. Attackers change infrastructure quickly, and IP addresses on shared hosting cause false positives long after the attacker has moved on.
7. How do you express uncertainty in an assessment?Clear communicationUses consistent estimative language, such as the UK Professional Head of Intelligence Assessment’s probability yardstick (“realistic possibility”, “likely”, “highly likely”), and states confidence separately from likelihood.

Scenario-based threat intelligence interview questions

These show whether a candidate can serve real stakeholders. Listen for questions back about what the requester actually needs to decide.

QuestionWhat it testsWhat a strong answer includes
8. The CISO asks, “Are we a target for the group in the news?” How do you answer?Relevance and honestyChecks whether the group targets the organisation’s sector, geography and technology, compares its techniques with existing defences, and gives a clear judgement with a confidence level, not a yes or no.
9. A vendor feed sends 10,000 indicators a day. What do you do with them?Feed managementMeasures the feed’s quality and relevance, removes duplicates, scores and expires indicators, tracks false positives, and checks whether the feed ever catches anything real.
10. A new zero-day is trending on social media. How do you brief leadership within the hour?Speed under uncertaintyVerifies the sources, separates what is known from what is rumoured, checks whether the organisation runs the affected product, recommends actions, and sets a time for the next update.
11. The SOC says your intelligence is not useful. What do you do?Customer focusAsks the SOC what decisions they make, changes the format to what they can use, such as detection ideas and hunting leads, and builds a feedback loop to measure impact.
12. A stakeholder wants to know who was behind an incident. How do you handle attribution?RestraintExplains what can and cannot be concluded, attaches confidence, and points out that the attacker’s techniques usually matter more to defenders than their name.
13. You find company credentials for sale on a criminal forum. What do you do?Acting on findings safelyValidates them, has the accounts reset and sessions revoked, checks for misuse, and does not interact with or buy from sellers without legal approval.
14. How would you set intelligence requirements for a new programme?Programme designInterviews stakeholders, writes priority intelligence requirements tied to business risks and decisions, and reviews them regularly.
15. A lookalike domain impersonating the company appears. What do you do?Brand protectionInvestigates the domain and its hosting, monitors it for activity, starts a takedown with the registrar or host, blocks it internally, and warns staff or customers if needed.
16. How do you stay safe while researching threat actors?Operational securityUses isolated research systems and accounts that cannot be traced to the company, follows legal and ethical limits, and never investigates from a corporate device.
17. Two reliable sources contradict each other. How do you report it?Analytic honestyPresents both, assesses each source, considers competing explanations, states the confidence, and says what new information would settle it.

Hands-on threat intelligence interview tasks

Short tasks to run in the interview with prepared material. Watching a candidate work through a real report tells you more than any answer above.

TaskWhat it testsWhat a strong answer includes
18. Here is a threat report. Extract the techniques and map them to ATT&CK.Structured analysisAccurate technique mapping with the evidence for each, and notes on what the report does not say.
19. Here are 20 indicators. Which would you block, which would you watch, and which would you discard?Indicator judgementDiscards shared hosting and content delivery addresses, blocks high-confidence indicators, and watches the rest with an expiry date.
20. Write a one-page brief for the board on ransomware risk to our sector.Strategic writingThe threat, why it matters to this organisation, current exposure, recommended decisions, and estimative language. No jargon.
21. Here is an email from a phishing campaign. What can you learn about the attacker?Campaign analysisReads headers and infrastructure, notes the lure and targeting, and identifies pivot points such as domains and hosting.
22. Starting from this domain, what else can you find?PivotingUses passive DNS, certificate transparency logs, registration data and hosting overlaps to find related infrastructure, with care about false links.
23. Turn this report into a hunting hypothesis and a query.Making intelligence actionableA testable hypothesis based on the attacker’s techniques, and a query that would find them in your logs.
24. Grade these three sources using the Admiralty Code.Source evaluationJustified grades for reliability and credibility, and an explanation of what would change them.
25. Here is an intelligence report we published. Critique it.Quality controlComments on clarity, sourcing, confidence language and whether the reader knows what to do next.

Which questions for which audience?

Threat intelligence roles differ by who they serve. Pick questions that match the people the analyst will brief.

AudienceWhat it coversQuestions to use
Board and CISO (strategic)Risk, relevance and clear judgements1, 3, 7, 8, 10, 12, 20
Responders and defenders (operational)Campaigns, actors and investigation5, 13, 15, 17, 21, 22, 24, 25
SOC and detection (tactical)Techniques, indicators and hunting6, 9, 11, 18, 19, 23
Running the programmeRequirements, sources and safety2, 4, 14, 16

If the role feeds a detection team, add some of the detection engineer interview questions.

What are the red flags in a threat intelligence interview?

  • Indicators as the product. Thinks the job is forwarding lists of IP addresses.
  • Certainty without evidence. States attribution or intent with no confidence level.
  • No stakeholder in sight. Cannot say who would use their work or what decision it supports.
  • News summaries as intelligence. Repeats public reporting without asking what it means for the organisation.
  • Poor operational security. Researches threat actors from a corporate laptop or personal accounts.

Why a hands-on task beats any threat intelligence interview question

Describing the intelligence lifecycle is easy. Taking real evidence and reaching a sound judgement about it is the job. A hands-on task shows whether the candidate reads the evidence carefully or jumps to a story.

portal.cyber-hire.com/challenge/email Inbox Threat intelligence analyst interview alternative: an email analysis lab showing a CEO-impersonation wire transfer phishing email in an inbox, with a question for the candidate to answer about it.
A real phishing lure with full headers. The candidate has to read the evidence and reach a judgement, which is where campaign analysis starts.

Used before the interview, this shows you who can analyse real material. The interview can then focus on judgement, writing and how they work with stakeholders.

Frequently asked questions

What does a threat intelligence analyst do?

A threat intelligence analyst collects and analyses information about attackers and their methods, then turns it into judgements and recommendations for the people who defend the organisation, from the SOC to the board.

What skills does a threat intelligence analyst need?

Analytical thinking, clear writing, an understanding of attacker techniques and frameworks such as MITRE ATT&CK, the ability to pivot through technical data, and good judgement about reliability and confidence.

What is the difference between a threat intelligence analyst and a SOC analyst?

A SOC analyst responds to alerts in the organisation’s own environment. A threat intelligence analyst studies attackers and campaigns more broadly and helps the SOC, detection and leadership teams prepare for them.

How do you assess a threat intelligence candidate before the interview?

Give them real material to analyse, such as a threat report, a phishing campaign or a set of indicators, and ask for a short written judgement. Score the analysis and the clarity of the writing.

How CyberHire tests threat intelligence analysts before the interview

CyberHire is cyber technical screening that shows you who can turn evidence into a judgement before you book an interview. Paste your job specification and generate an assessment, or build one from the library of 270+ hands-on challenges. Candidates work with real material in real environments, such as phishing campaigns with full headers, sign-in and endpoint telemetry, and Windows event logs, and their answers are scored the same way for everyone.

Every score comes with integrity signals, and you see each candidate’s actual answers. Threat intelligence analysts are one of the roles we assess; see all use cases. If you would rather not build the assessment yourself, our team will build it with you.

Hiring a threat intelligence analyst?

See who can turn data into a decision before you interview anyone.

Send us the job spec. Within 48 hours we send you a hands-on assessment built around it, in your branding, free. Real evidence to analyse, scored the same way for every candidate.

Get a free assessment Request a sample report