CyberHire

Skills test for hiring

SOC analyst test for hiring

A hands-on SOC analyst assessment that shows who can actually triage. Candidates work real alerts in real environments, from phishing emails and Windows event logs to KQL hunting, and are scored the same way, calibrated to Tier 1, 2 or 3.

17 hands-on challenges · 15 to 30 minutes each · Built around your job spec

portal.cyber-hire.com/challenge/email Inbox
SOC analyst skills test: an email analysis challenge showing a phishing message in a mail client with Email, Headers and Raw Source tabs. The message impersonates Microsoft SharePoint, passes SPF, DKIM and DMARC, and links to a genuine Microsoft OAuth authorise URL.

What candidates actually do

The work itself. Not questions about it.

Candidates work in environments that look like the job, on realistic data with legitimate activity left in. The answer only exists in the data in front of them, so there is nothing to look up and nothing to guess between.

  • KQL workspace (Sentinel-style)
  • Windows Event Viewer
  • Email client with full headers
  • Linux shell
Sample task Event Viewer

Windows Event Log: Kerberoasting investigation

Several accounts in this domain request RC4-encrypted Kerberos service tickets, because legacy systems still do. One of them is an attacker. Using the Security log, find which account is Kerberoasting and explain why the others are not.

What a strong answer shows

Names the attacking account, and rules out the legitimate legacy accounts with evidence, such as the services requested, the timing and the source host. A weak answer flags every RC4 request.

Skills covered

17 real challenges. Pick the ones that fit the role.

Every assessment is assembled from the library to match your job spec, then calibrated to the level you are hiring. These are the SOC analyst challenges it draws on.

Alert triage and escalation

  • Phishing Triage - Morning Queue Easy 15 min
  • SOC Escalation Decisions - Who, When, Why Easy 15 min
  • Brute Force Attack Detection Easy 15 min

Phishing and email analysis

  • Phishing Analysis: Credential Harvesting Campaign Easy 15 min
  • Email Analysis - Payroll Diversion Targeting HR Medium 16 min
  • Email Analysis - Cloud-Share Impersonation Phishing Medium 18 min
  • Email Analysis - Compromised Tenant with Valid DMARC Medium 18 min

Windows event log investigation

  • Windows Event Hunt - Brute Force to Lateral Movement Medium 20 min
  • Windows Event Log - Kerberoasting Investigation Medium 28 min
  • Windows Event Log - Cleared Logs and Indicator Removal Medium 28 min
  • Lateral Movement & Credential Abuse Detection Hard 25 min

Log analysis in a live shell

  • Log Analysis: Apache Web Attack Detection Medium 20 min
  • Attack Log Investigation (Terminal) Medium 20 min
  • Log Analysis: JSON Threat Hunting Medium 25 min

KQL hunting

  • KQL Lab: Phishing Campaign Detection Medium 20 min
  • KQL Lab: Suspicious Sign-In Investigation Medium 25 min
  • KQL Lab: Password Spray & Privilege Escalation Hard 30 min

Levels: 4 Easy · 11 Medium · 2 Hard. Assessments usually combine a few challenges to fit the time you set.

What you get back

Evidence for every candidate. Scored the same way.

Every candidate is scored against the same answers, so you compare the work, not impressions. Read a candidate in two minutes, then interview the ones who can do the job.

  1. A score per skill See where each candidate is strong and where they are thin, not just a single number.
  2. Their actual answers Read what they found and how they explained it, so you can probe it in the interview.
  3. Integrity signals Time away, outside pasting, fullscreen exits and second screens, next to every score.

Common questions

About the SOC analyst test.

What does the SOC analyst test measure?

Whether a candidate can do the core work of a SOC analyst: triage alerts, investigate phishing, read Windows event logs and raw logs, hunt with KQL, and decide what to escalate. Each challenge puts real evidence in front of them rather than asking about it.

Can the test be calibrated to Tier 1, 2 or 3?

Yes. Tier 1 assessments focus on triage, phishing and escalation; Tier 2 adds deeper event log and cross-source investigation; Tier 3 adds hunting and harder multi-step cases. The assessment is built from your job spec at the tier you are hiring.

How long does the SOC analyst test take?

Individual challenges take 15 to 30 minutes. An assessment usually combines a few of them, so you set the total time to suit the stage, shorter for first screening and deeper for a shortlist.

Can candidates cheat with AI?

Much less than on a multiple-choice test, because the answers only exist in the data in front of the candidate. Integrity monitoring also records time away from the test, outside pasting, fullscreen exits and second screens next to every score.

Do candidates need to know our SIEM?

No. The environments look like common tools, such as a Sentinel-style KQL workspace and Windows Event Viewer, but the test measures investigation skills that transfer between tools.

Try it on your role

See the SOC analyst test built for your job spec.

Send us the job spec for a role you are hiring. Within 48 hours we send you a hands-on assessment built around it, in your brand, to try for yourself. Free, and with no commitment.