Skills test for hiring
SOC analyst test for hiring
A hands-on SOC analyst assessment that shows who can actually triage. Candidates work real alerts in real environments, from phishing emails and Windows event logs to KQL hunting, and are scored the same way, calibrated to Tier 1, 2 or 3.
17 hands-on challenges · 15 to 30 minutes each · Built around your job spec
What candidates actually do
The work itself. Not questions about it.
Candidates work in environments that look like the job, on realistic data with legitimate activity left in. The answer only exists in the data in front of them, so there is nothing to look up and nothing to guess between.
- KQL workspace (Sentinel-style)
- Windows Event Viewer
- Email client with full headers
- Linux shell
Windows Event Log: Kerberoasting investigation
Several accounts in this domain request RC4-encrypted Kerberos service tickets, because legacy systems still do. One of them is an attacker. Using the Security log, find which account is Kerberoasting and explain why the others are not.
Names the attacking account, and rules out the legitimate legacy accounts with evidence, such as the services requested, the timing and the source host. A weak answer flags every RC4 request.
Skills covered
17 real challenges. Pick the ones that fit the role.
Every assessment is assembled from the library to match your job spec, then calibrated to the level you are hiring. These are the SOC analyst challenges it draws on.
Alert triage and escalation
- Phishing Triage - Morning Queue
- SOC Escalation Decisions - Who, When, Why
- Brute Force Attack Detection
Phishing and email analysis
- Phishing Analysis: Credential Harvesting Campaign
- Email Analysis - Payroll Diversion Targeting HR
- Email Analysis - Cloud-Share Impersonation Phishing
- Email Analysis - Compromised Tenant with Valid DMARC
Windows event log investigation
- Windows Event Hunt - Brute Force to Lateral Movement
- Windows Event Log - Kerberoasting Investigation
- Windows Event Log - Cleared Logs and Indicator Removal
- Lateral Movement & Credential Abuse Detection
Log analysis in a live shell
- Log Analysis: Apache Web Attack Detection
- Attack Log Investigation (Terminal)
- Log Analysis: JSON Threat Hunting
KQL hunting
- KQL Lab: Phishing Campaign Detection
- KQL Lab: Suspicious Sign-In Investigation
- KQL Lab: Password Spray & Privilege Escalation
Levels: 4 Easy · 11 Medium · 2 Hard. Assessments usually combine a few challenges to fit the time you set.
What you get back
Evidence for every candidate. Scored the same way.
Every candidate is scored against the same answers, so you compare the work, not impressions. Read a candidate in two minutes, then interview the ones who can do the job.
- A score per skill See where each candidate is strong and where they are thin, not just a single number.
- Their actual answers Read what they found and how they explained it, so you can probe it in the interview.
- Integrity signals Time away, outside pasting, fullscreen exits and second screens, next to every score.
Roles it fits
Use it for the hire. Then for the interview.
- SOC analyst interview questions 25 questions with strong answers and a table for Tier 1, 2 and 3 hires.
- How to hire a SOC analyst What each tier must do on day one, and how to test for it.
- SOC analyst job description template Copy-ready adverts for Tier 1, 2 and 3 roles.
- Technical assessment for SOC analyst candidates The method behind the test: decoys, calibration and scoring.
- SOC analyst hiring with CyberHire How a SOC hiring campaign runs, end to end.
Common questions
About the SOC analyst test.
What does the SOC analyst test measure?
Whether a candidate can do the core work of a SOC analyst: triage alerts, investigate phishing, read Windows event logs and raw logs, hunt with KQL, and decide what to escalate. Each challenge puts real evidence in front of them rather than asking about it.
Can the test be calibrated to Tier 1, 2 or 3?
Yes. Tier 1 assessments focus on triage, phishing and escalation; Tier 2 adds deeper event log and cross-source investigation; Tier 3 adds hunting and harder multi-step cases. The assessment is built from your job spec at the tier you are hiring.
How long does the SOC analyst test take?
Individual challenges take 15 to 30 minutes. An assessment usually combines a few of them, so you set the total time to suit the stage, shorter for first screening and deeper for a shortlist.
Can candidates cheat with AI?
Much less than on a multiple-choice test, because the answers only exist in the data in front of the candidate. Integrity monitoring also records time away from the test, outside pasting, fullscreen exits and second screens next to every score.
Do candidates need to know our SIEM?
No. The environments look like common tools, such as a Sentinel-style KQL workspace and Windows Event Viewer, but the test measures investigation skills that transfer between tools.
Try it on your role
See the SOC analyst test built for your job spec.
Send us the job spec for a role you are hiring. Within 48 hours we send you a hands-on assessment built around it, in your brand, to try for yourself. Free, and with no commitment.