Q1
Walk me through how you would analyze a suspicious network packet capture file. What tools would you use, and what indicators of compromise would you look for?
Why they ask this:* Assesses hands-on experience with packet analysis tools (Wireshark, tcpdump), network protocol knowledge, and ability to identify malicious activity—core skills for threat detection.
Q2
Explain the differences between symmetric and asymmetric encryption, and describe a real-world scenario where you've implemented or recommended each in a previous role.
Why they ask this:* Tests foundational cryptography knowledge and practical application experience, which is essential for data protection and secure communication strategies.
Q3
Describe your experience with SIEM platforms (Splunk, ELK, ArcSight, etc.). How would you configure alerts for detecting lateral movement within a network?
Why they ask this:* Evaluates proficiency with security log aggregation and correlation tools, critical for monitoring and incident detection in modern SOC environments.
Q4
What is the OWASP Top 10, and can you explain how you've helped remediate vulnerabilities like SQL injection or cross-site scripting (XSS) in web applications?