Technology

Security Analyst Interview Questions and Answers

Cybersecurity interviews test your grasp of core security principles, common attacks and how to defend against them, and how you respond when something goes wrong. These questions suit SOC analyst, security engineer and penetration testing roles.

Reading answers is not the same as saying them.Practise cybersecurity questions out loud and get a score, what you missed and a model answer for each one.
Practise free with AI

Topics interviewers ask about

Network SecurityEthical HackingOWASP Top 10CryptographyFirewalls & IDSSIEMIncident ResponseCloud SecurityRisk & Compliance (ISO 27001)

Basic cybersecurity interview questions

Fundamentals, definitions and simple scenarios. Good for freshers and warm-ups.

1. What is the CIA triad?

Confidentiality means only authorised people can see the data, through encryption and access control. Integrity means data is not altered without authorisation, through hashing, digital signatures and change controls. Availability means systems are usable when needed, through redundancy, backups and DDoS protection. Every security control supports one or more of the three.

2. What is the difference between symmetric and asymmetric encryption?

Symmetric encryption uses one shared key to encrypt and decrypt (for example AES); it is fast but the key must be shared securely. Asymmetric encryption uses a public and private key pair (for example RSA or elliptic-curve cryptography); it solves key distribution and enables digital signatures but is slower. TLS uses asymmetric cryptography to agree on keys, then symmetric encryption for the data itself.

3. What is the difference between hashing and encryption?

Encryption is reversible with the right key and protects confidentiality. Hashing is one-way: it produces a fixed-length digest, such as with SHA-256, that cannot be turned back into the input, so it is used to check integrity. Passwords should be stored with a slow, salted hash such as bcrypt or Argon2, never encrypted, so even the system cannot recover them.

4. What is phishing, and how do organisations defend against it?

Phishing uses fake emails, messages or websites to trick people into revealing credentials, paying money or running malware. Defences are layered: security awareness training and simulations, email filtering, SPF, DKIM and DMARC to stop spoofing, multi-factor authentication (ideally phishing-resistant, like FIDO2 security keys), and an easy way for staff to report suspicious messages.

Intermediate cybersecurity interview questions

Applied problems, trade-offs and questions about your own projects.

5. What is SQL injection, and how do you prevent it?

SQL injection happens when untrusted input is concatenated into a query and changes its meaning; for example, entering ' OR '1'='1 can bypass a login check. The fix is parameterised queries or prepared statements, so input is always treated as data, not code. ORMs help, and defence in depth adds input validation, a least-privilege database account and a web application firewall.

6. What is the difference between XSS and CSRF?

Cross-site scripting (XSS) gets an attacker's script to run in a victim's browser on your site, through stored, reflected or DOM-based injection, so it can steal data or act as the user. Defences are output encoding, sanitising HTML, a Content Security Policy and HttpOnly cookies. Cross-site request forgery (CSRF) tricks a logged-in browser into sending an unwanted request; defences are SameSite cookies, anti-CSRF tokens and checking the Origin header.

7. What does a SIEM do?

A Security Information and Event Management system collects logs from servers, network devices, applications and cloud services, normalises them, and correlates events to detect suspicious patterns, such as many failed logins followed by a success from a new country. It raises alerts for the SOC, supports investigations and keeps logs for compliance. Examples are Splunk, Microsoft Sentinel, IBM QRadar and Elastic Security.

8. What is the principle of least privilege?

Every user, service and process gets only the access it needs to do its job, and only for as long as it needs it. This limits the damage from a compromised account or a mistake. It is implemented with role-based access control, separate admin accounts, just-in-time elevation, scoped API keys and regular access reviews that remove permissions no longer needed.

High level cybersecurity interview questions

System design, deep internals, leadership and tough follow-ups.

9. Walk me through the incident response process.

Following the NIST framework: Preparation (plans, tools, playbooks and training); Detection and Analysis (confirm the incident, judge its scope and severity); Containment, Eradication and Recovery (isolate affected systems, remove the threat, restore from clean backups and monitor closely); and Post-incident Activity (a lessons-learned review and improved controls). Throughout, I preserve evidence, keep a timeline and communicate with stakeholders and, where required, regulators.

10. How does a TLS 1.3 handshake work?

The client sends a ClientHello with its supported cipher suites and a key share. The server replies with its own key share, its certificate and a signature proving it owns the private key. Both sides derive the same session keys through ephemeral Diffie-Hellman, which gives forward secrecy, and the client validates the certificate against trusted certificate authorities. It completes in one round trip, after which data is encrypted symmetrically.

11. What is zero trust security?

Zero trust means no request is trusted just because it comes from inside the network. Every access is verified explicitly using strong identity with MFA, device health, location and context. Users get least-privilege access, the network is micro-segmented to limit lateral movement, and activity is monitored continuously, with the assumption that a breach may already have happened.

12. How would you approach a web application penetration test?

First I agree the scope, rules of engagement and written authorisation. Then I do reconnaissance and map the application, and test systematically against the OWASP Top 10 (broken access control, injection, authentication flaws, misconfiguration and more) using tools like Burp Suite plus manual testing. I confirm findings carefully without damaging data, report each one with severity (for example CVSS), evidence and a clear fix, and retest after remediation.

Ready to test yourself?Pick your topics and level, answer by voice or text, and get instant feedback. Free.
Start a mock interview

More technology interview questions