Interview track
DFIR-leaning Intelligence Analyst
Intelligence work anchored in incident response. You turn forensic findings into durable intelligence, feed IR with adversary context mid-incident, and write the intrusion analysis afterwards.
What is expected at this level
Expected to be strong on host and network forensics, timeline reconstruction and evidence handling, and to translate artefacts into TTP-level findings rather than stopping at indicator lists.
Start a mock interview
7 questions
Questions from this track
Each one has a vetted expert answer you can read before or after you practise.
- What is F3EAD, and why do some CTI teams prefer it to the traditional intelligence cycle?
- You have an unknown Windows executable and two hours. What do you do, and what would you be able to tell the incident team at the end?
- How would you find command-and-control beaconing in network telemetry when you have no indicators to search for?
- It is 2am during a live incident and the incident commander asks you "is this ransomware?" You genuinely do not know yet. What do you say?
- An intrusion started with valid credentials against an internet-facing VPN, with no malware involved until well after initial access. How well does the Cyber Kill Chain describe this, and what would you use instead?
- You have recovered a suspicious executable from an executive's laptop during a live incident. A colleague suggests uploading it to VirusTotal. What do you say?