Question library
CTI interview questions with expert answers
Every question comes with the key points a strong answer covers, the mistakes that lose candidates points, and a vetted expert answer. Read them, then practise them under questioning.
36 questions in the library
- What is cyber threat intelligence, and how is it different from a threat feed? Almost every CTI interview opens here. The question looks trivial and is not — it is checking whether you understand that intelligence is defined by process and purpose, not by…
- Why do you want to work in threat intelligence rather than another security discipline? A motivation question with a technical subtext: the interviewer is checking whether you know what the job actually involves day to day, or whether you are picturing a more…
- What threat intelligence do you read regularly, and how do you decide whether to believe a vendor report? The second half is the real question. Anyone can list sources; the interviewer wants to know whether you read them critically.
- Explain the difference between tactical, operational and strategic threat intelligence, with an example of each. A definitional question that becomes diagnostic the moment you are asked for examples — most candidates produce three tactical examples.
- A board member asks you what your team does and why it is worth the budget. You have two minutes. What do you say? A communication test disguised as a definitions question. The scoring is almost entirely about whether you can drop the jargon and name a decision.
- What is the difference between an indicator of compromise and a TTP, and why does the distinction matter? The Pyramid of Pain question in disguise. Getting the definitions right is the easy half; explaining the operational consequence is what scores.
- How do the Diamond Model, the Cyber Kill Chain and MITRE ATT&CK relate to each other? Do they compete? A comparison question where the expected answer is that they compose rather than compete — and that you can say what each one uniquely gives you.
- You are the first intelligence hire at a company with a working SOC but no CTI function. What do you do in your first 90 days? A senior question that separates people who would start by buying a feed from people who would start by asking who the customer is.
- An endpoint alert shows that a scheduled task was created which launches a PowerShell one-liner from a user's AppData directory. Map this to MITRE ATT&CK. A mapping question with a deliberate trap: the evidence is ambiguous, and the correct answer includes saying so rather than committing to a single technique ID.
- You have one piece of evidence: a single IP address that a compromised host was beaconing to. Walk me through how you would develop this. The canonical Diamond Model question. Interviewers are listening for a structured pivot sequence and for restraint about what infrastructure overlap actually proves.
- Your CISO says "I want to know about ransomware." Turn that into something you can actually collect against. Requirements management is where most CTI functions quietly fail, and this question tests it directly.
- What is F3EAD, and why do some CTI teams prefer it to the traditional intelligence cycle? F3EAD comes up because it fixes the intelligence cycle's weakest joint — the handoff between analysis and operations.
- What is the difference between saying something is "likely" and saying you have "high confidence" in an assessment? Can you have high confidence in an unlikely outcome? The single highest-leverage tradecraft question in CTI interviews. A large share of candidates conflate the two axes, and interviewers use it as a fast proxy for real analytic…
- Critique this line from a draft report: "It is believed that this sophisticated attack may possibly be linked to a nation-state actor." Rewrite it. A red-pen exercise. Every fault in this sentence is one interviewers see regularly in real drafts.
- Explain the Admiralty source grading scale. How would you grade a well-regarded vendor's report making a claim that no other source has corroborated? A question with a specific correct shape: the scale grades source and information separately, and this scenario is exactly the case where the two diverge.
- Tell me about a time your analysis turned out to be wrong. What happened, and what did you change? The behavioural question that most reliably separates analysts with real experience from those without. Everyone has been wrong; the question is what you did about it.
- Four separate publications report the same breach claim. How do you decide whether that counts as corroboration? Circular reporting is the most common way corroboration gets faked, and this question tests whether you check provenance or count citations.
- You have an unknown Windows executable and two hours. What do you do, and what would you be able to tell the incident team at the end? A time-boxed triage question. The constraint is the point — it tests prioritisation, not whether you can reverse engineer.
- In STIX, what is the difference between a cyber-observable object and an indicator? And what does TAXII do that STIX does not? A standards question that doubles as a check on indicator thinking — the SCO/indicator distinction is the same distinction as data versus intelligence.
- How would you find command-and-control beaconing in network telemetry when you have no indicators to search for? A behaviour-first detection question. With no indicators available, the answer has to reason from what beaconing inherently looks like.
Practise these
Reading an expert answer and producing one under questioning are different skills. The simulator asks these questions, grades your answer against the same rubric you see here, and asks the follow-up an interviewer would ask next.