Interview question
Four separate publications report the same breach claim. How do you decide whether that counts as corroboration?
Circular reporting is the most common way corroboration gets faked, and this question tests whether you check provenance or count citations.
What a strong answer covers
- Recognises that four publications may be one source.
- Traces each claim to the earliest publication presenting original evidence rather than the most recent.
- Distinguishes sources that observed something from sources that agree with an observer.
- Checks for shared collection — vendors using the same telemetry partner or sinkhole are not independent.
- Looks for tells: identical phrasing, identical indicator lists, a propagating error or typo.
- Considers whether the original claim is actor self-reporting, e.g. a leak-site listing, which actors have incentives to exaggerate.
- Adjusts confidence to reflect the true number of independent sources.
- May note that corroboration from the victim side is a different and stronger class of evidence.
Expert answer
The first question is not how many publications reported it but how many independently observed it.
I would trace each one back. For every publication, find whether it presents original evidence or cites someone else. Very often three of the four cite the fourth, sometimes at second hand, in which case I have one source and my confidence should reflect that rather than the citation count.
Independence has to mean independent collection, not just separate bylines. Two vendors that both draw on the same telemetry partner, the same sinkhole, or the same commercial feed are not independent sources even if neither cites the other. That is harder to detect and worth asking about directly when the relationship matters to the assessment.
There are tells. Identical phrasing or identical indicator lists across publications point to a common origin. So does an error propagating — if the first report has a typo in a domain and the others carry the same typo, the chain is obvious.
I would also look hard at what the original source actually is. For breach claims specifically, the origin is frequently the actor themselves — a leak-site listing or a forum post. Actors have clear incentives to exaggerate, to re-list old data as new, and occasionally to claim breaches that did not happen. Four outlets reporting an actor's claim is four reports of a claim, not evidence the breach occurred.
The strongest corroboration is different in kind: confirmation from the victim, from a regulator filing, or from telemetry showing the activity. One of those outweighs any number of outlets repeating each other.
So my answer to the stakeholder would state how many genuinely independent sources exist, note that the reporting volume overstates it, and set confidence accordingly.
Mistakes that cost candidates points
- Treating four publications as four sources.
- Not checking for shared collection between nominally independent vendors.
- Missing that breach claims often originate with the actor.
- Not adjusting confidence once the true source count is established.
You have read the answer, which is the easy part. Answer it in your own words and get graded against this same rubric, with the follow-up probe an interviewer would ask next.
Go deeper
Related questions
- What threat intelligence do you read regularly, and how do you decide whether to believe a vendor report?
- A vendor publishes a report claiming an intrusion set is actively targeting your sector, with 200 indicators appended. Your CISO forwards it and asks "are we affected?" Walk me through your response.
- Explain the Admiralty source grading scale. How would you grade a well-regarded vendor's report making a claim that no other source has corroborated?
- How do the Diamond Model, the Cyber Kill Chain and MITRE ATT&CK relate to each other? Do they compete?
- An endpoint alert shows that a scheduled task was created which launches a PowerShell one-liner from a user's AppData directory. Map this to MITRE ATT&CK.