Interview question
It is 2am during a live incident and the incident commander asks you "is this ransomware?" You genuinely do not know yet. What do you say?
A pressure question. The failure modes are equally bad in both directions: guessing to sound useful, or refusing to commit and being useless.
What a strong answer covers
- Does not guess, and does not refuse to answer either.
- States what is known, what is not known, and the current best judgement with an explicit confidence.
- Gives the incident commander something actionable despite the uncertainty.
- Names the specific evidence that would resolve it and how quickly it could be obtained.
- Recognises that in IR the cost of the two possible errors is asymmetric and worth stating.
- Recommends action that is reasonable under both hypotheses where possible.
- Commits to a time to come back with an update.
- Uses plain language rather than analytic hedging at 2am.
Expert answer
The two ways to fail here are opposite: guess a confident answer to sound useful, or say "I cannot say yet" and leave the commander with nothing. Both are bad. The job is to be useful while uncertain.
What I would actually say is something like: "I do not know yet. Here is what we have — encrypted files on two file servers, a ransom note, no exfiltration observed so far. Here is what makes me cautious: we have not confirmed whether this is a ransomware operation or destructive activity presented as ransomware, and we have a six-day gap in the timeline before the encryption. My current read is that this is likely a ransomware operation, at low confidence, and I will hold that lightly until we have the sample and the C2 behaviour.
"What would settle it: the binary itself and whether it has a working decryption path and a functioning C2 channel, and whether there is staging or exfiltration in the proxy logs from the days before. I can have the first in about an hour and the second sooner.
"What I would do meanwhile does not depend on the answer: contain and isolate, preserve volatile evidence before we reboot anything, and pull the authentication logs for the whole window."
Three things make that a good answer at 2am. It separates observation from judgement so the commander knows which is which. It attaches an explicit and honest confidence rather than either false certainty or a shrug. And it recommends action that is correct under both hypotheses, so the uncertainty does not stall the response.
I would also name the asymmetry if it matters, because it changes the decision. If treating it as ransomware when it is destructive costs us evidence preservation, that is worth saying out loud so the commander can weigh it.
And I would commit to a specific time to come back. "I will have an update by 3:30" is worth more than an open-ended promise, because the commander can plan around it.
The one thing I would not do is use analytic register at 2am. "Roughly even chance" is precise but it is not what a tired incident commander needs. Plain language, honest uncertainty.
Mistakes that cost candidates points
- Guessing confidently to appear useful.
- Answering only "I do not know" with nothing actionable attached.
- Not naming what evidence would resolve it or how quickly.
- No recommendation that holds under both hypotheses.
- No commitment to a follow-up time.
- Over-formal analytic hedging in an operational moment.
You have read the answer, which is the easy part. Answer it in your own words and get graded against this same rubric, with the follow-up probe an interviewer would ask next.
Go deeper
Related questions
- What is the difference between saying something is "likely" and saying you have "high confidence" in an assessment? Can you have high confidence in an unlikely outcome?
- Critique this line from a draft report: "It is believed that this sophisticated attack may possibly be linked to a nation-state actor." Rewrite it.
- Tell me about a time your analysis turned out to be wrong. What happened, and what did you change?
- A senior analyst has written an assessment you think is wrong. It is going out to the CISO tomorrow. What do you do?
- You have been producing reports for six months and you suspect nobody is reading them. How do you find out, and what do you change?