ctianalyst.com

Interview question

It is 2am during a live incident and the incident commander asks you "is this ransomware?" You genuinely do not know yet. What do you say?

A pressure question. The failure modes are equally bad in both directions: guessing to sound useful, or refusing to commit and being useless.

What a strong answer covers

Expert answer

The two ways to fail here are opposite: guess a confident answer to sound useful, or say "I cannot say yet" and leave the commander with nothing. Both are bad. The job is to be useful while uncertain.

What I would actually say is something like: "I do not know yet. Here is what we have — encrypted files on two file servers, a ransom note, no exfiltration observed so far. Here is what makes me cautious: we have not confirmed whether this is a ransomware operation or destructive activity presented as ransomware, and we have a six-day gap in the timeline before the encryption. My current read is that this is likely a ransomware operation, at low confidence, and I will hold that lightly until we have the sample and the C2 behaviour.

"What would settle it: the binary itself and whether it has a working decryption path and a functioning C2 channel, and whether there is staging or exfiltration in the proxy logs from the days before. I can have the first in about an hour and the second sooner.

"What I would do meanwhile does not depend on the answer: contain and isolate, preserve volatile evidence before we reboot anything, and pull the authentication logs for the whole window."

Three things make that a good answer at 2am. It separates observation from judgement so the commander knows which is which. It attaches an explicit and honest confidence rather than either false certainty or a shrug. And it recommends action that is correct under both hypotheses, so the uncertainty does not stall the response.

I would also name the asymmetry if it matters, because it changes the decision. If treating it as ransomware when it is destructive costs us evidence preservation, that is worth saying out loud so the commander can weigh it.

And I would commit to a specific time to come back. "I will have an update by 3:30" is worth more than an open-ended promise, because the commander can plan around it.

The one thing I would not do is use analytic register at 2am. "Roughly even chance" is precise but it is not what a tired incident commander needs. Plain language, honest uncertainty.

Mistakes that cost candidates points

Try answering it

You have read the answer, which is the easy part. Answer it in your own words and get graded against this same rubric, with the follow-up probe an interviewer would ask next.

Go deeper

Related questions