ctianalyst.com

Interview question

A vendor publishes a report claiming an intrusion set is actively targeting your sector, with 200 indicators appended. Your CISO forwards it and asks "are we affected?" Walk me through your response.

The most common real task in CTI, and a test of whether you start with the indicators or with the question.

What a strong answer covers

Expert answer

The first move is not the indicators. It is working out what the CISO is really asking, which is usually some combination of "are we compromised", "are we likely to be targeted", and "do we need to do something".

In parallel I would grade the report. Does it show its evidence or assert conclusions? What is the sourcing — their own incident response, telemetry, or open-source aggregation? Is the sector claim based on a meaningful number of victims or on two? And there is a commercial incentive to publish and to frame things as novel and targeted, which does not make the technical content wrong but does mean the emphasis is not neutral.

Relevance assessment next, because "our sector" is often broad enough to be meaningless. Does the targeting profile actually match us — our geography, our size, the specific technology the actor goes after? An intrusion set hitting large North American manufacturers through a specific ICS product is not relevant to a mid-size European services firm just because both are nominally in industry.

Then the direct question. I would run the indicators retrospectively against our telemetry — proxy, DNS, EDR, email — and I would check retention first, because the search only covers the window we still hold. I would report that window explicitly, because "no hits" over 30 days when the campaign has been running for six months is a much weaker statement than it sounds.

I would be clear with the CISO about what that search can and cannot establish. Indicator matching answers a narrow question: have these specific artefacts appeared. It does not tell us we are not compromised, because indicators decay fast, the report only contains what that vendor saw, and any competent actor has rotated infrastructure since.

The more valuable work is the TTPs. I would extract the behaviours — initial access vector, persistence mechanism, lateral movement, the specifics — map them to ATT&CK, and check whether we have detection for them. Validated detection, ideally, not a green square. That produces a gap list that stays useful after the indicators are dead, and it is the thing I would actually recommend acting on.

The answer back would be a short judgement rather than a data dump: whether we found evidence of this activity and over what window, how relevant the targeting profile is to us and at what confidence, where our detection gaps are for the techniques described, and what I recommend doing. The 200 indicators go into the platform for ongoing matching and into an appendix — they are not the answer.

Mistakes that cost candidates points

Try answering it

You have read the answer, which is the easy part. Answer it in your own words and get graded against this same rubric, with the follow-up probe an interviewer would ask next.

Go deeper

Related questions