Question library
CTI interview questions with expert answers
Every question comes with the key points a strong answer covers, the mistakes that lose candidates points, and a vetted expert answer. Read them, then practise them under questioning.
35 questions matching your filters
- You have been producing reports for six months and you suspect nobody is reading them. How do you find out, and what do you change? A question about the feedback step of the intelligence cycle — the one most teams skip, and the reason many CTI functions get cut.
- It is 2am during a live incident and the incident commander asks you "is this ransomware?" You genuinely do not know yet. What do you say? A pressure question. The failure modes are equally bad in both directions: guessing to sound useful, or refusing to commit and being useless.
- On the same morning: a new critical vulnerability is being exploited in the wild, the CISO wants a board paper by Friday, and IR needs support on a live case. You cannot do all three. How do you decide? A prioritisation question. The interviewer wants a decision rule, not a heroic claim that you would somehow do everything.
- The SOC escalates: a finance team member's account authenticated successfully from an IP in a country the company has no presence in, at 03:00 local time. MFA was satisfied. No alerts have fired since. What do you do, and what do you tell the SOC lead? A triage scenario where the obvious conclusion is wrong often enough to matter. Interviewers watch whether you generate benign hypotheses before escalating.
- A vendor publishes a report claiming an intrusion set is actively targeting your sector, with 200 indicators appended. Your CISO forwards it and asks "are we affected?" Walk me through your response. The most common real task in CTI, and a test of whether you start with the indicators or with the question.
- Your CISO has seen an ATT&CK coverage heat map showing 70% of techniques as "covered" and wants to know if that means we are 70% secure. What do you say? A question about the limits of a framework, aimed at analysts senior enough to be asked to defend a metric they did not choose.
- An intrusion started with valid credentials against an internet-facing VPN, with no malware involved until well after initial access. How well does the Cyber Kill Chain describe this, and what would you use instead? A question designed to see whether you can criticise a framework you are expected to know. Identity-based intrusions are exactly where the kill chain fails.
- Walk me through how you would use Analysis of Competing Hypotheses on an intrusion where the evidence is ambiguous. What makes ACH different from just weighing the evidence? ACH questions separate people who can name the technique from people who understand its central counterintuitive claim: supporting evidence is nearly worthless.
- An executive wants a named attacker for a board slide tomorrow. Your evidence supports clustering the activity but not naming a group. What do you do? A behavioural question testing analytic integrity under stakeholder pressure — and whether you can push back without being obstructive.
- You have recovered a suspicious executable from an executive's laptop during a live incident. A colleague suggests uploading it to VirusTotal. What do you say? An operational security question that catches a lot of otherwise strong candidates. The instinct to upload is exactly the instinct being tested.
- You have read a report describing an actor that uses scheduled tasks to run scripts from user-writable directories. Turn that into a threat hunt. The intelligence-to-operations handoff, tested concretely. A hypothesis without expected false positives is not a hunt.
- You receive TLP:RED intelligence in a trust group indicating a specific vulnerability is being exploited against your sector. Your organisation is exposed. What do you do? A handling scenario with a deliberate conflict between an obligation and an urgent need to act. Inventing permission is the failure mode.
- Ransomware has been deployed across part of your estate. A known family was used, a ransom note was left, but no data exfiltration has been observed despite C2 being active for six days beforehand. What are your hypotheses, and how would you test them? A case built around one diagnostic anomaly. The scoring is about whether you notice that the missing exfiltration is the interesting part.
- The incident is contained. You have 10 minutes with the board next week. The technical picture is still incomplete and attribution is unresolved. What do you present? A communication scenario at the strategic altitude, with the added constraint that you have to be useful while significant things are still unknown.
- Which classes of attribution evidence are hardest for an adversary to fake, and which are easiest? How does that change how you weight them? A senior attribution question. The expected answer ranks evidence by cost-to-fake and connects that ranking to how confidence should be assigned.
Practise these
Reading an expert answer and producing one under questioning are different skills. The simulator asks these questions, grades your answer against the same rubric you see here, and asks the follow-up an interviewer would ask next.