Question library
CTI interview questions with expert answers
Every question comes with the key points a strong answer covers, the mistakes that lose candidates points, and a vetted expert answer. Read them, then practise them under questioning.
7 questions matching your filters
- What is F3EAD, and why do some CTI teams prefer it to the traditional intelligence cycle? F3EAD comes up because it fixes the intelligence cycle's weakest joint — the handoff between analysis and operations.
- You have an unknown Windows executable and two hours. What do you do, and what would you be able to tell the incident team at the end? A time-boxed triage question. The constraint is the point — it tests prioritisation, not whether you can reverse engineer.
- How would you find command-and-control beaconing in network telemetry when you have no indicators to search for? A behaviour-first detection question. With no indicators available, the answer has to reason from what beaconing inherently looks like.
- It is 2am during a live incident and the incident commander asks you "is this ransomware?" You genuinely do not know yet. What do you say? A pressure question. The failure modes are equally bad in both directions: guessing to sound useful, or refusing to commit and being useless.
- An intrusion started with valid credentials against an internet-facing VPN, with no malware involved until well after initial access. How well does the Cyber Kill Chain describe this, and what would you use instead? A question designed to see whether you can criticise a framework you are expected to know. Identity-based intrusions are exactly where the kill chain fails.
- You have recovered a suspicious executable from an executive's laptop during a live incident. A colleague suggests uploading it to VirusTotal. What do you say? An operational security question that catches a lot of otherwise strong candidates. The instinct to upload is exactly the instinct being tested.
- Ransomware has been deployed across part of your estate. A known family was used, a ransom note was left, but no data exfiltration has been observed despite C2 being active for six days beforehand. What are your hypotheses, and how would you test them? A case built around one diagnostic anomaly. The scoring is about whether you notice that the missing exfiltration is the interesting part.
Practise these
Reading an expert answer and producing one under questioning are different skills. The simulator asks these questions, grades your answer against the same rubric you see here, and asks the follow-up an interviewer would ask next.