Question library
CTI interview questions with expert answers
Every question comes with the key points a strong answer covers, the mistakes that lose candidates points, and a vetted expert answer. Read them, then practise them under questioning.
24 questions matching your filters
- What threat intelligence do you read regularly, and how do you decide whether to believe a vendor report? The second half is the real question. Anyone can list sources; the interviewer wants to know whether you read them critically.
- You are the first intelligence hire at a company with a working SOC but no CTI function. What do you do in your first 90 days? A senior question that separates people who would start by buying a feed from people who would start by asking who the customer is.
- You have one piece of evidence: a single IP address that a compromised host was beaconing to. Walk me through how you would develop this. The canonical Diamond Model question. Interviewers are listening for a structured pivot sequence and for restraint about what infrastructure overlap actually proves.
- Your CISO says "I want to know about ransomware." Turn that into something you can actually collect against. Requirements management is where most CTI functions quietly fail, and this question tests it directly.
- What is F3EAD, and why do some CTI teams prefer it to the traditional intelligence cycle? F3EAD comes up because it fixes the intelligence cycle's weakest joint — the handoff between analysis and operations.
- What is the difference between saying something is "likely" and saying you have "high confidence" in an assessment? Can you have high confidence in an unlikely outcome? The single highest-leverage tradecraft question in CTI interviews. A large share of candidates conflate the two axes, and interviewers use it as a fast proxy for real analytic…
- Critique this line from a draft report: "It is believed that this sophisticated attack may possibly be linked to a nation-state actor." Rewrite it. A red-pen exercise. Every fault in this sentence is one interviewers see regularly in real drafts.
- Explain the Admiralty source grading scale. How would you grade a well-regarded vendor's report making a claim that no other source has corroborated? A question with a specific correct shape: the scale grades source and information separately, and this scenario is exactly the case where the two diverge.
- Tell me about a time your analysis turned out to be wrong. What happened, and what did you change? The behavioural question that most reliably separates analysts with real experience from those without. Everyone has been wrong; the question is what you did about it.
- Four separate publications report the same breach claim. How do you decide whether that counts as corroboration? Circular reporting is the most common way corroboration gets faked, and this question tests whether you check provenance or count citations.
- A senior analyst has written an assessment you think is wrong. It is going out to the CISO tomorrow. What do you do? A question about analytic culture. The interviewer is checking whether you raise disagreement well — and whether you would let something wrong go out to avoid friction.
- You have been producing reports for six months and you suspect nobody is reading them. How do you find out, and what do you change? A question about the feedback step of the intelligence cycle — the one most teams skip, and the reason many CTI functions get cut.
- On the same morning: a new critical vulnerability is being exploited in the wild, the CISO wants a board paper by Friday, and IR needs support on a live case. You cannot do all three. How do you decide? A prioritisation question. The interviewer wants a decision rule, not a heroic claim that you would somehow do everything.
- A vendor publishes a report claiming an intrusion set is actively targeting your sector, with 200 indicators appended. Your CISO forwards it and asks "are we affected?" Walk me through your response. The most common real task in CTI, and a test of whether you start with the indicators or with the question.
- Your CISO has seen an ATT&CK coverage heat map showing 70% of techniques as "covered" and wants to know if that means we are 70% secure. What do you say? A question about the limits of a framework, aimed at analysts senior enough to be asked to defend a metric they did not choose.
- An intrusion started with valid credentials against an internet-facing VPN, with no malware involved until well after initial access. How well does the Cyber Kill Chain describe this, and what would you use instead? A question designed to see whether you can criticise a framework you are expected to know. Identity-based intrusions are exactly where the kill chain fails.
- Walk me through how you would use Analysis of Competing Hypotheses on an intrusion where the evidence is ambiguous. What makes ACH different from just weighing the evidence? ACH questions separate people who can name the technique from people who understand its central counterintuitive claim: supporting evidence is nearly worthless.
- An executive wants a named attacker for a board slide tomorrow. Your evidence supports clustering the activity but not naming a group. What do you do? A behavioural question testing analytic integrity under stakeholder pressure — and whether you can push back without being obstructive.
- You have recovered a suspicious executable from an executive's laptop during a live incident. A colleague suggests uploading it to VirusTotal. What do you say? An operational security question that catches a lot of otherwise strong candidates. The instinct to upload is exactly the instinct being tested.
- You have read a report describing an actor that uses scheduled tasks to run scripts from user-writable directories. Turn that into a threat hunt. The intelligence-to-operations handoff, tested concretely. A hypothesis without expected false positives is not a hunt.
Practise these
Reading an expert answer and producing one under questioning are different skills. The simulator asks these questions, grades your answer against the same rubric you see here, and asks the follow-up an interviewer would ask next.