Question library
CTI interview questions with expert answers
Every question comes with the key points a strong answer covers, the mistakes that lose candidates points, and a vetted expert answer. Read them, then practise them under questioning.
9 questions matching your filters
- What is cyber threat intelligence, and how is it different from a threat feed? Almost every CTI interview opens here. The question looks trivial and is not — it is checking whether you understand that intelligence is defined by process and purpose, not by…
- Why do you want to work in threat intelligence rather than another security discipline? A motivation question with a technical subtext: the interviewer is checking whether you know what the job actually involves day to day, or whether you are picturing a more…
- What threat intelligence do you read regularly, and how do you decide whether to believe a vendor report? The second half is the real question. Anyone can list sources; the interviewer wants to know whether you read them critically.
- What is the difference between an indicator of compromise and a TTP, and why does the distinction matter? The Pyramid of Pain question in disguise. Getting the definitions right is the easy half; explaining the operational consequence is what scores.
- How do the Diamond Model, the Cyber Kill Chain and MITRE ATT&CK relate to each other? Do they compete? A comparison question where the expected answer is that they compose rather than compete — and that you can say what each one uniquely gives you.
- An endpoint alert shows that a scheduled task was created which launches a PowerShell one-liner from a user's AppData directory. Map this to MITRE ATT&CK. A mapping question with a deliberate trap: the evidence is ambiguous, and the correct answer includes saying so rather than committing to a single technique ID.
- How would you find command-and-control beaconing in network telemetry when you have no indicators to search for? A behaviour-first detection question. With no indicators available, the answer has to reason from what beaconing inherently looks like.
- It is 2am during a live incident and the incident commander asks you "is this ransomware?" You genuinely do not know yet. What do you say? A pressure question. The failure modes are equally bad in both directions: guessing to sound useful, or refusing to commit and being useless.
- The SOC escalates: a finance team member's account authenticated successfully from an IP in a country the company has no presence in, at 03:00 local time. MFA was satisfied. No alerts have fired since. What do you do, and what do you tell the SOC lead? A triage scenario where the obvious conclusion is wrong often enough to matter. Interviewers watch whether you generate benign hypotheses before escalating.
Practise these
Reading an expert answer and producing one under questioning are different skills. The simulator asks these questions, grades your answer against the same rubric you see here, and asks the follow-up an interviewer would ask next.