Question library
Detection & threat hunting interview questions
Every question comes with the key points a strong answer covers, the mistakes that lose candidates points, and a vetted expert answer. Read them, then practise them under questioning.
3 questions matching your filters
- What is the difference between an indicator of compromise and a TTP, and why does the distinction matter? The Pyramid of Pain question in disguise. Getting the definitions right is the easy half; explaining the operational consequence is what scores.
- How would you find command-and-control beaconing in network telemetry when you have no indicators to search for? A behaviour-first detection question. With no indicators available, the answer has to reason from what beaconing inherently looks like.
- You have read a report describing an actor that uses scheduled tasks to run scripts from user-writable directories. Turn that into a threat hunt. The intelligence-to-operations handoff, tested concretely. A hypothesis without expected false positives is not a hunt.
Practise these
Reading an expert answer and producing one under questioning are different skills. The simulator asks these questions, grades your answer against the same rubric you see here, and asks the follow-up an interviewer would ask next.