Question library
Intelligence cycle & F3EAD interview questions
Every question comes with the key points a strong answer covers, the mistakes that lose candidates points, and a vetted expert answer. Read them, then practise them under questioning.
5 questions matching your filters
- Explain the difference between tactical, operational and strategic threat intelligence, with an example of each. A definitional question that becomes diagnostic the moment you are asked for examples — most candidates produce three tactical examples.
- You are the first intelligence hire at a company with a working SOC but no CTI function. What do you do in your first 90 days? A senior question that separates people who would start by buying a feed from people who would start by asking who the customer is.
- Your CISO says "I want to know about ransomware." Turn that into something you can actually collect against. Requirements management is where most CTI functions quietly fail, and this question tests it directly.
- What is F3EAD, and why do some CTI teams prefer it to the traditional intelligence cycle? F3EAD comes up because it fixes the intelligence cycle's weakest joint — the handoff between analysis and operations.
- On the same morning: a new critical vulnerability is being exploited in the wild, the CISO wants a board paper by Friday, and IR needs support on a live case. You cannot do all three. How do you decide? A prioritisation question. The interviewer wants a decision rule, not a heroic claim that you would somehow do everything.
Practise these
Reading an expert answer and producing one under questioning are different skills. The simulator asks these questions, grades your answer against the same rubric you see here, and asks the follow-up an interviewer would ask next.