Question library
Source grading & evaluation interview questions
Every question comes with the key points a strong answer covers, the mistakes that lose candidates points, and a vetted expert answer. Read them, then practise them under questioning.
4 questions matching your filters
- What threat intelligence do you read regularly, and how do you decide whether to believe a vendor report? The second half is the real question. Anyone can list sources; the interviewer wants to know whether you read them critically.
- Explain the Admiralty source grading scale. How would you grade a well-regarded vendor's report making a claim that no other source has corroborated? A question with a specific correct shape: the scale grades source and information separately, and this scenario is exactly the case where the two diverge.
- Four separate publications report the same breach claim. How do you decide whether that counts as corroboration? Circular reporting is the most common way corroboration gets faked, and this question tests whether you check provenance or count citations.
- A vendor publishes a report claiming an intrusion set is actively targeting your sector, with 200 indicators appended. Your CISO forwards it and asks "are we affected?" Walk me through your response. The most common real task in CTI, and a test of whether you start with the indicators or with the question.
Practise these
Reading an expert answer and producing one under questioning are different skills. The simulator asks these questions, grades your answer against the same rubric you see here, and asks the follow-up an interviewer would ask next.