Interview track
SOC Analyst moving into CTI
You already triage alerts and understand detection. The gap is intelligence tradecraft: requirements, sourcing, structured analysis and writing for someone who is not in the SOC.
What is expected at this level
Expected to reason well about telemetry and detection logic, and to show awareness of intelligence process without yet owning it. Framework depth is assessed generously; analytical discipline and clear reasoning are not.
Start a mock interview
9 questions
Questions from this track
Each one has a vetted expert answer you can read before or after you practise.
- What is cyber threat intelligence, and how is it different from a threat feed?
- Why do you want to work in threat intelligence rather than another security discipline?
- What threat intelligence do you read regularly, and how do you decide whether to believe a vendor report?
- What is the difference between an indicator of compromise and a TTP, and why does the distinction matter?
- How do the Diamond Model, the Cyber Kill Chain and MITRE ATT&CK relate to each other? Do they compete?
- An endpoint alert shows that a scheduled task was created which launches a PowerShell one-liner from a user's AppData directory. Map this to MITRE ATT&CK.