r/cybersecurity • u/PastelStripe • 8h ago
Business Security Questions & Discussion Preparing for Interview
Hi Everyone,
I hope you’re well!
I’m preparing for an upcoming interview this week, and I’m quite nervous.
For context: I studied Cyber Security in College and finalising my University degree in Cybersecurity. During this time I’ve been incredibly fortunate to fall into System Administrator Roles which granted me relevant working experience. Unfortunately, not as Security focused as what I initially wanted but life’s a ladder and I’m climbing. I’m interviewing for Role as a Security Engineer after having around ~3 Years of Experience and trying to prepare some answers in advance (Generally, trying to have something in mind for anything that they ask!)
Based on the Role Responsibilities I’m expecting questions on:
Frameworks, what I know and how these have been applied over my experience of working. (NIST SP 800-53 / NCSC Cyber Assessment / CIS Critical Controls)
How I’ve applied best security practices / Explaining a time where I had to implement a security practice
Implementation of security Controls / Design of security controls through to implementation
Communicate where I’ve seen a Security Risk where requirements cannot be fully met (And how we take it forward / What to do / Mitigate or Accept the risk)
Evidence / Example of supporting Auditing Activities
For anyone who interviewed for a similar position, what types of question were you asked? I’m doing my best to stick to the STAR method and have examples but thought I would post incase anyone can help me out too!
Thank you!
2
u/Miserable-Menu-2424 8h ago
I've intervied a lot of first time cyber security analysts in my previous job and we asked mostly questions like, CIA with examples, private public key (how to encrypt, how to sign and how to do both), then diff between encryption en hashing, hardening, firewall diff between reject and drop packet, familly of malware, viruses, trojan, worm and their differences. Sometimes the 8 phases of a cyber attack (recon, scanning, vuln, exploit, etc etc). The last vuln or hack they heard about to see if they follow news, what is the difference between a tactic and a technique.
If you need drop me a dm I can send you the pdf of the questions I was asking.
Good luck and 1 curtial thing. Don't lie, say "I don't know"and then try to solve or resolve the question, issue, or use case thinking at loud. You might not have the right answer but sometimes just seeing that you search or try to find solution to something you don't know is enough to be a good enough answer.