Blog › Interview Questions
Interview prep · Freshers to 2 years

Cyber Security Interview Questions and Answers (2026)

The 40 questions interviewers actually ask — in the order you will face them — with a short answer, what the interviewer is really checking, and how to say it.

✍️ Cyber Security Academy trainers ⏱ 14 min read 📅 Updated 9 October 2026
⚡ Short answer

Most cyber security interviews follow the same pattern: a few minutes of fundamentals (CIA triad, encryption, ports), a block of role questions (SOC, VAPT or network), one or two real scenarios, and a short HR round. Prepare the basics until you can explain them with an example, pick the block that matches your job description, and practise the scenarios out loud.

Start here

First, the questions running in your head

Before any technical question, almost every learner we train asks us these six. Here are the honest answers.

🤔

What will they ask a fresher like me?

Mostly fundamentals — the CIA triad, encryption vs hashing, common ports, TCP vs UDP — plus one block for the role and a couple of real situations. Nobody expects a fresher to know everything. They want clear basics and honest answers.

💻

Do I need coding?

Not for most entry-level SOC and VAPT roles. You should be able to read a short Python or Bash script and explain what it does. Writing small scripts is a plus, not a filter.

😬

What if I don’t know an answer?

Say so, then show how you would find out: “I haven’t used that directly, but I would start by…”. A confident wrong answer hurts you far more than an honest gap.

🎯

SOC or VAPT — what should I prepare?

Read the job description. SIEM, alerts and incidents mean SOC (Round 3). Burp Suite, Nmap and reports mean VAPT (Round 4). Everyone needs Rounds 1, 2 and 5.

🔁

How many rounds will there be?

Usually two to four: a screening call, one or two technical rounds (often with a scenario or a small practical task), and an HR or manager round. Larger companies may add an online test first.

📜

Will they ask about my certificate?

They will ask what you learned from it, not just its name. For every course or certification on your resume, be ready to explain one thing you practised hands-on.

The big picture

How a cyber security interview usually flows

Knowing the order takes away half the nerves. The rounds below follow the same sequence.

📞

Screening call

15–20 min

Why security, your background, notice period and shift preference.

🧠

Technical round

30–60 min

Fundamentals, networking and role questions — Rounds 1 to 4 below.

🧪

Scenario or practical

20–45 min

“What would you do if…”, a log to read, or a small lab task.

🤝

HR or manager

15–30 min

Communication, attitude, salary expectations and joining date.

Round 1 · Everyone gets this

Cyber security fundamentals interview questions

The first ten minutes decide how the rest goes. Interviewers use these to check whether your basics are solid enough to build on. Tap a question to see the answer.

Q1

What is the CIA triad?

Confidentiality, Integrity and Availability — the three goals every security control protects. Confidentiality: only the right people can read data (encryption, access control). Integrity: data is not changed without anyone noticing (hashes, digital signatures). Availability: systems are up when people need them (backups, redundancy, DDoS protection).

🎯 What they’re really checking: whether you can connect theory to real controls, not just recite three words.

💬 Say it like this: “CIA is confidentiality, integrity and availability. For example, ransomware attacks availability, a tampered invoice attacks integrity, and a leaked database attacks confidentiality.”

Q2

What is the difference between a threat, a vulnerability and a risk?

A vulnerability is a weakness, such as an unpatched server. A threat is something that could exploit it, such as a ransomware group. Risk is the chance of that happening multiplied by the damage it would cause. You reduce risk by fixing the weakness, reducing exposure or limiting the impact.

🎯 What they’re really checking: precise vocabulary. Mixing these three up is the most common fresher mistake.

Q3

Encryption vs hashing vs encoding — what is the difference?

Encryption is reversible with a key and protects confidentiality (AES, RSA). Hashing is one-way and produces a fixed-length value, used for integrity checks and storing passwords (SHA-256, bcrypt). Encoding such as Base64 only changes the format — anyone can decode it, so it gives no security at all.

🎯 What they’re really checking: that you will never call Base64 “encryption” in a report.

💬 Say it like this: “Encryption needs a key to reverse, hashing can’t be reversed, and encoding isn’t security — it’s just a different format.”

Q4

Symmetric vs asymmetric encryption?

Symmetric uses one shared key for both encryption and decryption — fast, used for bulk data (AES). Asymmetric uses a public and private key pair — slower, used for key exchange and digital signatures (RSA, ECC). HTTPS uses both: asymmetric to agree on a key, then symmetric for the actual data.

🎯 What they’re really checking: the TLS example. It shows you understand why both exist.

Q5

What is password salting and why is it used?

A salt is a random value added to each password before hashing, so two users with the same password get different hashes. It defeats precomputed rainbow tables. Good systems also use slow hashing algorithms such as bcrypt or Argon2 so that brute-forcing stolen hashes takes far longer.

🎯 What they’re really checking: whether you know how passwords should be stored, not just that they are “encrypted”.

Q6

IDS vs IPS — what is the difference?

An IDS (Intrusion Detection System) watches traffic and raises an alert, but does not stop anything. An IPS (Intrusion Prevention System) sits inline and can block traffic. The trade-off: a false positive on an IPS can block legitimate users, so IPS rules are tuned carefully.

🎯 What they’re really checking: that you mention the false-positive trade-off — it shows practical thinking.

Q7

What is defence in depth?

Using several layers of controls so that one failure does not become a breach: a firewall at the edge, MFA on accounts, EDR on laptops, patching, network segmentation, backups and user awareness training. If phishing gets past the email filter, MFA and EDR are still there.

🎯 What they’re really checking: whether you think in layers instead of “just buy a firewall”.

Q8

Authentication vs authorisation?

Authentication proves who you are (password, OTP, fingerprint). Authorisation decides what you are allowed to do once you are in (read files, approve payments). MFA strengthens authentication by combining factors: something you know, something you have and something you are.

🎯 What they’re really checking: a clean one-line distinction. Broken authorisation is the top web risk in the OWASP list, so this links to later questions.

Round 2 · Everyone gets this

Networking interview questions for cyber security

You can’t defend a network you can’t explain. Almost every attack question later builds on these answers.

Q9

Explain the OSI model in one minute.

Seven layers from the cable to the app: Physical, Data Link, Network, Transport, Session, Presentation, Application. The trick is to tie attacks to layers: ARP spoofing at layer 2, IP spoofing at layer 3, a SYN flood at layer 4, SQL injection and XSS at layer 7.

🎯 What they’re really checking: whether you can place an attack on the right layer, not whether you memorised seven names.

Q10

TCP vs UDP — when is each used?

TCP is connection-oriented and reliable — it confirms delivery and keeps order (web, SSH, email). UDP is connectionless and fast, with no delivery guarantee (DNS queries, video calls, streaming). Attackers abuse UDP for amplification attacks because the source address is easy to fake.

🎯 What they’re really checking: real examples of each, plus one security angle.

Q11

What happens in the TCP three-way handshake?

The client sends SYN, the server replies SYN-ACK, the client confirms with ACK — then data flows. A SYN flood sends thousands of SYNs and never completes the handshake, filling the server’s queue of half-open connections. SYN cookies and rate limiting are the usual defences.

🎯 What they’re really checking: that you know the attack that abuses it. Nmap’s SYN scan (-sS) also relies on this handshake.

Q12

What happens when you type a URL into the browser?

The browser resolves the domain through DNS, opens a TCP connection to the IP, performs a TLS handshake to set up encryption and verify the certificate, sends an HTTP request, and renders the response. Each step has its own attacks: DNS spoofing, man-in-the-middle, fake certificates, injection in the web app.

🎯 What they’re really checking: end-to-end understanding. This one question covers networking, crypto and web security together.

💬 Say it like this: “DNS gives the IP, TCP connects, TLS encrypts and proves the server’s identity, HTTP asks for the page — and I can name an attack at each step.”

Q13

Which common ports should you know?

21 FTP, 22 SSH, 23 Telnet, 25 SMTP, 53 DNS, 80 HTTP, 110 POP3, 143 IMAP, 443 HTTPS, 445 SMB, 3306 MySQL, 3389 RDP. Know why some are risky when exposed to the internet: Telnet and FTP send passwords in clear text, and open SMB or RDP is a favourite ransomware entry point.

🎯 What they’re really checking: quick recall, then the “so what” — which open port would worry you on a scan report.

Q14

What is ARP spoofing?

ARP maps IP addresses to MAC addresses on a local network and has no authentication. An attacker sends fake ARP replies saying “the gateway’s IP is at my MAC”, so traffic flows through them — a man-in-the-middle. Defences include Dynamic ARP Inspection on switches, static ARP entries for critical hosts, and encrypting traffic.

🎯 What they’re really checking: that you understand why local-network attacks work, and one defence for each.

Q15

What does a firewall do? Stateful vs stateless?

A firewall allows or blocks traffic based on rules. A stateless firewall checks each packet on its own (source, destination, port). A stateful firewall tracks connections, so it allows replies to traffic you started and blocks unsolicited packets. Next-generation firewalls also understand applications and users.

🎯 What they’re really checking: the stateful idea — it explains why most inbound traffic is blocked by default.

💡 Basics feel shaky? Our trainers explain these with live labs — sit in on a class for free.

Book a free demo
Round 3 · SOC analyst roles

SOC analyst interview questions

If the job description mentions SIEM, alerts, L1/L2 or incident response, expect this block. Want to go deeper? See our SOC Analyst training.

Q16

What is a SIEM and why does a SOC use it?

A SIEM (Security Information and Event Management) collects logs from firewalls, servers, endpoints and cloud services, normalises them, correlates events and raises alerts when rules match. Examples: Splunk, Microsoft Sentinel, IBM QRadar. Without it, analysts would be searching dozens of separate log sources by hand.

🎯 What they’re really checking: that you know what goes into a SIEM (log sources) and what comes out (alerts), and that you have used at least one.

Q17

Walk me through how you triage an alert.

1) Read the alert and the rule that fired. 2) Add context: which user, which host, how critical is the asset. 3) Check the raw logs around that time. 4) Check reputation of IPs, domains or file hashes in threat intelligence. 5) Decide: true positive or false positive. 6) Escalate or contain if real, otherwise close it — and in both cases write clear notes.

🎯 What they’re really checking: a calm, repeatable process and the habit of documenting. This is the single most important SOC question.

💬 Say it like this: “I never close an alert on a guess. I verify in the raw logs, check reputation, and write down why I decided what I decided.”

Q18

False positive vs false negative — which is worse?

A false positive is an alert on harmless activity — it wastes time and causes alert fatigue. A false negative is a real attack that raised no alert — far more dangerous, because nobody is looking. Good tuning cuts false positives without creating blind spots.

🎯 What they’re really checking: that you don’t “fix” noise by simply switching rules off.

Q19

What are the phases of incident response?

Using the NIST model: Preparation (plans, tools, training) → Detection and analysis → Containment, eradication and recovery → Post-incident activity (lessons learned, improving detections). Some teams use the six-step SANS version, which splits the middle phase.

🎯 What they’re really checking: the order — especially containment before eradication — and that lessons learned is a real step.

Q20

What is MITRE ATT&CK and how is it used?

A public knowledge base of real attacker tactics (the goal, such as initial access or persistence) and techniques (how they do it, such as T1566 phishing). SOC teams map their detections to it to see which techniques they can and cannot detect, and use it to describe incidents in a common language.

🎯 What they’re really checking: one concrete example of a tactic and a technique, not just the name of the framework.

Q21

Which Windows event IDs do you know?

4624 successful logon, 4625 failed logon, 4688 new process created, 4720 user account created, 4732 member added to a security-enabled group, 1102 audit log cleared. A burst of 4625s followed by a 4624 from the same source is a classic brute-force pattern worth investigating.

🎯 What they’re really checking: hands-on log experience. Reading real logs in a lab is the fastest way to answer this confidently.

Q22

How would you investigate a phishing email?

Check the headers (real sender, Return-Path, SPF, DKIM and DMARC results), open links and attachments only in a sandbox, find who else received it and who clicked, block the sender and URL, pull the email from all mailboxes, and reset credentials for anyone who entered them. Then document and report.

🎯 What they’re really checking: that you think beyond one mailbox — scope, containment and follow-up.

Q23

What is the difference between an IOC and an IOA?

An Indicator of Compromise is evidence that something already happened: a malicious file hash, IP address or domain. An Indicator of Attack is behaviour that shows an attack in progress, such as a process dumping credentials from memory. IOCs are easy to change for attackers; behaviour is harder to hide.

🎯 What they’re really checking: awareness of why modern detection focuses on behaviour, not just blocklists.

Round 4 · Ethical hacking & VAPT roles

Ethical hacking and penetration testing interview questions

If the job description mentions VAPT, Burp Suite, Nmap or pentest reports, expect this block. Related training: Ethical Hacking and Penetration Testing.

Q24

Vulnerability assessment vs penetration testing?

A vulnerability assessment finds and lists known weaknesses across many systems, mostly with scanners, and ranks them. A penetration test goes further: within an agreed scope, the tester actually exploits weaknesses to prove what an attacker could reach. VA is broad; a pentest is deep and proves impact.

🎯 What they’re really checking: that you know a scanner report alone is not a pentest.

Q25

What are the phases of a penetration test?

Planning and scoping (written authorisation, rules of engagement) → Reconnaissance → Scanning and enumeration → Exploitation → Post-exploitation (privilege escalation, what data is reachable) → Reporting and retesting after fixes.

🎯 What they’re really checking: that you start with authorisation and scope. Testing without written permission is illegal, and interviewers listen for this.

Q26

Explain SQL injection and how to prevent it.

SQL injection happens when user input is placed directly into a database query, so an attacker can change the query — for example to bypass a login or read other users’ data. Prevent it with parameterised queries (prepared statements), least-privilege database accounts and input validation. Escaping alone is not enough.

🎯 What they’re really checking: that you lead with parameterised queries as the fix, not a web application firewall.

💬 Say it like this: “The input becomes part of the query instead of staying data. Parameterised queries keep code and data separate, so the fix is in the code, not just a filter in front of it.”

Q27

What are the types of XSS?

Reflected — the script comes from the request (often a link) and is echoed straight back. Stored — the script is saved, for example in a comment, and runs for every visitor. DOM-based — client-side JavaScript writes untrusted data into the page. Defences: context-aware output encoding, Content Security Policy, and HttpOnly cookies.

🎯 What they’re really checking: that you can tell stored XSS is usually the most serious, and why.

Q28

What is CSRF?

Cross-Site Request Forgery tricks a logged-in user’s browser into sending a request they didn’t intend — such as changing their email — because the browser attaches their cookies automatically. Defences: anti-CSRF tokens, SameSite cookies, and asking for the password again for sensitive actions.

🎯 What they’re really checking: the difference from XSS — CSRF abuses the user’s session, XSS runs code in their browser.

Q29

Which Nmap scans do you use and why?

-sS SYN scan (fast, the default as root), -sV service versions, -O operating system detection, -p- all 65,535 ports, -sC default scripts, -sU UDP scan for services like DNS and SNMP. Always on targets you are authorised to test.

🎯 What they’re really checking: that you know why you pick a flag, and that you mention authorisation without being asked.

Q30

What is the OWASP Top 10?

A widely used list of the most critical web application security risks, published by the OWASP Foundation and updated every few years. Recent entries include broken access control (number one), cryptographic failures, injection, insecure design, security misconfiguration and server-side request forgery (SSRF).

🎯 What they’re really checking: that you can explain at least three categories with an example. Go deeper in our Web Application Security course.

Q31

What makes a good penetration test finding?

A clear title, a severity rating (usually CVSS), the affected asset, step-by-step reproduction, evidence such as screenshots or requests, the business impact in plain words, and a specific remediation. A developer should be able to reproduce and fix it without calling you.

🎯 What they’re really checking: that you understand the report is what the client pays for. Bring a sample finding from your own lab work.

🧪 Want hands-on labs for SQL injection, XSS and Nmap before your interview? Try a free demo class.

Book a free demo
Round 5 · The real test

Scenario-based cyber security interview questions

This is where interviews are won. There is rarely one right answer — they want to hear a calm order of steps: contain, investigate, fix, communicate.

Q32

“You see 500 failed logins on one account in 10 minutes. What do you do?”

Check the source: one IP points to brute force, many IPs to a distributed attack or password spraying. Most importantly, check for a successful login after the failures. Lock or protect the account, make sure MFA is on, block the source IPs, check whether the same IPs targeted other accounts, and document everything.

🎯 What they’re really checking: the “did any attempt succeed?” question. Missing it is the most common weak answer.

Q33

“An employee clicked a link in an email and entered their password. Now what?”

Reset the password and revoke active sessions immediately. Review sign-in logs for logins from unusual locations, make sure MFA is enforced, find and remove the same email from other mailboxes, block the phishing domain, and check whether mailbox rules or forwarding were created. Then report it — without blaming the employee.

🎯 What they’re really checking: speed and order — contain first, investigate second — and a no-blame attitude that keeps people reporting.

Q34

“Ransomware is found on one laptop. What are your first steps?”

Isolate the laptop from the network straight away — but don’t power it off, so memory evidence is preserved. Escalate according to the incident response plan, identify how it got in and whether it spread to other machines or file shares, then restore from clean, tested backups. Paying is a business and legal decision, not the analyst’s.

🎯 What they’re really checking: isolate-don’t-shut-down, and that you think about lateral spread.

Q35

“During a pentest you find real customer data you didn’t expect. What do you do?”

Stop going further, don’t download or copy more than the minimum needed as proof, record exactly what you accessed, and inform the client contact immediately as the rules of engagement require. Sensitive data exposure usually needs to be reported straight away, not saved for the final report.

🎯 What they’re really checking: ethics and professionalism. This question filters out people who “just want to hack”.

Q36

“A developer wants to switch off a security control to meet a deadline.”

First understand why the control is blocking them. Explain the risk in business terms, offer a safer alternative, and if an exception is really needed, make it time-limited with sign-off from the right owner and a date to switch it back on. Security works best as a partner, not a blocker.

🎯 What they’re really checking: communication and judgement — skills that matter more as you grow.

Round 6 · HR and manager

HR interview questions for cyber security roles

Easy to ignore, easy to lose marks on. Prepare these out loud at least once.

Q37

Why do you want to work in cyber security?

Give a short, specific and true story — the moment you got interested and what you have done since: labs you completed, a home lab you built, a CTF you tried, a course project. “It’s a growing field with good salaries” is true for everyone and tells them nothing about you.

🎯 What they’re really checking: genuine interest backed by action.

Q38

How do you keep yourself updated?

Name real sources you actually use: vendor security advisories, the CISA Known Exploited Vulnerabilities list, security news sites and podcasts, and practice platforms such as TryHackMe or Hack The Box. Mention one recent vulnerability or incident you read about and what you learned from it.

🎯 What they’re really checking: a habit of learning. The “one recent thing” example proves it.

Q39

Tell me about a project you have done.

Use STAR: the Situation, the Task, the Action you took and the Result. Pick a lab assessment, a SIEM use case or a vulnerability report, explain one problem you got stuck on and how you solved it, and offer to share the report or screenshots.

🎯 What they’re really checking: proof of hands-on work. A documented project beats any certificate in this answer.

Q40

Are you comfortable with rotational or night shifts?

Most SOC teams run 24×7, so entry-level roles often include rotational shifts. Answer honestly. If you can do it, say so and mention it is a fast way to see many real incidents. If you can’t, say so clearly — a wrong commitment helps nobody.

🎯 What they’re really checking: honesty and whether you understand how a SOC operates.

Your answer formula

How to answer any cyber security interview question

Stuck on a question you didn’t prepare? This four-step pattern keeps any answer clear and complete.

1

Define it in one line

A crisp definition first. No jargon you can’t explain if they ask “what does that mean?”

2

Give a real example

An attack, a tool or a log entry you have actually seen in a lab or a project.

3

Say how you’d detect or test it

Which log, which tool, which command. This is where hands-on practice shows.

4

Say how you’d fix or prevent it

The control that stops it, and who would own the fix. Ending here sounds professional.

Mistakes that cost freshers the offer

✕  Reciting definitions with no example

✕  Listing tools on the resume you have never actually used

✕  Talking about hacking without ever mentioning permission or scope

✕  Guessing instead of saying “I’m not sure, but here’s how I’d find out”

✕  Having no lab, project or report to show

One week, step by step

7-day cyber security interview preparation plan

Have an interview next week? Follow this plan. About two focused hours a day is enough if your basics are already in place. If they are not there yet, a structured cyber security course in Hyderabad with labs and mock interviews is the faster route.

Day 1

Fundamentals

CIA triad, encryption vs hashing, authentication. Round 1.

Day 2

Networking

OSI, TCP vs UDP, the handshake, ports, DNS. Round 2.

Day 3

Your role block

SOC (Round 3) or VAPT (Round 4) — whichever your job description asks for.

Day 4

Hands-on lab

Read real Windows logs in a SIEM, or run Nmap and Burp Suite on a practice app.

Day 5

Scenarios out loud

Answer every Round 5 question aloud. Record yourself once and listen back.

Day 6

Your story

Resume check, one project in STAR format, and a mock interview with a friend or trainer.

Day 7

Revise and rest

Skim only the yellow “what they’re checking” notes. Sleep well.

Interview day

You’ve got this 💪

Join or arrive 10 minutes early, keep your project report ready, and think out loud.

Still wondering?

Frequently asked questions

Are cyber security interviews hard for freshers?

They are manageable if your basics are clear. Most fresher interviews focus on fundamentals, networking and one role area, plus a couple of scenarios. Clear explanations with real examples matter more than knowing advanced topics.

How many interview questions should I prepare?

Prepare the 40 questions in this guide well rather than 200 superficially. Interviewers ask follow-up questions on whatever you answer, so understanding beats memorising.

Do cyber security interviews include coding?

Entry-level SOC and VAPT interviews rarely ask you to write code. You may be asked to read a short script or explain a command. Security engineering and automation roles may test scripting in Python or Bash.

Which certification helps most in interviews?

Employers value what you can demonstrate. A certification such as CompTIA Security+ or CEH helps your resume get shortlisted, but a documented lab project or report is what helps you in the interview itself.

How long should I prepare for a cyber security interview?

If your basics are already in place, one focused week using the plan above is enough to revise. If you are starting from zero, plan for a structured course of around three months with hands-on labs.

How can Cyber Security Academy help me prepare?

Our classroom and live online programmes include hands-on labs, documented projects, resume preparation and mock interviews as part of placement assistance. We do not guarantee placement. You can book a free demo class to see how sessions run.

🛡️
Written by the Cyber Security Academy training team

Based on the questions our learners report from real interviews. Last updated 9 October 2026. Spotted something outdated? Tell us on WhatsApp.

Next step

Practise these questions with a trainer, not alone

Hands-on labs, documented projects and mock interviews in every batch — in our Kukatpally classroom or live online. Next batch starts Monday, 2 November 2026.

Explore the course that matches your interview
Free demo class

Book a free Cyber Security demo

Leave your details and a course counsellor will call you to fix a demo slot.

Thank you! A counsellor will call you shortly to confirm your demo slot.

Or call +91 70367 44555