Threat Analyst Interview Questions

480 threat analyst interview questions shared by candidates

The interviewer talked about using brute force for lateral movement .. ->which is not stealth and most attackers do NOT use this technique instead they leverage existing tools on the network such as vulnerable remote access tools
avatar

Cyber Threat Analyst

Interviewed at Synchrony

4.1
Aug 9, 2019

The interviewer talked about using brute force for lateral movement .. ->which is not stealth and most attackers do NOT use this technique instead they leverage existing tools on the network such as vulnerable remote access tools

For initial access i talked about drive by downloads/watering hole techniques and methods to mitigate and detect it. After a while the other interviewer asks me - tell me a way an attacker from the outside would get into an organization?? well, drive by downloads is one such technique. I also mentioned valid accounts and spear phishing. Also when i mentioned drive-by downloads the interviewer mentioned that this technique is after an attacker has access to the system (LOL *BANGS MY HEAD TO THE WALL*). This technique is USED for initial compromise. How are these people even security professionals?
avatar

Cyber Threat Analyst

Interviewed at Synchrony

4.1
Aug 9, 2019

For initial access i talked about drive by downloads/watering hole techniques and methods to mitigate and detect it. After a while the other interviewer asks me - tell me a way an attacker from the outside would get into an organization?? well, drive by downloads is one such technique. I also mentioned valid accounts and spear phishing. Also when i mentioned drive-by downloads the interviewer mentioned that this technique is after an attacker has access to the system (LOL *BANGS MY HEAD TO THE WALL*). This technique is USED for initial compromise. How are these people even security professionals?

Asked about privilege access .. when trying to explain from attacker perspective they cut me off to say in a large environment an attacker would use user accounts with lower privileges to admin accounts and then establish lateral movement - which is just one vector? I guess that is all he knew?
avatar

Cyber Threat Analyst

Interviewed at Synchrony

4.1
Aug 9, 2019

Asked about privilege access .. when trying to explain from attacker perspective they cut me off to say in a large environment an attacker would use user accounts with lower privileges to admin accounts and then establish lateral movement - which is just one vector? I guess that is all he knew?

General questions about bad actor usage of social media, product features etc., and more technical questions about data mining/ analysis. Questions were too technical which is not quite possible for someone from outside the company to answer. It is not possible to know what resources the company has, what is the research and data mining capacity in the team. You have to presume things, which I think they didn't like. My specialisation in the field was not tested at all.
avatar

Threat Analyst

Interviewed at TikTok

3.2
Mar 4, 2021

General questions about bad actor usage of social media, product features etc., and more technical questions about data mining/ analysis. Questions were too technical which is not quite possible for someone from outside the company to answer. It is not possible to know what resources the company has, what is the research and data mining capacity in the team. You have to presume things, which I think they didn't like. My specialisation in the field was not tested at all.

Viewing 281 - 290 interview questions

Glassdoor has 480 interview questions and reports from Threat analyst interviews. Prepare for your interview. Get hired. Love your job.