All Cybersecurity Analyst Interview Flashcards
All 150 Cybersecurity Analyst interview flashcards. Tap any question to practice it.
Easy (50)
- What is the CIA triad in security?
- What does confidentiality mean in security?
- What does integrity mean in security?
- What does availability mean in security?
- What is authentication?
- How does authorization differ from authentication?
- What is multi-factor authentication?
- What does encryption do?
- What is the difference between symmetric and asymmetric encryption?
- What is hashing and how does it differ from encryption?
- What does a firewall do?
- What is malware?
- What is a computer virus?
- How does a worm differ from a virus?
- What is a Trojan?
- What is ransomware?
- What is phishing?
- What is social engineering?
- What is a vulnerability in security?
- What is an exploit?
- What is a threat in cybersecurity?
- What is risk in security terms?
- Why is patch management important?
- What does a VPN provide?
- What is the difference between an IDS and an IPS?
- What does a SIEM do?
- What is the principle of least privilege?
- What is defense in depth?
- What is the zero trust security model?
- What is a brute force attack?
- What is a denial-of-service attack?
- What is a man-in-the-middle attack?
- What is SQL injection?
- What is cross-site scripting?
- What is a data breach?
- What is a security incident?
- What is an access control list?
- What is public key infrastructure (PKI)?
- What does TLS protect?
- What is endpoint security?
- Why are audit logs important?
- What is penetration testing?
- Why is security awareness training important?
- What is a CVE?
- What does antivirus software do?
- Why is spam a security concern
- Why are backups a key security control?
- What is a honeypot?
- What is separation of duties?
- What is the difference between a patched vulnerability and a zero-day?
Medium (50)
- What is threat modeling?
- What is an attack surface?
- What is the cyber kill chain?
- What is the MITRE ATT&CK framework?
- What are the phases of incident response?
- What are indicators of compromise?
- What does endpoint detection and response provide?
- How does network segmentation improve security?
- What is privilege escalation?
- What is lateral movement in an attack?
- What is credential stuffing?
- Why are passwords stored as salted hashes?
- What is a rainbow table attack and what defeats it?
- What does the CVSS score represent?
- What are preventive
- What is role-based access control?
- What is single sign-on and a security tradeoff?
- How do OAuth and SAML differ?
- What is CSRF and how is it prevented?
- What do security headers like CSP and HSTS do?
- What do SPF
- What does data loss prevention do?
- What is threat intelligence?
- How does malware sandboxing help analysis?
- What does a digital signature provide?
- How do CRL and OCSP handle revoked certificates?
- What problem does Diffie-Hellman key exchange solve?
- How does tokenization protect sensitive data?
- What is an insider threat?
- What is a software supply chain attack?
- What is the difference between red team and blue team?
- What is responsible vulnerability disclosure?
- How does a stateful firewall differ from a stateless one?
- What is session hijacking?
- What is the purpose of frameworks like ISO 27001 or NIST CSF?
- What is PII and why protect it?
- How does vulnerability scanning differ from penetration testing?
- What is the role of a security operations center?
- What does user and entity behavior analytics detect?
- Why test patches before wide deployment?
- What is the principle of least functionality?
- What does DNSSEC protect against?
- Why classify data?
- What is forward secrecy?
- What is privilege creep and how is it controlled?
- When is a compensating control used instead of a patch?
- How does a honeynet differ from a honeypot?
- How do patch and vulnerability management relate?
- What is a security baseline?
- What is a tabletop exercise in security?
Hard (50)
- What is a buffer overflow and what can it enable?
- How does return-oriented programming bypass DEP?
- How does address space layout randomization protect systems?
- What is a stack canary?
- What is a pass-the-hash attack?
- What is kerberoasting?
- What is a Kerberos golden ticket attack?
- How is DNS tunneling used by attackers?
- What does living off the land mean in attacks?
- Why is fileless malware hard to detect?
- What is a side-channel attack?
- What is a padding oracle attack?
- What is a TLS downgrade attack?
- What does an HSM provide?
- What is SSRF?
- Why is insecure deserialization dangerous?
- What is a TOCTOU vulnerability?
- What characterizes an advanced persistent threat?
- What is an SBOM and why does it matter?
- What is a container escape?
- How do attackers escalate privileges in cloud IAM?
- What is detection engineering?
- What is hypothesis-driven threat hunting?
- What are YARA rules used for?
- What can memory forensics reveal?
- What does SOAR add to security operations?
- What does an assume-breach mindset mean?
- How does cyber resilience differ from cybersecurity?
- What is an NTLM relay attack?
- What problem does certificate transparency solve?
- How do defenders detect command-and-control traffic?
- Why is cryptographic agility important?
- Why is post-quantum cryptography needed?
- What is a business logic vulnerability?
- How do attackers bypass web application firewalls?
- Why is chain of custody important in digital forensics?
- How does privilege separation harden software?
- How do seccomp and sandboxing reduce risk?
- How is MITRE ATT&CK used to assess detection coverage?
- Why are secrets in CI/CD pipelines a major risk?
- How can misconfigured sudo lead to root access?
- What does the pyramid of pain illustrate?
- What is a common Kubernetes RBAC security risk?
- What is forensic readiness?
- When are air gaps and data diodes used?
- How does deception technology aid defense?
- Why is the period after patch release risky?
- Why is mutual TLS important in zero-trust service communication?
- How do you ensure software build integrity against tampering?
- How do you measure the value of purple team exercises?
Ready to practice the full interview?
Try a 10-minute interview for free!
No credit card needed.
