Cyber Security: interview questions and learning guide

Security basics, monitoring, ethical testing and incident response

Practise Cyber Security on Padimachi

What you will learn

Security fundamentals: CIA and risk

A house has a lock, a guard and an alarm. Security is the same idea for data: several small protections so one failure does not open everything.

Information security protects data and systems by keeping three goals: confidentiality (only the right people see it), integrity (it is not changed wrongly) and availability (it works when needed). A threat is something that can cause harm, a vulnerability is a weakness it can use, and risk is how likely and how costly that harm is. Good security layers many controls, gives people the least access they need, and assumes some defences will fail.

Interview tip: In an interview, link every control you mention to one of the three goals and to a risk it reduces.

Networking for security

Data travels like parcels through a postal system. To spot a suspicious parcel you first need to know how normal delivery works.

Security work starts with networking. Devices have IP addresses, use DNS to turn names into addresses, and talk through ports such as 80 and 443 for web traffic. A firewall allows or blocks traffic by rules. A VPN creates an encrypted tunnel across a public network. Network segmentation splits a network into zones so a problem in one zone cannot spread freely. Analysts read traffic logs to tell normal behaviour from scans and unusual connections.

Interview tip: Be ready to explain what happens when you open a website, step by step, including DNS and the secure connection.

Common threats and attacks

Most break-ins use the front door: a tricked person, a weak password or an old unpatched system, not movie-style hacking.

Attackers usually take the easiest path. Social engineering tricks people through fake emails, calls or messages. Malware is harmful software, including ransomware that locks files for money. Password attacks guess or reuse stolen passwords. Denial of service floods a service so real users cannot reach it. Insiders can misuse access by mistake or on purpose. Defenders reduce these risks with awareness training, multi-factor login, updates, backups and monitoring.

Interview tip: Describe an attack and then its defences. Interviewers want to hear how you would stop it, not how to run it.

Security operations and monitoring

A control room watches many screens. Most alerts are noise; the skill is spotting the few that matter and acting fast.

A security operations centre (SOC) watches logs and alerts from firewalls, servers, email and laptops. A SIEM tool collects and searches these logs and raises alerts by rules. An analyst triages each alert: is it real, how serious, who is affected? False positives are alerts that look bad but are harmless. Real incidents are escalated with clear notes. Endpoint tools (EDR) watch laptops and servers and can isolate a machine. Good analysts write precise tickets and follow runbooks.

Interview tip: Practise a triage answer: confirm, scope, contain, escalate, document. Bring one example of reading logs.

Identity, access and passwords

A building gives each person a card that opens only certain doors. Identity security is the same card system for digital doors.

Authentication proves who you are and authorization decides what you may do. Multi-factor authentication adds a second proof such as a code or app approval, which blocks most stolen-password attacks. Single sign-on lets one secure login open many apps. Role-based access gives permissions to roles instead of individuals. Privileged accounts, such as administrators, need extra care: separate accounts, approval, and logs. When someone leaves or changes role, access must be removed quickly.

Interview tip: Mention least privilege, MFA and regular access reviews in any identity answer.

Encryption and certificates

A sealed envelope hides a letter in transit. A signature on it proves who wrote it. Encryption and signatures do these two jobs for data.

Encryption scrambles data so only someone with the right key can read it. Symmetric encryption uses one shared key and is fast. Asymmetric encryption uses a public key to lock and a private key to unlock. Hashing turns data into a fixed fingerprint that cannot be reversed and is used to store passwords and check files. A digital certificate ties a public key to a website identity, and TLS uses it to protect the connection you see as HTTPS. Keys must be kept safe, because losing the key means losing the protection.

Interview tip: Know the difference between encryption (reversible with a key) and hashing (one way).

Web application security basics

A shop counter must check every note and every request. If it trusts everything a customer hands over, someone will eventually hand over trouble.

Web applications are attacked through the data they accept. The OWASP Top 10 lists the most common weaknesses, such as broken access control, injection and misconfiguration. Injection happens when user input is mixed into a database query or command. Cross-site scripting runs harmful script in another user's browser. Developers stop these with parameterised queries, input validation, output encoding, safe session handling and checking permissions on every request. Testers look for these weaknesses only on systems they have written permission to test.

Interview tip: Always connect a weakness to its fix. Say you test only with permission and inside the agreed scope.

Incident response and recovery

A fire drill is practised before the fire. A good response plan means people calm down and follow steps when the alarm is real.

Incident response is the plan for handling a security event. The usual phases are preparation, detection, containment, eradication, recovery and lessons learned. Containment limits the damage, for example by isolating a laptop. Eradication removes the cause. Recovery restores systems from clean backups. Evidence is kept carefully, and clear notes are taken with times. In India, serious incidents may need to be reported to CERT-In within the time limit set by current rules, so teams check the latest rules.

Interview tip: Give a calm sequence: detect, contain, eradicate, recover, learn. Mention communication to staff and management.

Ethical testing: VAPT basics

A bank hires a locksmith to try its own doors, in writing, at an agreed time, then report what he found. That is ethical testing.

Vulnerability assessment finds and lists weaknesses, usually with scanners. Penetration testing goes a step further and shows whether a weakness can really be used, in a controlled way. Both are done only with written permission, a defined scope and rules about what is allowed. Testers follow steps: plan, scan, test, report and retest. The report ranks findings by risk and gives clear fixes. Testing without permission is illegal in India under the IT Act 2000, so beginners practise only in legal labs and bug bounty programs inside their stated scope.

Interview tip: Start with legal practice: home labs, TryHackMe, Hack The Box and OWASP Juice Shop. Say clearly that you work only with permission.

Risk, compliance and privacy

Rules of the road keep traffic safe. Compliance rules do the same for how a company protects data and proves it.

Governance, risk and compliance (GRC) work keeps security organised. A risk assessment lists assets, threats and controls and ranks risks. Policies state the rules; procedures show how; audits check that people follow them. Common frameworks include ISO 27001 for security management, SOC 2 for service providers and PCI DSS for card data. India's Digital Personal Data Protection Act covers how personal data may be collected and used. Teams check current rules, keep evidence and fix gaps found in audits.

Interview tip: Say you would check the latest rules for the company's industry, because laws and standards change.

Interview questions and sample answers

What is the difference between a threat, a vulnerability and a risk?

A threat can cause harm, a vulnerability is a weakness it can use, and risk is the chance and impact of that happening.

What is the CIA triad?

Confidentiality, integrity and availability: private, correct and available data.

How would you handle a phishing email report?

Do not click, collect headers and links, block sender and link, check who clicked, reset affected passwords and warn staff.

Explain the difference between IDS and IPS.

An IDS detects and alerts. An IPS sits inline and can block the traffic.

What is multi-factor authentication and why does it help?

It needs two or more proofs, so a stolen password alone cannot log in.

What is the difference between symmetric and asymmetric encryption?

Symmetric uses one shared key and is fast. Asymmetric uses a public and private key pair.

What happens in a TLS handshake in simple words?

The client and server agree on settings, the server shows a certificate, they create a shared key and then encrypt traffic.

How do you triage a SIEM alert?

Confirm it is real, check scope and severity, contain if needed, escalate with evidence and document.

What is a false positive and how do you reduce them?

An alert for harmless activity. Tune rules, add context and whitelist known good behaviour carefully.

What is least privilege?

Giving only the access needed for the job, and no more.

What is SQL injection and how do you prevent it?

Untrusted input changes a database query. Use parameterised queries and validation.

What is XSS?

Harmful script runs in another user's browser. Encode output and use a content security policy.

What is the OWASP Top 10?

A list of the most common web application risks, used as a checklist for developers and testers.

What are the phases of incident response?

Preparation, detection, containment, eradication, recovery and lessons learned.

What is hashing and why salt passwords?

Hashing is a one-way fingerprint. A salt makes identical passwords hash differently.

What is a firewall and how does it work?

It allows or blocks traffic using rules on address, port and direction.

What is the difference between a vulnerability scan and a penetration test?

A scan lists likely weaknesses. A penetration test tries to use them safely, with permission.

What is a VPN?

An encrypted tunnel across a public network that protects data and hides the route.

How do you secure a home Wi-Fi network?

Change default admin password, use WPA2 or WPA3, a strong passphrase, update firmware and disable WPS.

What would you do if you found a vulnerability in a company's website without permission?

Do not exploit it. Report it through their disclosure or bug bounty page or security email with clear details.

What is a zero-day vulnerability?

A flaw the vendor does not know about or has not yet fixed.

How do you keep logs useful for investigations?

Collect from key systems, keep accurate time, protect from tampering and keep them long enough.

What is a DDoS attack and how is it reduced?

Traffic floods a service. Use CDN, rate limits, filtering and scaling.

What is data encryption at rest versus in transit?

At rest protects stored data. In transit protects data moving over a network.

What does a SOC analyst do on a typical day?

Monitors alerts, triages them, investigates, escalates incidents, writes notes and tunes rules.

Senior and lead interview questions

How do you build a security programme from scratch?

Assess assets and risks, set policies, add basic controls, monitoring and training, and report progress to leadership.

How do you prioritise hundreds of vulnerabilities?

Rank by exploitability, asset value and exposure, fix critical first and track SLAs.

How do you lead incident response for a major breach?

Declare and contain, assign roles, preserve evidence, communicate legally and clearly and run a review.

How do you explain risk to the board?

Use business impact in plain words, a few key risks, trends and a clear ask for decisions.

How do you prepare for ISO 27001 or a compliance audit?

Define scope, assess gaps, fix controls, collect evidence and run an internal audit.

How do you build security awareness across a company?

Short, regular training, phishing drills, easy reporting and positive recognition.

How do you balance security with developer speed?

Automate checks in pipelines, give secure defaults and involve security early.

Padimachi is free. Content is general learning material, not a promise of a job. Privacy