Cyber Security: interview questions and learning guide
Security basics, monitoring, ethical testing and incident response
Practise Cyber Security on Padimachi
What you will learn
Security fundamentals: CIA and risk
A house has a lock, a guard and an alarm. Security is the same idea for data: several small protections so one failure does not open everything.
Information security protects data and systems by keeping three goals: confidentiality (only the right people see it), integrity (it is not changed wrongly) and availability (it works when needed). A threat is something that can cause harm, a vulnerability is a weakness it can use, and risk is how likely and how costly that harm is. Good security layers many controls, gives people the least access they need, and assumes some defences will fail.
Interview tip: In an interview, link every control you mention to one of the three goals and to a risk it reduces.
Networking for security
Data travels like parcels through a postal system. To spot a suspicious parcel you first need to know how normal delivery works.
Security work starts with networking. Devices have IP addresses, use DNS to turn names into addresses, and talk through ports such as 80 and 443 for web traffic. A firewall allows or blocks traffic by rules. A VPN creates an encrypted tunnel across a public network. Network segmentation splits a network into zones so a problem in one zone cannot spread freely. Analysts read traffic logs to tell normal behaviour from scans and unusual connections.
Interview tip: Be ready to explain what happens when you open a website, step by step, including DNS and the secure connection.
Common threats and attacks
Most break-ins use the front door: a tricked person, a weak password or an old unpatched system, not movie-style hacking.
Attackers usually take the easiest path. Social engineering tricks people through fake emails, calls or messages. Malware is harmful software, including ransomware that locks files for money. Password attacks guess or reuse stolen passwords. Denial of service floods a service so real users cannot reach it. Insiders can misuse access by mistake or on purpose. Defenders reduce these risks with awareness training, multi-factor login, updates, backups and monitoring.
Interview tip: Describe an attack and then its defences. Interviewers want to hear how you would stop it, not how to run it.
Security operations and monitoring
A control room watches many screens. Most alerts are noise; the skill is spotting the few that matter and acting fast.
A security operations centre (SOC) watches logs and alerts from firewalls, servers, email and laptops. A SIEM tool collects and searches these logs and raises alerts by rules. An analyst triages each alert: is it real, how serious, who is affected? False positives are alerts that look bad but are harmless. Real incidents are escalated with clear notes. Endpoint tools (EDR) watch laptops and servers and can isolate a machine. Good analysts write precise tickets and follow runbooks.
Interview tip: Practise a triage answer: confirm, scope, contain, escalate, document. Bring one example of reading logs.
Identity, access and passwords
A building gives each person a card that opens only certain doors. Identity security is the same card system for digital doors.
Authentication proves who you are and authorization decides what you may do. Multi-factor authentication adds a second proof such as a code or app approval, which blocks most stolen-password attacks. Single sign-on lets one secure login open many apps. Role-based access gives permissions to roles instead of individuals. Privileged accounts, such as administrators, need extra care: separate accounts, approval, and logs. When someone leaves or changes role, access must be removed quickly.
Interview tip: Mention least privilege, MFA and regular access reviews in any identity answer.
Encryption and certificates
A sealed envelope hides a letter in transit. A signature on it proves who wrote it. Encryption and signatures do these two jobs for data.
Encryption scrambles data so only someone with the right key can read it. Symmetric encryption uses one shared key and is fast. Asymmetric encryption uses a public key to lock and a private key to unlock. Hashing turns data into a fixed fingerprint that cannot be reversed and is used to store passwords and check files. A digital certificate ties a public key to a website identity, and TLS uses it to protect the connection you see as HTTPS. Keys must be kept safe, because losing the key means losing the protection.
Interview tip: Know the difference between encryption (reversible with a key) and hashing (one way).
Web application security basics
A shop counter must check every note and every request. If it trusts everything a customer hands over, someone will eventually hand over trouble.
Web applications are attacked through the data they accept. The OWASP Top 10 lists the most common weaknesses, such as broken access control, injection and misconfiguration. Injection happens when user input is mixed into a database query or command. Cross-site scripting runs harmful script in another user's browser. Developers stop these with parameterised queries, input validation, output encoding, safe session handling and checking permissions on every request. Testers look for these weaknesses only on systems they have written permission to test.
Interview tip: Always connect a weakness to its fix. Say you test only with permission and inside the agreed scope.
Incident response and recovery
A fire drill is practised before the fire. A good response plan means people calm down and follow steps when the alarm is real.
Incident response is the plan for handling a security event. The usual phases are preparation, detection, containment, eradication, recovery and lessons learned. Containment limits the damage, for example by isolating a laptop. Eradication removes the cause. Recovery restores systems from clean backups. Evidence is kept carefully, and clear notes are taken with times. In India, serious incidents may need to be reported to CERT-In within the time limit set by current rules, so teams check the latest rules.
Interview tip: Give a calm sequence: detect, contain, eradicate, recover, learn. Mention communication to staff and management.
Ethical testing: VAPT basics
A bank hires a locksmith to try its own doors, in writing, at an agreed time, then report what he found. That is ethical testing.
Vulnerability assessment finds and lists weaknesses, usually with scanners. Penetration testing goes a step further and shows whether a weakness can really be used, in a controlled way. Both are done only with written permission, a defined scope and rules about what is allowed. Testers follow steps: plan, scan, test, report and retest. The report ranks findings by risk and gives clear fixes. Testing without permission is illegal in India under the IT Act 2000, so beginners practise only in legal labs and bug bounty programs inside their stated scope.
Interview tip: Start with legal practice: home labs, TryHackMe, Hack The Box and OWASP Juice Shop. Say clearly that you work only with permission.
Risk, compliance and privacy
Rules of the road keep traffic safe. Compliance rules do the same for how a company protects data and proves it.
Governance, risk and compliance (GRC) work keeps security organised. A risk assessment lists assets, threats and controls and ranks risks. Policies state the rules; procedures show how; audits check that people follow them. Common frameworks include ISO 27001 for security management, SOC 2 for service providers and PCI DSS for card data. India's Digital Personal Data Protection Act covers how personal data may be collected and used. Teams check current rules, keep evidence and fix gaps found in audits.
Interview tip: Say you would check the latest rules for the company's industry, because laws and standards change.
Interview questions and sample answers
A threat can cause harm, a vulnerability is a weakness it can use, and risk is the chance and impact of that happening.
Confidentiality, integrity and availability: private, correct and available data.
Do not click, collect headers and links, block sender and link, check who clicked, reset affected passwords and warn staff.
An IDS detects and alerts. An IPS sits inline and can block the traffic.
It needs two or more proofs, so a stolen password alone cannot log in.
Symmetric uses one shared key and is fast. Asymmetric uses a public and private key pair.
The client and server agree on settings, the server shows a certificate, they create a shared key and then encrypt traffic.
Confirm it is real, check scope and severity, contain if needed, escalate with evidence and document.
An alert for harmless activity. Tune rules, add context and whitelist known good behaviour carefully.
Giving only the access needed for the job, and no more.
Untrusted input changes a database query. Use parameterised queries and validation.
Harmful script runs in another user's browser. Encode output and use a content security policy.
A list of the most common web application risks, used as a checklist for developers and testers.
Preparation, detection, containment, eradication, recovery and lessons learned.
Hashing is a one-way fingerprint. A salt makes identical passwords hash differently.
It allows or blocks traffic using rules on address, port and direction.
A scan lists likely weaknesses. A penetration test tries to use them safely, with permission.
An encrypted tunnel across a public network that protects data and hides the route.
Change default admin password, use WPA2 or WPA3, a strong passphrase, update firmware and disable WPS.
Do not exploit it. Report it through their disclosure or bug bounty page or security email with clear details.
A flaw the vendor does not know about or has not yet fixed.
Collect from key systems, keep accurate time, protect from tampering and keep them long enough.
Traffic floods a service. Use CDN, rate limits, filtering and scaling.
At rest protects stored data. In transit protects data moving over a network.
Monitors alerts, triages them, investigates, escalates incidents, writes notes and tunes rules.
Senior and lead interview questions
Assess assets and risks, set policies, add basic controls, monitoring and training, and report progress to leadership.
Rank by exploitability, asset value and exposure, fix critical first and track SLAs.
Declare and contain, assign roles, preserve evidence, communicate legally and clearly and run a review.
Use business impact in plain words, a few key risks, trends and a clear ask for decisions.
Define scope, assess gaps, fix controls, collect evidence and run an internal audit.
Short, regular training, phishing drills, easy reporting and positive recognition.
Automate checks in pipelines, give secure defaults and involve security early.
Padimachi is free. Content is general learning material, not a promise of a job. Privacy