Cyber Security Interview Questions
- what are the log sources you integrated with siem tool
- what is dos, ddos
- difference b/n dos & ddos
- if you dont have rule condition how you will identify ddos attack
- what is tcp & udp and difference
- explain bruteforce attack and how you will investigate
- ssh telnet and dns port numbers
- what is the use of arp
- Port scanning investigation
- Malware investigation
- DDOS INVESTIGATION
- SQL injection
- Suspicious outbound connection happened wt will you see for mitigation
- Owasp top 10
- What is threat management
- In mitre attack on persistence technique tell me any two subtechniques
- Sentinel architecture
- How vulnerability will come in edr?
- Bruteforce investigation
- Evenid 4791,4624,4625,4688
- Port number RDP,LDAP,telnet,ssh,amb
- ell me about the investigation in DLP?
- 2. On what basis DLP tool creates a alert?
- 3. How are u gonna report about forensics in DLP?
- 4. Difference between EDR and AV?
- 5. Explain any two alerts investigation in SIEM?
- 6. Why do u use comm. prompt during malware investigation?
- 7. Why do u report malicious domain to proxy? Why not to Firewall?
- 8. Explain about Phishing email analysis?
- 9. Any idea about "scheduled task" in Windows OS?
- 1) explain any investigation particulaerly investigated in EDR
- 2) Explain query to search windows sign in logs
- 3) how you coloborate end points to EDR what is the process
- 4) difernce between EDR and antivirus
- 5) what are the poliecies you know in EDR
- 6) Event ID for account lockout
Comments