Threat Hunting and Threat Intelligence Questions

Proactively pursuing adversaries and operationalizing knowledge of them. Covers threat hunting and hypothesis-driven investigation, threat intelligence collection and integration, indicators of compromise, the MITRE ATT&CK framework, advanced persistent threats, and situating activity within the current threat landscape. The 'go find what the alerts missed, informed by adversary knowledge' discipline.

EasyTechnical
23 practiced

Compare Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF): describe how each attack works, where they commonly appear in an application stack, and list three practical defenses for each that you would require in code review and enforce via the secure development lifecycle.

EasyTechnical
18 practiced

Define supply chain attacks in a software context and enumerate the stages an adversary typically uses (compromise vendor, introduce malicious code, sign/publish malicious artifact, distribute via updates). As a cybersecurity engineer, present a supplier risk-management checklist that includes vendor vetting, SBOM consumption, artifact signing, CI/CD controls, and runtime protections you would implement.

MediumTechnical
24 practiced

A production API log shows exceptions during object deserialization and you observe unusual outbound commands executed by auxiliary systems. Explain how insecure deserialization vulnerabilities operate, what specific log indicators you would search for to confirm exploitation, and describe the code changes and patching steps you would perform to remediate and prevent insecure deserialization.

MediumTechnical
25 practiced

Write a Python script or provide clear pseudocode that parses web server access logs and identifies IP addresses exhibiting suspicious failed-login behavior defined as more than 50 failed login attempts in a 10-minute sliding window across more than 20 distinct usernames. Explain your threshold choices and describe tuning approaches to reduce false positives.

MediumTechnical
23 practiced

Design rate-limiting and API gateway controls to protect public APIs from abuse, scraping, and slow DDoS attacks. Discuss token-bucket vs leaky-bucket implementations, per-user versus global limits, burst handling, client feedback via headers, and the metrics you would monitor to tune the system effectively.

Unlock Full Question Bank

Get access to all 37 Threat Hunting and Threat Intelligence interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.