Security Monitoring, SIEM, and Detection Engineering Questions

Building and operating the detection stack: the SOC and detection-engineering practice that answers 'can we see an attack happening.' Covers SIEM platform selection and architecture, use-case and detection-rule query development (for example Splunk SPL, KQL, or Sigma), alert triage and tuning to reduce false positives, detection engineering and closing coverage gaps, mapping detections to the MITRE ATT&CK framework and scoring detection coverage, log analysis and anomaly and baseline development, network and endpoint telemetry sourcing, malware and compromise-indicator recognition, and security operations center (SOC) alert escalation workflows. Distinct from the reactive work of containing, remediating, and communicating during a confirmed incident (incident response and postmortem topics own that ground; this topic stops at 'the alert fired and here is the detection logic', not 'here is how we contained and recovered from it'). Distinct from generic system-reliability monitoring and observability (SLOs, error budgets, uptime dashboards), a separate discipline even when the underlying ingestion mechanics look similar; the anomaly or signal here must be framed as adversarial or security-relevant. Distinct from hardening a software delivery pipeline against supply-chain compromise (SBOM generation, artifact signing, dependency and build-permission controls); this topic only touches the delivery pipeline from the detection side, spotting a compromised build or tainted artifact via telemetry, not the preventive-controls side. Distinct from designing security control architecture and governance (security architecture and cloud security architecture topics own the design-time question of what controls should exist); this topic is the run-time operation of the detection stack once those controls are in place.

EasyTechnical
73 practiced

Explain the differences between HIDS (Host-based Intrusion Detection System) and NIDS (Network-based Intrusion Detection System). For each, describe the primary telemetry they consume, their deployment location, strengths and weaknesses, and example detections each is best suited for in a SOC environment.

EasyTechnical
65 practiced

Define false positives and false negatives in the context of detection rules. Provide two realistic examples of each from SIEM/EDR monitoring and discuss the operational impact (analyst time, missed breaches, alert fatigue) of both error types.

MediumTechnical
72 practiced

Write a Sigma rule (YAML-style) that detects suspicious usage of certutil or powershell when invoked with command-line patterns indicating encoding or decoding of content (for example '-EncodedCommand' or 'certutil -decode'). Target Windows ProcessCreate events and include reasonable fields (process_name, command_line, parent_process). Keep the rule generic and explain rationale for key fields.

MediumSystem Design
68 practiced

System design (medium): Design a detection coverage matrix that maps existing detections to MITRE ATT&CK techniques for a mid-size organization. Explain how you would populate the matrix, calculate a coverage score per tactic/technique, prioritize gaps for remediation, and what dashboards or KPIs you'd provide to leadership to show progress over time.

EasyTechnical
79 practiced

Given a relational table login_attempts(user_id TEXT, timestamp TIMESTAMP, status TEXT, source_ip TEXT), write a standard SQL query that returns user_id and source_ip pairs which had 5 or more failed login attempts within any five-minute window. State assumptions about timestamp precision and indexing.

Unlock Full Question Bank

Get access to all Security Monitoring, SIEM, and Detection Engineering interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.