InterviewStack.io LogoInterviewStack.io

Threat Hunting and Threat Intelligence Questions

Proactively pursuing adversaries and operationalizing knowledge of them. Covers threat hunting and hypothesis-driven investigation, threat intelligence collection and integration, indicators of compromise, the MITRE ATT&CK framework, advanced persistent threats, and situating activity within the current threat landscape. The 'go find what the alerts missed, informed by adversary knowledge' discipline.

MediumTechnical
19 practiced

You observe many clients resolving an unusual domain and subsequently making web requests to a small set of IPs that appear in a threat-intel feed. Describe step-by-step how you would correlate DNS logs, proxy logs, and endpoint telemetry to determine scope, pivot to affected hosts, and decide on escalation. Include what timestamps, fields, and joins you would perform.

MediumTechnical
22 practiced

Write a Splunk or KQL query to detect potential lateral movement via SMB by correlating successful authentication events followed by suspicious outbound SMB connections within 10 minutes. Describe which fields you expect from Windows event logs and which event codes or schema you used.

EasyTechnical
22 practiced

Compare automated threat hunting (e.g., scheduled rules, SIEM correlation, ML alerts) versus manual interactive hunting. For each approach explain strengths, weaknesses, and scenarios when one is preferred over the other in a production SOC.

EasyTechnical
18 practiced

List and justify the minimum set of telemetry sources you would require to enable effective threat hunting across endpoints, network, and cloud. Explain why each source is important and a common limitation to be aware of for that source.

MediumTechnical
34 practiced

Explain common challenges when normalizing logs from heterogeneous sources (on-prem Windows, cloud services, Linux, network devices). For each challenge propose concrete solutions or architectural changes, and describe how you would validate that normalization enables accurate cross-source hunting.

Unlock Full Question Bank

Get access to hundreds of Threat Hunting and Threat Intelligence interview questions and detailed answers.

Sign in to Continue

Join thousands of developers preparing for their dream job.