Question library
CTI interview questions with expert answers
Every question comes with the key points a strong answer covers, the mistakes that lose candidates points, and a vetted expert answer. Read them, then practise them under questioning.
24 questions matching your filters
- You receive TLP:RED intelligence in a trust group indicating a specific vulnerability is being exploited against your sector. Your organisation is exposed. What do you do? A handling scenario with a deliberate conflict between an obligation and an urgent need to act. Inventing permission is the failure mode.
- Ransomware has been deployed across part of your estate. A known family was used, a ransom note was left, but no data exfiltration has been observed despite C2 being active for six days beforehand. What are your hypotheses, and how would you test them? A case built around one diagnostic anomaly. The scoring is about whether you notice that the missing exfiltration is the interesting part.
- The incident is contained. You have 10 minutes with the board next week. The technical picture is still incomplete and attribution is unresolved. What do you present? A communication scenario at the strategic altitude, with the added constraint that you have to be useful while significant things are still unknown.
- Which classes of attribution evidence are hardest for an adversary to fake, and which are easiest? How does that change how you weight them? A senior attribution question. The expected answer ranks evidence by cost-to-fake and connects that ranking to how confidence should be assigned.
Practise these
Reading an expert answer and producing one under questioning are different skills. The simulator asks these questions, grades your answer against the same rubric you see here, and asks the follow-up an interviewer would ask next.