A collection for interview questions for Information Security roles
Table Of Contents
Application Security
-
If you had to both encrypt and compress data during transmission, which would you do first, and why?
- Compression aims to use patterns in data to reduce its size.
- Encryption aims to randomize data so that it's uninterpretable without a secret key.
- If you encrypt first, then compress, then your compression will be useless. Compression doesn't work on random data.
- If you compress first, then encrypt, then an attacker can find patterns in message length (Compression Ratio) to learn something about the data and potentially foil the encryption (like CRIME)
- Resources:
-
What could attackers do with HTTP Header Injection vulnerability?
- Carriage returns and line feeds (or %0D & %0A) are means to an end that would allow attackers to control HTTP headers
- Attackers could inject XSS via Referer header
- Attackers could set cookie to a value known by the attacker (session fixation)
- Attackers could redirect to a malicious server
-
Describe the last program or script that you wrote. What problem did it solve?
- Just looking for signs that the candidate has basic understanding of programming concepts and is at least able to write simple programs
-
How would you implement a secure login field on a high traffic website where performance is a consideration?
-
What are the various ways to handle brute forcing?
- Account Lockouts/timeouts
- API rate limiting
- IP restrictions
- Fail2ban
- ...etc
-
What is Cross-Site Request Forgery? And how to defend against it?
- When an attacker gets a victim's browser to make requests with the victim's credentials
- Example: if an image tag (``) points to a URL with an associated action, e.g. https://foo.com/logout
- Defense includes but are not limited to:
- check origins header & referer header
- check CSRF tokens or nonce
-
What is Cross-Site Scripting? What are the different types of XSS? How to defend against XSS?
- XSS is when attackers get victim's browsers to execute some code (usually JavaScript) within their browser
- Traditionally, types have been categorized into Stored and Reflected XSS attacks.
- Stored XSS is some code that an attacker was able to persist in a database and gets retrieved and presented to victims (e.g. forum)
- Reflected XSS is usually in the form of a maliciously crafted URL which includes the malicious code. When the user clicks on the link, the code runs in their browser
- Recently there has been discussions around DOM-based XSS, which occurs when attackers can control DOM elements, thus achieve XSS without sending any requests to the server
- XSS categories tend to overlap, therefore it's much better to describe XSS in terms like Server Stored XSS, Server Reflected XSS, Client Stored XSS (e.g. stored DOM-based XSS), or Client Reflected XSS (e.g. reflected DOM-based XSS)
- Defense includes:
- Output encoding (more important)
- Input validation (less important)
-
How does HTTP handle state?
- HTTP is stateless
- State is stored in cookies
Architect
- Have you designed security measures that span overlapping information domains?
- Can you give me a few examples of security architecture requirements?
- What special security challenges does Service-Oriented-Architecture (SOA) present?
- Have you architected a security solution that involved SaaS components? What challenges did you face?
- Have you worked on a project in which stakeholders choose to accept identified security risks that worried you? How did you handle the situation?
- How do you handle demands from different stakeholders who have conflicting requirements?
- How do you ensure that solution architects develop secure solutions?
- How do you ensure that a solution continues to be resilient in the face of evolving threats?
- What do you think the most important technology is right now? How are we going to secure it?
Blue Team
- Given an HTTP traffic log between a machine on your network and a 3rd party website (e.g. Google), what would the source and destination ports look like?
- Source port might be some number above port 1024 (aka ephemeral port)
- Destination port might be 80 (HTTP) or 443 (HTTPS)
Encryption
-
What's the difference between encoding, encryption, and hashing?
- Encoding ensures message integrity. Can be easily reversible. Example: base64
- Encryption guarantees message confidentiality. Reversible only using the appropriate decryption keys. Example: AES256
- Hashing is a one-way function. Cannot be reversed. The output is fixed length and usually smaller than the input.
-
Does TLS use symmetric or asymmetric encryption?
- Both.
- The initial exchange is done using asymmetric encryption, but bulk data encryption is done using symmetric. See next question for additional information.
- Resources:
-
Describe the process of a TLS session being set up when someone visits a secure website.