Interview practice

SOC analyst interview questions and answers

The questions entry-level SOC candidates are most often asked — with sample answers that show how to think, not just what to say.

Updated October 2026 · 25 questions with sample answers

SOC analyst interviews usually mix fundamentals, tool knowledge and scenario questions. Interviewers are not only checking whether you know definitions — they want to hear how you think through an investigation. Use these sample answers as a guide, then put them in your own words with examples from your own practice.

General and fundamentals

1. Tell me about yourself and why you want to work in a SOC.

Keep it to about a minute: your background, how you got into security, what you have done to build practical skills, and why monitoring and investigation appeal to you. Mention specific practice — for example, investigations you have completed or a home lab — rather than only courses.

2. What is the CIA triad?

Confidentiality (only authorized people can access data), integrity (data is accurate and not tampered with) and availability (systems and data are accessible when needed). Give an example of an attack against each, such as data theft, record tampering and ransomware or DDoS.

3. What is the difference between a vulnerability, a threat and a risk?

A vulnerability is a weakness. A threat is something that could exploit it. Risk is the likelihood and impact of that happening. An unpatched server is a vulnerability; a ransomware group is a threat; the chance and cost of them exploiting it is the risk.

4. What is the difference between an event, an alert and an incident?

An event is any logged activity. An alert is an event (or pattern of events) that a rule flagged as suspicious. An incident is a confirmed or likely security breach that needs a response. Most events never become alerts, and most alerts never become incidents.

5. Explain false positives and false negatives.

A false positive is an alert on harmless activity. A false negative is malicious activity that was not detected. False positives waste analyst time and cause alert fatigue; false negatives are more dangerous because nobody investigates them.

Networking

6. What happens when you type a URL into a browser?

DNS resolves the domain to an IP address, the browser opens a TCP connection (and a TLS handshake for HTTPS), sends an HTTP request and renders the response. Interviewers want to see that you understand DNS, TCP and TLS in sequence.

7. What is the difference between TCP and UDP?

TCP is connection-oriented, with a three-way handshake, ordering and retransmission. UDP is connectionless and faster but unreliable. Web traffic typically uses TCP; DNS queries and streaming often use UDP.

8. Name some common ports and what they are used for.

22 SSH, 25 SMTP, 53 DNS, 80 HTTP, 443 HTTPS, 445 SMB, 3389 RDP. Explain why some matter to a SOC — for example, RDP or SMB exposed to the internet is a common attack path. See our ports cheat sheet.

9. What is the difference between a firewall, an IDS and an IPS?

A firewall allows or blocks traffic based on rules. An IDS monitors traffic and alerts on suspicious patterns. An IPS can also block that traffic in line.

10. Why would you see lots of DNS queries to random-looking domains?

It can indicate malware using domain generation algorithms (DGAs) to find its command-and-control server, or DNS tunneling. Check which host is making the requests, the process responsible and the reputation of the domains.

SOC tools and logs

11. What is a SIEM and how do you use it?

A SIEM collects and correlates logs from across the organization. Analysts use it to search events, build timelines and investigate alerts. Mention any query language you have practiced, such as KQL or SPL.

12. What is EDR and how is it different from antivirus?

Traditional antivirus mainly blocks known malicious files. EDR continuously records endpoint activity — processes, command lines, network connections — so analysts can investigate behavior and isolate devices.

13. Which Windows event IDs do you know?

4624 successful logon, 4625 failed logon, 4672 special privileges assigned, 4688 process creation, 4720 user account created, 4740 account locked out, 1102 audit log cleared. Explain why 1102 is suspicious: attackers clear logs to hide their tracks.

14. How would you find a brute-force attack in logs?

Look for many failed logons (for example event 4625 or failed sign-ins in identity logs) against one account or many accounts from the same source in a short time — and, critically, check whether a successful logon followed.

15. What is MITRE ATT&CK and why is it useful?

A public framework of attacker tactics and techniques. SOC teams use it to describe what an attacker did, map detections to techniques and spot gaps in coverage.

Scenario questions

16. A user reports a suspicious email. What do you do?

Check the headers (sender, return-path, SPF/DKIM/DMARC results), inspect links and attachments safely, check whether other users received it, and find out whether anyone clicked or entered credentials. Then remove the email, block indicators and reset credentials if needed. Our phishing analysis guide walks through it.

17. You see a successful sign-in from another country right after several failed attempts. How do you investigate?

Confirm the timeline, check the source IP reputation and whether it is a VPN or hosting provider, compare with the user’s normal locations and devices, review MFA results and look at what the session did after sign-in. If it looks malicious, revoke sessions, reset the password and escalate. See how to investigate a suspicious login.

18. EDR alerts on PowerShell with an encoded command. What next?

Decode the command (for example with CyberChef), check the parent process and user, review network connections and files written, and look for the same command on other hosts. Encoded PowerShell launched from Office or a browser is highly suspicious.

19. How do you decide the severity of an incident?

Consider the asset and data involved, how many users or systems are affected, whether the attacker achieved access or execution, and whether the activity is ongoing. Follow your organization’s severity matrix and explain your reasoning.

20. When would you escalate an alert?

When there is confirmed compromise, when the scope is larger than you can handle, when actions need higher authority (such as isolating a critical server), or when you are unsure and the potential impact is high. Escalating with good notes is a strength, not a weakness.

21. How do you handle a large queue of alerts?

Prioritize by severity and asset criticality, group related alerts, close clear false positives with documented reasoning, and raise recurring noisy rules for tuning.

Behavioural

22. Describe a time you made a mistake and how you handled it.

Choose a real, low-stakes example. Explain what happened, how you noticed, how you fixed it and what you changed afterwards. SOC managers value honesty and learning.

23. How do you keep up with security news?

Name specific sources you actually use — vendor threat reports, security news sites, podcasts or communities — and give an example of something you learned recently.

24. How would you explain a security incident to a non-technical manager?

Lead with impact and status: what happened, what is affected, what has been done and what is needed from them. Avoid jargon and give a clear next update time.

25. Why should we hire you without SOC experience?

Point to evidence: foundations you have built, certifications, and practical investigations you can describe in detail. Then show enthusiasm for learning and working shifts as part of a team.

Interview tips

  • Think out loud. For scenario questions, explain each step and why you are taking it.
  • Say “I would check…” rather than guessing. Investigation is about evidence.
  • Bring examples. Specific investigations you have practiced are more convincing than definitions.
  • Ask good questions. For example: what does a typical shift look like, which tools does the team use, and how are new analysts trained?

Want more practice? Work through realistic scenarios in the SOC Analyst simulator so you have real investigations to talk about.

Have real stories to tell

Practice the scenarios interviewers ask about.

Investigate realistic phishing, login and endpoint incidents so you can answer from experience.

Start free. No experience required.