1. You are a L2 SOC Analyst, you receive an alert that a user logs in/successfully authenticated from Greece but normally log ins from Texas, how would you investigate this. a. I asked: what type of logs do I have access to? Office 365 b. Am I the first person to investigate or has it been elevated to me? First person c. After investigating the logs, has there been signs multiple login attempts? User1. User01, user_1? No, it was a legit login d. No, but what are those called, what type of attack? Brute force—credential surfing e. How did the user authenticate? RSA f. Is this the first time the user logged in from a different location? Yes g. VPN used? No h. The scenario ended with me with saying “I am stuck and unsure what to do next, I would gather my notes and send it to a teammate for guidance/assistance” 2. You are a L2 SOC Analyst, you received an email from a third party vendor. The vendor software was just installed and it is in detention mode. Why did the email land in your inbox? How would you investigate? a. First, I would look at the details of the email details message id, date time, from, to, spf, dkim, dmarc for further analysis. –All the email details are legit b. Next, I would investigate the IP address to see if it is legit. The IP is legit. c. Does the emails have any attachments? No d. Phone numbers or misspellings? No e. The scenario ended with me with saying “I am stuck and unsure what to do next, I would gather my notes and send it to a teammate for guidance/assistance”
Securities Operations Specialist Interview Questions
387 securities operations specialist interview questions shared by candidates
Why did you choose the university that you attended? Asking about all the critical issues that I had to face in my experiences and about my achievements.
Can you have a difficult conversation with an analyst, how would you approach this.
Some security specific questions like describe XSS in 1st round
Pourquoi avez vous opté pour ce poste
DNS, DNS, DNS ....
Why are you interested in this position?
How do you meet deadlines, examples of projects you have worked on and how do you manage them, how do you prioritize tasks, how do you work under pressure, questions regarding project management in general.
They left me waiting for an interview for weeks.
How do you setup a WAF? What kind of configuration for blocking do you setup on a WAF? What is your experience with FedRAMP? Describe your process in setting up security controls and how this applies to the wider organization.
Viewing 351 - 360 interview questions