CyberIncidents Logo
Guides & Learning

SOC Analyst Interview

Part 1

CyberIncidents TeamOctober 4, 202610 min read
SOC Analyst Interview

1. What is a SOC?

Answer:
A SOC, or Security Operations Center, is a team responsible for continuously monitoring, detecting, investigating, and responding to security threats within an organization's environment. It uses tools such as SIEM, EDR, SOAR, firewalls, and threat-intelligence platforms.

2. What are the responsibilities of an L1 SOC Analyst?

Answer:
An L1 analyst primarily performs alert monitoring and initial triage. My responsibilities would include:

  1. Monitoring security alerts.
  2. Validating whether an alert is a true or false positive.
  3. Collecting relevant evidence.
  4. Checking IPs, domains, hashes, users, and endpoints.
  5. Performing initial investigation.
  6. Documenting findings.
  7. Escalating confirmed or suspicious incidents to L2 according to the SOP and SLA.

3. What is the difference between an alert and an incident?

Answer:
An alert is a notification generated by a security tool indicating potentially suspicious activity.

An incident is a confirmed or suspected security event that requires investigation or response.

For example, one failed login may generate an alert, but repeated failed logins followed by a successful login from a suspicious IP could become a security incident.

4. What is SIEM?

Answer:
SIEM stands for Security Information and Event Management. It collects and correlates logs from different sources such as endpoints, servers, firewalls, applications, cloud platforms, and identity providers to detect suspicious activity.

Examples include Splunk and Microsoft Sentinel.

5. How does a SIEM work?

Answer:
The basic workflow is:

Log Collection → Parsing/Normalization → Correlation → Detection Rule → Alert → Investigation → Response

For example, a SIEM can correlate multiple failed logins with a successful login and generate a suspicious authentication alert.

6. What is a false positive?

Answer:
A false positive occurs when a security tool generates an alert for activity that appears malicious but is actually legitimate.

For example, a legitimate administrator performing multiple failed authentication attempts because of an expired password could trigger a brute-force alert.

7. What is a true positive?

Answer:
A true positive is a security alert that correctly identifies malicious or unauthorized activity.

For example, detecting PowerShell downloading a known malicious payload from a suspicious domain would likely be a true positive.

8. What is an IOC?

Answer:
IOC stands for Indicator of Compromise. It is evidence that may indicate malicious activity.

Examples include:

  • Malicious IP address
  • Domain
  • File hash
  • Malicious URL
  • Suspicious file
  • Malware filename

9. What is an IOA?

Answer:
IOA stands for Indicator of Attack. It focuses on suspicious behavior or attack techniques rather than just known malicious indicators.

For example, PowerShell downloading and executing a payload from the internet can be an IOA.

10. What is MITRE ATT&CK?

Answer:
MITRE ATT&CK is a knowledge base that documents real-world adversary tactics and techniques.

For example:

  • T1059.001 – PowerShell
  • T1053 – Scheduled Task/Job
  • T1078 – Valid Accounts

It helps analysts understand attacker behavior and map detections to attack techniques.

SIEM & Investigation Questions

11. How would you investigate a suspicious login alert?

Answer:

I would follow this process:

  1. Identify the user and source IP.
  2. Check the login timestamp.
  3. Check the geolocation.
  4. Check whether the IP is associated with VPN, proxy, or TOR.
  5. Check the device and user agent.
  6. Review MFA activity.
  7. Search for previous activity from the same IP.
  8. Check whether other users were targeted.
  9. Review activity after the successful login.
  10. Determine whether it is TP or FP and escalate if required.

12. You see multiple failed logins followed by a successful login. What would you do?

Answer:
I would investigate whether this represents a possible brute-force or password-spraying attack.

I would check:

  • Username
  • Source IP
  • Number of failures
  • Time interval
  • Successful authentication
  • Geo-location
  • User agent/device
  • MFA events
  • Other accounts targeted by the same IP
  • Post-login activity

If the successful login is suspicious, I would escalate it as a potential account compromise.

13. What is brute-force attack?

Answer:
A brute-force attack involves repeatedly attempting different passwords against an account until the correct password is discovered.

14. What is password spraying?

Answer:
Password spraying is when an attacker tries one or a few commonly used passwords against many accounts, rather than trying many passwords against one account.

Brute force: Many passwords → one account.
Password spraying: One/few passwords → many accounts.

15. How do you determine whether an alert is a false positive?

Answer:
I compare the alert with the available context.

I check:

  • User
  • Asset
  • Source/destination IP
  • Process
  • Command line
  • Time
  • Historical behavior
  • Threat intelligence
  • Business justification
  • Related events

If the activity is legitimate and supported by evidence, I classify it as a false positive. If the evidence indicates malicious or unauthorized behavior, I treat it as a true positive.

Networking Questions

16. What is TCP?

Answer:
TCP is a connection-oriented protocol that provides reliable and ordered delivery of data.

17. What is UDP?

Answer:
UDP is a connectionless protocol. It is faster than TCP but does not guarantee delivery or ordering.

18. What is the TCP three-way handshake?

Answer:

SYN → SYN-ACK → ACK

The client sends SYN, the server responds with SYN-ACK, and the client sends ACK to establish the TCP connection.

19. What is DNS?

Answer:
DNS, or Domain Name System, translates domain names into IP addresses.

For example:

example.com → IP address

Attackers can abuse DNS for techniques such as DNS tunneling and malicious domain communication.

20. What is a firewall?

Answer:
A firewall controls network traffic based on predefined rules. It can allow or block traffic based on parameters such as IP address, port, protocol, and application.

21. What is a C2 connection?

Answer:
C2 stands for Command and Control. It is communication between a compromised system and an attacker-controlled infrastructure.

An infected endpoint may communicate with a C2 server to receive commands or send stolen information.

Windows Security Questions

22. What is Windows Event ID 4624?

Answer:
Event ID 4624 indicates a successful logon.

During investigation, I would examine the account, source IP, logon type, timestamp, workstation and authentication details.

23. What is Event ID 4625?

Answer:
Event ID 4625 indicates a failed logon attempt.

Multiple 4625 events can indicate brute-force, password spraying, misconfiguration, or legitimate authentication problems.

24. What is Event ID 4672?

Answer:
Event ID 4672 indicates that special privileges were assigned to a new logon.

It can be legitimate for administrative accounts but should be investigated if associated with an unexpected or compromised account.

25. What is Event ID 4720?

Answer:
Event ID 4720 indicates that a user account was created.

I would verify who created the account, which account was created, when it happened, and whether the activity was authorized.

26. What is Event ID 4768?

Answer:
Event ID 4768 represents a Kerberos authentication ticket-granting ticket (TGT) request.

It can be useful when investigating authentication-related attacks such as suspicious Kerberos activity.

27. What is Event ID 4769?

Answer:
Event ID 4769 represents a Kerberos service ticket request.

It is particularly useful when investigating suspicious Kerberos activity, including potential Kerberoasting.

28. What does Windows Security Log Cleared mean?

Answer:
Event ID 1102 indicates that the Windows Security audit log was cleared.

This can be legitimate administrative activity, but attackers may clear logs to remove evidence of their activity, so I would investigate who performed the action and what happened before and after it.

Malware & EDR

29. What is EDR?

Answer:
EDR stands for Endpoint Detection and Response. It continuously monitors endpoint activity such as processes, files, network connections, command lines, and user activity to detect and respond to threats.

Examples include CrowdStrike Falcon, Microsoft Defender, and SentinelOne.

30. How would you investigate a malware alert?

Answer:

I would:

  1. Identify the affected endpoint.
  2. Identify the user.
  3. Check the detected file.
  4. Obtain the file hash.
  5. Check hash reputation.
  6. Investigate the process tree.
  7. Review command-line arguments.
  8. Check network connections.
  9. Look for persistence mechanisms.
  10. Search for the same IOC across the environment.
  11. Contain the endpoint if required.
  12. Escalate and document the incident.

31. PowerShell is downloading a file from an external IP. What would you do?

Answer:
I would consider it suspicious and investigate the parent process, command line, destination IP/domain, downloaded file, hash, user, endpoint, and subsequent execution.

I would also check whether the activity maps to MITRE ATT&CK T1059.001 – PowerShell and search for related activity across the environment.

32. What is process parent-child relationship?

Answer:
It shows which process launched another process.

For example:

WINWORD.EXE → PowerShell → cmd.exe

This can be suspicious because Office applications normally should not spawn command interpreters in many business scenarios.

Phishing

33. How would you investigate a phishing email?

Answer:

I would check:

  • Sender address
  • Reply-to address
  • Subject
  • URLs
  • Attachments
  • Email headers
  • SPF/DKIM/DMARC
  • Domain reputation
  • URL reputation
  • Attachment hash
  • Whether other users received the same email
  • Whether the recipient clicked the link

If malicious, I would recommend containment actions according to the organization's procedure and escalate the incident.

34. A user clicked a malicious link. What would you do?

Answer:

I would:

Identify URL → Check reputation → Determine whether it was accessed → Check endpoint → Review browser/process activity → Check for downloads/execution → Search for related IOCs → Contain if necessary → Escalate → Document.

Incident Response

35. What is incident response?

Answer:
Incident response is the structured process of identifying, investigating, containing, eradicating, and recovering from security incidents.

A common lifecycle is:

Preparation → Detection & Analysis → Containment → Eradication → Recovery → Lessons Learned

36. When would you escalate an alert to L2?

Answer:
I would escalate when:

  • There is evidence of compromise.
  • The alert requires deeper investigation.
  • The incident involves a critical asset.
  • Privileged accounts are involved.
  • Malware execution is confirmed.
  • L1 lacks the required permissions or expertise.
  • The incident exceeds the L1 investigation scope.
  • Immediate containment or advanced threat hunting is required.

37. How do you prioritize multiple alerts?

Answer:
I prioritize based on:

Severity + Asset Criticality + Confidence + User Privilege + Business Impact + Evidence of Active Compromise.

For example, a confirmed malware infection on a domain controller would receive higher priority than a low-confidence informational alert on a normal workstation.

38. What information should an incident ticket contain?

Answer:

I would include:

  • Alert name
  • Date/time
  • Affected user
  • Hostname
  • Source/destination IP
  • IOC details
  • Investigation performed
  • Relevant logs
  • Evidence
  • TP/FP determination
  • MITRE ATT&CK mapping where applicable
  • Actions taken
  • Escalation details
  • Recommended next steps

Scenario-Based Questions

39. An employee says, "I did not perform this login." What would you do?

Answer:
I would treat it as a potential account compromise.

I would verify the authentication logs, source IP, location, device, user agent, MFA events, and activity following the login. I would also check whether the credentials were used elsewhere.

If the evidence supports compromise, I would follow the organization's containment process, such as session revocation or credential reset, and escalate according to the incident-response procedure.

40. You receive an alert for a suspicious scheduled task. What would you investigate?

Answer:
I would investigate:

  • Task name
  • Task creation time
  • User who created it
  • Executable/script path
  • Command line
  • Parent process
  • File hash
  • Persistence mechanism
  • Network connections
  • Whether the task executes from suspicious locations such as %TEMP%

I would also map it to MITRE ATT&CK T1053 – Scheduled Task/Job where applicable.

41. An endpoint suddenly starts communicating with a known malicious IP. What do you do?

Answer:

I would:

  1. Identify the endpoint and user.
  2. Determine which process initiated the connection.
  3. Check the destination IP reputation.
  4. Review DNS and network logs.
  5. Check the process tree.
  6. Investigate downloaded/executed files.
  7. Search for the IOC across the environment.
  8. Determine whether the endpoint is compromised.
  9. Isolate the endpoint if required.
  10. Escalate and document.

Filed under Guides & Learning