Build Job-Ready Skills-1,000+ Job Opportunities- Admissions Open for Career Launchpad -Join INCRITO Now
Explore Course
Cyber Security

Top Cybersecurity Questions Beginners Should Know in 2026

MKMonika K 29 Sept 2026 16 min read
Top Cybersecurity Questions Beginners Should Know in 2026

Starting your cybersecurity journey? Explore important cybersecurity questions every beginner should understand, covering threats, networks, ethical hacking, security tools and career fundamentals.

Cybersecurity Interview Questions & Answers

1. Could you share some general endpoint security product names?

    • Antivirus
    • EDR – Endpoint Detection and Response
    • XDR – Extended Detection and Response
    • DLP – Data Loss Prevention

2. What are HIDS and NIDS?

    • HIDS: Host Intrusion Detection System. HIDS is installed on individual hosts/endpoints and monitors activities occurring on that system.
    • NIDS: Network Intrusion Detection System. NIDS monitors network traffic and detects suspicious or malicious network activity.

3. What is the CIA Triad?

The three letters in the CIA Triad stand for:

    • Confidentiality
    • Integrity
    • Availability

The CIA Triad is a common information-security model used as the foundation for designing and evaluating security systems.

Confidentiality

Confidentiality ensures that information is accessible only to authorized individuals.

The objective is to prevent unauthorized people from accessing sensitive information or business assets.

Examples:

    • Encryption
    • Access controls
    • Authentication
    • Permissions

Integrity

Integrity ensures that data is accurate, trustworthy, complete and has not been modified without authorization.

Examples:

    • Hashing
    • Digital signatures
    • File integrity monitoring

Availability

Availability ensures that systems, applications, networks and information are accessible to authorized users whenever required.

Examples:

    • Backups
    • Redundancy
    • Disaster recovery
    • High availability

4. What is AAA?

AAA stands for:

Authentication

Authentication verifies who the user is.

Users usually prove their identity using credentials such as:

    • Username and password
    • OTP
    • Biometrics
    • Security tokens

Authorization

Authorization determines what an authenticated user is allowed to access or perform.

For example, an employee may be allowed to view files while an administrator can modify them.

Accounting

Accounting records and tracks user activities.

It may record information such as:

    • Login time
    • Logout time
    • IP address
    • Resources accessed
    • Data sent or received
    • Services used

5. What is the Cyber Kill Chain?

The Cyber Kill Chain was developed by Lockheed Martin as part of the Intelligence Driven Defense model.

It describes the stages attackers commonly follow when conducting a cyberattack.

The seven stages are:

1. Reconnaissance

The attacker collects information about the target.

Examples:

    • Email addresses
    • Employee information
    • Technologies used
    • Domains
    • Public information

2. Weaponization

The attacker prepares a malicious payload by combining an exploit with malware or a backdoor.

3. Delivery

The malicious payload is delivered to the victim.

Examples:

    • Email
    • Malicious link
    • Website
    • USB device

4. Exploitation

The attacker exploits a vulnerability to execute malicious code on the victim's system.

5. Installation

Malware or another malicious component is installed on the compromised system.

6. Command and Control (C2)

The compromised system communicates with the attacker's command-and-control infrastructure.

7. Actions on Objectives

The attacker performs their intended objective.

Examples:

    • Data theft
    • Data destruction
    • Credential theft
    • Surveillance
    • Lateral movement

6. What is SIEM?

SIEM – Security Information and Event Management is a security solution used to collect, aggregate, analyze and correlate logs and security events from multiple systems.

A SIEM helps security teams identify suspicious activity and potential threats.

Important SIEM functions include:

    • Centralized log collection
    • Event correlation
    • Real-time monitoring
    • Alert generation
    • Investigation
    • Reporting
    • Threat detection

For SOC analysts, SIEM platforms are especially important because they filter large amounts of security data and generate alerts for suspicious activity.

7. What are Indicators of Compromise (IOCs)?

Indicators of Compromise (IOCs) are pieces of forensic evidence that may indicate that a system or network has been compromised.

Examples of IOCs include:

    • Malicious IP addresses
    • Suspicious domains
    • File hashes
    • Malware files
    • Registry modifications
    • Suspicious processes
    • Unusual network connections

Security analysts use IOCs to investigate attacks, detect malicious activities and improve incident response.

8. What are Indicators of Attack (IOAs)?

Indicators of Attack (IOAs) focus on the behavior, intent and techniques used by an attacker during an attack.

Instead of concentrating only on known malicious files or hashes, IOAs focus on what an attacker is attempting to do.

Examples:

    • Suspicious PowerShell execution
    • Credential dumping attempts
    • Unusual privilege escalation
    • Abnormal lateral movement
    • Suspicious command execution

IOC vs IOA

IOC: Evidence that compromise may already have occurred.

IOA: Behavioral evidence that an attack may currently be occurring.

9. Explain True Positive and False Positive

True Positive

A True Positive occurs when a security system correctly detects a real malicious activity.

Example:

A SIEM detects a real SQL Injection attack and generates an alert.

Attack exists → Alert generated = True Positive

False Positive

A False Positive occurs when a security system generates an alert for legitimate activity.

Example:

A security camera detects your cat's movement and triggers an intrusion alert.

No attack → Alert generated = False Positive

For complete understanding:

    • True Positive: Attack exists and alert is generated.
    • False Positive: No attack exists but an alert is generated.
    • True Negative: No attack exists and no alert is generated.
    • False Negative: Attack exists but no alert is generated.

10. What is the OSI Model? Explain each layer.

The Open Systems Interconnection (OSI) Model is a conceptual networking model that divides network communication into seven layers.

The seven OSI layers are:

Layer 7 – Application Layer

The Application Layer is closest to the end user.

It provides network services to applications.

Examples:

    • HTTP
    • HTTPS
    • FTP
    • DNS
    • SMTP
    • SNMP

Layer 6 – Presentation Layer

The Presentation Layer handles:

    • Data formatting
    • Encryption
    • Decryption
    • Encoding
    • Compression

Examples:

    • TLS
    • Encryption formats
    • Character encoding

Layer 5 – Session Layer

The Session Layer establishes, manages and terminates communication sessions between applications.

Functions include:

    • Session establishment
    • Session maintenance
    • Session termination
    • Synchronization

Layer 4 – Transport Layer

The Transport Layer provides end-to-end communication between hosts.

Functions include:

    • Segmentation
    • Reliability
    • Flow control
    • Error recovery
    • Port numbers

Protocols:

    • TCP
    • UDP

Layer 3 – Network Layer

The Network Layer handles logical addressing and packet routing between networks.

Examples:

    • IP
    • ICMP
    • Routing protocols

Devices:

    • Routers

Layer 2 – Data Link Layer

The Data Link Layer provides node-to-node communication.

Functions include:

    • MAC addressing
    • Frame transmission
    • Error detection
    • Media access control

Examples:

    • Ethernet
    • PPP

Devices:

    • Switches

Layer 1 – Physical Layer

The Physical Layer deals with the physical transmission of raw bits.

Examples:

    • Cables
    • Electrical signals
    • Fiber optics
    • Radio signals
    • Network connectors

11. What is a TCP Three-Way Handshake?

TCP uses a three-way handshake to establish a reliable connection between a client and server.

The three steps are:

Step 1 – SYN

The client sends a SYN packet to the server requesting a connection.

Step 2 – SYN-ACK

The server responds with a SYN-ACK packet.

Step 3 – ACK

The client sends an ACK packet.

The TCP connection is now established and data can be exchanged.

In short:

Client → SYN → Server

Server → SYN-ACK → Client

Client → ACK → Server

12. What is the TCP/IP Model?

The TCP/IP model is the communication model used by the Internet.

It divides network communication into four layers.

TCP/IP Model Layers

    1. Application Layer
    2. Transport Layer
    3. Internet Layer
    4. Network Access Layer

Application Layer

Provides network services to applications.

Examples:

    • HTTP
    • HTTPS
    • DNS
    • FTP
    • SMTP

Transport Layer

Provides end-to-end communication.

Protocols:

    • TCP
    • UDP

Internet Layer

Handles logical addressing and routing.

Examples:

    • IP
    • ICMP

Network Access Layer

Handles communication with the physical network.

Examples:

    • Ethernet
    • Wi-Fi

13. Difference between OSI and TCP/IP Model

TCP/IPOSI

Has 4 layersHas 7 layers
Application combines Application, Presentation and Session functionsApplication, Presentation and Session are separate layers
Internet Layer corresponds mainly to OSI Network LayerHas Network Layer
Network Access combines Data Link and Physical functionsData Link and Physical are separate
Primarily used for real-world Internet communicationPrimarily used as a reference/conceptual model

14. What is ARP?

ARP – Address Resolution Protocol is used to map an IPv4 address to a MAC address on a local network.

Example:

A device knows another device's IP address but needs its MAC address before sending an Ethernet frame.

ARP helps discover that MAC address.

15. What is DHCP?

DHCP – Dynamic Host Configuration Protocol automatically assigns network configuration information to devices.

DHCP can provide:

    • IP address
    • Subnet mask
    • Default gateway
    • DNS server

DHCP follows a client-server architecture.

A common DHCP process is:

DORA

    • Discover
    • Offer
    • Request
    • Acknowledge

16. Could you share some general network security product categories?

    • Firewall
    • IDS
    • IPS
    • WAF

17. What is the key difference between IDS and IPS?

IDS – Intrusion Detection System

IDS monitors network traffic and detects suspicious activity.

It normally generates alerts.

IPS – Intrusion Prevention System

IPS detects suspicious activity and can also block or prevent malicious traffic.

In simple terms:

IDS = Detect + Alert

IPS = Detect + Block/Prevent

18. How can you protect yourself from Man-in-the-Middle attacks?

Encryption is one of the most important protections against MITM attacks.

Other protections include:

    • Use HTTPS/TLS
    • Avoid unsecured public Wi-Fi
    • Use a trusted VPN when appropriate
    • Verify website certificates
    • Use MFA
    • Keep systems updated
    • Avoid certificate warnings
    • Use secure Wi-Fi protocols
    • Use encrypted communication

19. Explain OWASP Top 10

The OWASP Top 10 is a security-awareness document that highlights major security risks affecting web applications.

The 2021 OWASP Top 10 includes:

    1. A01 – Broken Access Control
    2. A02 – Cryptographic Failures
    3. A03 – Injection
    4. A04 – Insecure Design
    5. A05 – Security Misconfiguration
    6. A06 – Vulnerable and Outdated Components
    7. A07 – Identification and Authentication Failures
    8. A08 – Software and Data Integrity Failures
    9. A09 – Security Logging and Monitoring Failures
    10. A10 – Server-Side Request Forgery (SSRF)

20. What is SQL Injection?

SQL Injection (SQLi) is a web application vulnerability where untrusted user input is incorporated into SQL queries in an unsafe manner.

This may allow attackers to manipulate database queries.

Potential impacts include:

    • Unauthorized data access
    • Data modification
    • Authentication bypass
    • Data deletion
    • Database compromise

21. Explain SQL Injection Types

There are three major categories.

1. In-Band SQL Injection

The attacker sends the attack and receives the result through the same communication channel.

Common examples:

    • Error-based SQLi
    • UNION-based SQLi

2. Inferential SQL Injection / Blind SQL Injection

The application does not directly return database information.

The attacker infers information based on application behavior.

Common types:

    • Boolean-based Blind SQLi
    • Time-based Blind SQLi

3. Out-of-Band SQL Injection

The attacker receives database information through a different communication channel.

For example, DNS or another external communication mechanism may be used.

22. How can SQL Injection vulnerabilities be prevented?

The strongest protections include:

    • Use parameterized queries/prepared statements
    • Avoid dynamically concatenating user input into SQL
    • Validate user input
    • Apply allow-list validation where appropriate
    • Use least-privilege database accounts
    • Use stored procedures safely
    • Perform secure code reviews
    • Conduct application security testing
    • Use a WAF as an additional defensive layer

Checking only for words such as SELECT, INSERT or special characters is not sufficient protection because attackers can bypass simple filters.

23. What is XSS and how can XSS be prevented?

Cross-Site Scripting (XSS) is a web vulnerability where malicious scripts are executed in another user's browser through a vulnerable web application.

It can occur when untrusted data is inserted into a web page without appropriate validation or output handling.

XSS Prevention

Use:

    • Context-aware output encoding
    • Input validation
    • HTML sanitization where HTML input is required
    • Secure frameworks and templating engines
    • Content Security Policy (CSP)
    • Safe DOM APIs
    • HttpOnly cookies where appropriate

24. Explain XSS Types

1. Reflected XSS

The malicious input is included in a request and immediately reflected by the application in its response.

It is generally non-persistent.

2. Stored XSS

The malicious script is stored by the application, for example in:

    • Database
    • Comment
    • Profile
    • Message

It is later delivered to users.

3. DOM-Based XSS

DOM-Based XSS occurs when insecure client-side JavaScript processes attacker-controlled data and modifies the page DOM in an unsafe manner.

25. What is IDOR?

IDOR – Insecure Direct Object Reference occurs when an application exposes an object identifier and does not properly verify whether the user is authorized to access that object.

Example:

A user accesses:

/invoice/1001

and changes it to:

/invoice/1002

If the application displays another user's invoice without authorization checks, it contains an access-control vulnerability.

IDOR is generally considered a form of Broken Access Control.

26. What is RFI?

RFI – Remote File Inclusion is a file inclusion vulnerability where an application improperly allows user-controlled input to cause inclusion of a file from a remote source.

It can potentially result in:

    • Malicious code execution
    • Application compromise
    • Server compromise

27. What is LFI?

LFI – Local File Inclusion is a vulnerability where an application improperly allows user-controlled input to access or include local files from the server.

Potentially exposed files may include:

    • Configuration files
    • Log files
    • Application files
    • System files

28. Difference between LFI and RFI

LFI

The targeted file is located on the same/local server.

RFI

The application attempts to include a file from a remote/external location.

In short:

LFI = Local file

RFI = Remote file

29. Explain CSRF

CSRF – Cross-Site Request Forgery is an attack that tricks an authenticated user into performing an unwanted action on a web application.

For example, an attacker may trick a logged-in user into unintentionally:

    • Changing an email address
    • Updating account information
    • Making a transaction
    • Changing security settings

Common protections include:

    • Anti-CSRF tokens
    • SameSite cookies
    • Re-authentication for sensitive operations
    • Origin/Referer validation where appropriate

30. What is WAF?

WAF – Web Application Firewall helps protect web applications by monitoring and filtering HTTP/HTTPS traffic between the application and users.

A WAF may help detect or block attacks such as:

    • SQL Injection
    • Cross-Site Scripting
    • Malicious requests
    • File inclusion attempts
    • Some automated attacks

A WAF mainly operates at the application layer and should be considered one part of a broader security strategy.

31. What are Encoding, Hashing and Encryption?

Encoding

Encoding converts information from one representation into another format so different systems can process or transfer it.

Examples:

    • Base64
    • URL encoding

Encoding is not designed to provide security.

Hashing

Hashing converts input data into a fixed-size digest using a hash function.

It is generally one-way.

Uses include:

    • Integrity verification
    • Password storage when used with suitable password-hashing algorithms
    • File verification

Examples:

    • SHA-256
    • SHA-3

Encryption

Encryption converts readable data (plaintext) into unreadable data (ciphertext) using a cryptographic key.

Authorized parties can decrypt the ciphertext using the appropriate key.

Its main purpose is to protect confidentiality.

32. Difference between Hashing and Encryption

Hashing

    • Primarily one-way
    • Usually does not use a secret encryption key
    • Produces a digest
    • Used for integrity and password verification
    • Original information is not normally recovered from the hash

Encryption

    • Reversible with the appropriate key
    • Uses cryptographic keys
    • Produces ciphertext
    • Used to protect confidentiality
    • Ciphertext can be decrypted back into plaintext

33. Explain Salted Hashes

A salt is a unique random value added to a password before password hashing.

Example conceptually:

Password + Salt → Password Hash

Using salts helps ensure that two users with the same password do not automatically have identical stored hashes.

Salting helps defend against precomputed attacks such as rainbow tables.

For password storage, modern password-hashing algorithms such as:

    • Argon2
    • bcrypt
    • scrypt
    • PBKDF2

are commonly used.

34. What are the differences between SSL and TLS?

SSL

SSL stands for Secure Sockets Layer.

    • SSL is an older cryptographic protocol.
    • SSL versions are obsolete and should not be used.

TLS

TLS stands for Transport Layer Security.

    • TLS is the successor to SSL.
    • TLS provides encryption, authentication and integrity for network communication.
    • TLS 1.2 and TLS 1.3 are widely used modern versions.

In everyday conversation, people sometimes still say SSL certificate, although modern secure websites actually use TLS.

35. What is the name of the software that compiles written code?

Compiler

A compiler translates source code written in a programming language into machine code, object code or another lower-level representation.

36. What is the name of the software that translates machine code into assembly language?

Disassembler

A disassembler converts machine instructions into assembly-language representations.

37. What is the difference between Static and Dynamic Malware Analysis?

Static Analysis

Static malware analysis examines malicious software without executing it.

Methods may include:

    • File hashing
    • Strings analysis
    • PE/header analysis
    • Disassembly
    • Decompilation
    • Examining imported functions

Advantages:

    • Safer because malware is not executed
    • Can reveal internal code structure
    • Useful for detailed reverse engineering

Dynamic Analysis

Dynamic analysis examines malware while it is running, usually in an isolated sandbox or controlled environment.

Analysts can observe:

    • Processes
    • File changes
    • Registry changes
    • Network traffic
    • DNS requests
    • Memory activity
    • Created services

Both static and dynamic analysis are commonly used together because each provides different information.

38. Which event logs are available by default on Windows?

Common Windows Event Logs include:

    • Security
    • Application
    • System

Additional logs are also available depending on Windows configuration and installed services.

39. With which Security Event ID can a successful logon be detected?

Event ID 4624

Windows Security Event ID 4624 indicates that an account successfully logged on.

40. With which Event ID can failed logons be detected?

Event ID 4625

Windows Security Event ID 4625 indicates that an account failed to log on.

41. Which field of which event should I look at to detect RDP logons?

You can investigate successful RDP logon activity using:

Windows Security Event ID: 4624

Look at the field:

Logon Type = 10

Logon Type 10 generally represents RemoteInteractive, commonly associated with Remote Desktop/RDP logons.

For SOC investigations, it is useful to correlate this with other Remote Desktop and Windows events instead of relying on Event ID 4624 alone.

42. Explain vulnerability, risk and threat

    • Vulnerability: Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source. (Source: NIST)
    • Risk: The level of impact on agency operations, including mission functions, image or reputation, agency assets, or individuals, resulting from the operation of an information system, considering the potential impact of a threat and the likelihood of that threat occurring. (Source: NIST)
    • Threat: Any circumstance or event with the potential to adversely impact organizational operations, organizational assets, individuals, other organizations, or the Nation through a system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. (Source: NIST)

43. What is compliance?

    • Following the set of standards authorized by an organization, independent party, or government.

44. What is MITRE ATT&CK?

    • MITRE ATT&CK® is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations.
    • The ATT&CK knowledge base is used as a foundation for developing specific threat models and methodologies in the private sector, government, and cybersecurity product and service community. (MITRE ATT&CK)

45. Do you have any project that we can look at?

    • If you have any project to show, make sure that you prepare it before the interview.

46. Explain 2FA

    • 2FA (Two-Factor Authentication) is an extra layer of security used to make sure that people trying to gain access to an online account are who they say they are.
    • First, a user enters their username and password.
    • Then, instead of immediately gaining access, they are required to provide another piece of information, such as an OTP, authentication app code, security key, or biometric verification.

Want to Build Practical Cybersecurity Skills?

Explore INCRITO’s Cybersecurity learning path and start developing hands-on, career-focused skills.

Button: Explore Cybersecurity Course →

Start with a free demo

Ready to start a career in tech?

Sit in on a free live demo class, meet a trainer and see the placement process before you enrol.

Browse courses
MK

Written by

Monika K

Start with a free demo

Not Sure Which Course Is Right for You?

Book a free demo and get guidance to choose the right course based on your skills, background and career goals.

Explore Courses