Top Cybersecurity Questions Beginners Should Know in 2026

Starting your cybersecurity journey? Explore important cybersecurity questions every beginner should understand, covering threats, networks, ethical hacking, security tools and career fundamentals.
Cybersecurity Interview Questions & Answers
1. Could you share some general endpoint security product names?
- Antivirus
- EDR – Endpoint Detection and Response
- XDR – Extended Detection and Response
- DLP – Data Loss Prevention
2. What are HIDS and NIDS?
- HIDS: Host Intrusion Detection System. HIDS is installed on individual hosts/endpoints and monitors activities occurring on that system.
- NIDS: Network Intrusion Detection System. NIDS monitors network traffic and detects suspicious or malicious network activity.
3. What is the CIA Triad?
The three letters in the CIA Triad stand for:
- Confidentiality
- Integrity
- Availability
The CIA Triad is a common information-security model used as the foundation for designing and evaluating security systems.
Confidentiality
Confidentiality ensures that information is accessible only to authorized individuals.
The objective is to prevent unauthorized people from accessing sensitive information or business assets.
Examples:
- Encryption
- Access controls
- Authentication
- Permissions
Integrity
Integrity ensures that data is accurate, trustworthy, complete and has not been modified without authorization.
Examples:
- Hashing
- Digital signatures
- File integrity monitoring
Availability
Availability ensures that systems, applications, networks and information are accessible to authorized users whenever required.
Examples:
- Backups
- Redundancy
- Disaster recovery
- High availability
4. What is AAA?
AAA stands for:
Authentication
Authentication verifies who the user is.
Users usually prove their identity using credentials such as:
- Username and password
- OTP
- Biometrics
- Security tokens
Authorization
Authorization determines what an authenticated user is allowed to access or perform.
For example, an employee may be allowed to view files while an administrator can modify them.
Accounting
Accounting records and tracks user activities.
It may record information such as:
- Login time
- Logout time
- IP address
- Resources accessed
- Data sent or received
- Services used
5. What is the Cyber Kill Chain?
The Cyber Kill Chain was developed by Lockheed Martin as part of the Intelligence Driven Defense model.
It describes the stages attackers commonly follow when conducting a cyberattack.
The seven stages are:
1. Reconnaissance
The attacker collects information about the target.
Examples:
- Email addresses
- Employee information
- Technologies used
- Domains
- Public information
2. Weaponization
The attacker prepares a malicious payload by combining an exploit with malware or a backdoor.
3. Delivery
The malicious payload is delivered to the victim.
Examples:
- Malicious link
- Website
- USB device
4. Exploitation
The attacker exploits a vulnerability to execute malicious code on the victim's system.
5. Installation
Malware or another malicious component is installed on the compromised system.
6. Command and Control (C2)
The compromised system communicates with the attacker's command-and-control infrastructure.
7. Actions on Objectives
The attacker performs their intended objective.
Examples:
- Data theft
- Data destruction
- Credential theft
- Surveillance
- Lateral movement
6. What is SIEM?
SIEM – Security Information and Event Management is a security solution used to collect, aggregate, analyze and correlate logs and security events from multiple systems.
A SIEM helps security teams identify suspicious activity and potential threats.
Important SIEM functions include:
- Centralized log collection
- Event correlation
- Real-time monitoring
- Alert generation
- Investigation
- Reporting
- Threat detection
For SOC analysts, SIEM platforms are especially important because they filter large amounts of security data and generate alerts for suspicious activity.
7. What are Indicators of Compromise (IOCs)?
Indicators of Compromise (IOCs) are pieces of forensic evidence that may indicate that a system or network has been compromised.
Examples of IOCs include:
- Malicious IP addresses
- Suspicious domains
- File hashes
- Malware files
- Registry modifications
- Suspicious processes
- Unusual network connections
Security analysts use IOCs to investigate attacks, detect malicious activities and improve incident response.
8. What are Indicators of Attack (IOAs)?
Indicators of Attack (IOAs) focus on the behavior, intent and techniques used by an attacker during an attack.
Instead of concentrating only on known malicious files or hashes, IOAs focus on what an attacker is attempting to do.
Examples:
- Suspicious PowerShell execution
- Credential dumping attempts
- Unusual privilege escalation
- Abnormal lateral movement
- Suspicious command execution
IOC vs IOA
IOC: Evidence that compromise may already have occurred.
IOA: Behavioral evidence that an attack may currently be occurring.
9. Explain True Positive and False Positive
True Positive
A True Positive occurs when a security system correctly detects a real malicious activity.
Example:
A SIEM detects a real SQL Injection attack and generates an alert.
Attack exists → Alert generated = True Positive
False Positive
A False Positive occurs when a security system generates an alert for legitimate activity.
Example:
A security camera detects your cat's movement and triggers an intrusion alert.
No attack → Alert generated = False Positive
For complete understanding:
- True Positive: Attack exists and alert is generated.
- False Positive: No attack exists but an alert is generated.
- True Negative: No attack exists and no alert is generated.
- False Negative: Attack exists but no alert is generated.
10. What is the OSI Model? Explain each layer.
The Open Systems Interconnection (OSI) Model is a conceptual networking model that divides network communication into seven layers.
The seven OSI layers are:
Layer 7 – Application Layer
The Application Layer is closest to the end user.
It provides network services to applications.
Examples:
- HTTP
- HTTPS
- FTP
- DNS
- SMTP
- SNMP
Layer 6 – Presentation Layer
The Presentation Layer handles:
- Data formatting
- Encryption
- Decryption
- Encoding
- Compression
Examples:
- TLS
- Encryption formats
- Character encoding
Layer 5 – Session Layer
The Session Layer establishes, manages and terminates communication sessions between applications.
Functions include:
- Session establishment
- Session maintenance
- Session termination
- Synchronization
Layer 4 – Transport Layer
The Transport Layer provides end-to-end communication between hosts.
Functions include:
- Segmentation
- Reliability
- Flow control
- Error recovery
- Port numbers
Protocols:
- TCP
- UDP
Layer 3 – Network Layer
The Network Layer handles logical addressing and packet routing between networks.
Examples:
- IP
- ICMP
- Routing protocols
Devices:
- Routers
Layer 2 – Data Link Layer
The Data Link Layer provides node-to-node communication.
Functions include:
- MAC addressing
- Frame transmission
- Error detection
- Media access control
Examples:
- Ethernet
- PPP
Devices:
- Switches
Layer 1 – Physical Layer
The Physical Layer deals with the physical transmission of raw bits.
Examples:
- Cables
- Electrical signals
- Fiber optics
- Radio signals
- Network connectors
11. What is a TCP Three-Way Handshake?
TCP uses a three-way handshake to establish a reliable connection between a client and server.
The three steps are:
Step 1 – SYN
The client sends a SYN packet to the server requesting a connection.
Step 2 – SYN-ACK
The server responds with a SYN-ACK packet.
Step 3 – ACK
The client sends an ACK packet.
The TCP connection is now established and data can be exchanged.
In short:
Client → SYN → Server
Server → SYN-ACK → Client
Client → ACK → Server
12. What is the TCP/IP Model?
The TCP/IP model is the communication model used by the Internet.
It divides network communication into four layers.
TCP/IP Model Layers
- Application Layer
- Transport Layer
- Internet Layer
- Network Access Layer
Application Layer
Provides network services to applications.
Examples:
- HTTP
- HTTPS
- DNS
- FTP
- SMTP
Transport Layer
Provides end-to-end communication.
Protocols:
- TCP
- UDP
Internet Layer
Handles logical addressing and routing.
Examples:
- IP
- ICMP
Network Access Layer
Handles communication with the physical network.
Examples:
- Ethernet
- Wi-Fi
13. Difference between OSI and TCP/IP Model
| TCP/IP | OSI |
| Has 4 layers | Has 7 layers |
| Application combines Application, Presentation and Session functions | Application, Presentation and Session are separate layers |
| Internet Layer corresponds mainly to OSI Network Layer | Has Network Layer |
| Network Access combines Data Link and Physical functions | Data Link and Physical are separate |
| Primarily used for real-world Internet communication | Primarily used as a reference/conceptual model |
14. What is ARP?
ARP – Address Resolution Protocol is used to map an IPv4 address to a MAC address on a local network.
Example:
A device knows another device's IP address but needs its MAC address before sending an Ethernet frame.
ARP helps discover that MAC address.
15. What is DHCP?
DHCP – Dynamic Host Configuration Protocol automatically assigns network configuration information to devices.
DHCP can provide:
- IP address
- Subnet mask
- Default gateway
- DNS server
DHCP follows a client-server architecture.
A common DHCP process is:
DORA
- Discover
- Offer
- Request
- Acknowledge
16. Could you share some general network security product categories?
- Firewall
- IDS
- IPS
- WAF
17. What is the key difference between IDS and IPS?
IDS – Intrusion Detection System
IDS monitors network traffic and detects suspicious activity.
It normally generates alerts.
IPS – Intrusion Prevention System
IPS detects suspicious activity and can also block or prevent malicious traffic.
In simple terms:
IDS = Detect + Alert
IPS = Detect + Block/Prevent
18. How can you protect yourself from Man-in-the-Middle attacks?
Encryption is one of the most important protections against MITM attacks.
Other protections include:
- Use HTTPS/TLS
- Avoid unsecured public Wi-Fi
- Use a trusted VPN when appropriate
- Verify website certificates
- Use MFA
- Keep systems updated
- Avoid certificate warnings
- Use secure Wi-Fi protocols
- Use encrypted communication
19. Explain OWASP Top 10
The OWASP Top 10 is a security-awareness document that highlights major security risks affecting web applications.
The 2021 OWASP Top 10 includes:
- A01 – Broken Access Control
- A02 – Cryptographic Failures
- A03 – Injection
- A04 – Insecure Design
- A05 – Security Misconfiguration
- A06 – Vulnerable and Outdated Components
- A07 – Identification and Authentication Failures
- A08 – Software and Data Integrity Failures
- A09 – Security Logging and Monitoring Failures
- A10 – Server-Side Request Forgery (SSRF)
20. What is SQL Injection?
SQL Injection (SQLi) is a web application vulnerability where untrusted user input is incorporated into SQL queries in an unsafe manner.
This may allow attackers to manipulate database queries.
Potential impacts include:
- Unauthorized data access
- Data modification
- Authentication bypass
- Data deletion
- Database compromise
21. Explain SQL Injection Types
There are three major categories.
1. In-Band SQL Injection
The attacker sends the attack and receives the result through the same communication channel.
Common examples:
- Error-based SQLi
- UNION-based SQLi
2. Inferential SQL Injection / Blind SQL Injection
The application does not directly return database information.
The attacker infers information based on application behavior.
Common types:
- Boolean-based Blind SQLi
- Time-based Blind SQLi
3. Out-of-Band SQL Injection
The attacker receives database information through a different communication channel.
For example, DNS or another external communication mechanism may be used.
22. How can SQL Injection vulnerabilities be prevented?
The strongest protections include:
- Use parameterized queries/prepared statements
- Avoid dynamically concatenating user input into SQL
- Validate user input
- Apply allow-list validation where appropriate
- Use least-privilege database accounts
- Use stored procedures safely
- Perform secure code reviews
- Conduct application security testing
- Use a WAF as an additional defensive layer
Checking only for words such as SELECT, INSERT or special characters is not sufficient protection because attackers can bypass simple filters.
23. What is XSS and how can XSS be prevented?
Cross-Site Scripting (XSS) is a web vulnerability where malicious scripts are executed in another user's browser through a vulnerable web application.
It can occur when untrusted data is inserted into a web page without appropriate validation or output handling.
XSS Prevention
Use:
- Context-aware output encoding
- Input validation
- HTML sanitization where HTML input is required
- Secure frameworks and templating engines
- Content Security Policy (CSP)
- Safe DOM APIs
- HttpOnly cookies where appropriate
24. Explain XSS Types
1. Reflected XSS
The malicious input is included in a request and immediately reflected by the application in its response.
It is generally non-persistent.
2. Stored XSS
The malicious script is stored by the application, for example in:
- Database
- Comment
- Profile
- Message
It is later delivered to users.
3. DOM-Based XSS
DOM-Based XSS occurs when insecure client-side JavaScript processes attacker-controlled data and modifies the page DOM in an unsafe manner.
25. What is IDOR?
IDOR – Insecure Direct Object Reference occurs when an application exposes an object identifier and does not properly verify whether the user is authorized to access that object.
Example:
A user accesses:
/invoice/1001
and changes it to:
/invoice/1002
If the application displays another user's invoice without authorization checks, it contains an access-control vulnerability.
IDOR is generally considered a form of Broken Access Control.
26. What is RFI?
RFI – Remote File Inclusion is a file inclusion vulnerability where an application improperly allows user-controlled input to cause inclusion of a file from a remote source.
It can potentially result in:
- Malicious code execution
- Application compromise
- Server compromise
27. What is LFI?
LFI – Local File Inclusion is a vulnerability where an application improperly allows user-controlled input to access or include local files from the server.
Potentially exposed files may include:
- Configuration files
- Log files
- Application files
- System files
28. Difference between LFI and RFI
LFI
The targeted file is located on the same/local server.
RFI
The application attempts to include a file from a remote/external location.
In short:
LFI = Local file
RFI = Remote file
29. Explain CSRF
CSRF – Cross-Site Request Forgery is an attack that tricks an authenticated user into performing an unwanted action on a web application.
For example, an attacker may trick a logged-in user into unintentionally:
- Changing an email address
- Updating account information
- Making a transaction
- Changing security settings
Common protections include:
- Anti-CSRF tokens
- SameSite cookies
- Re-authentication for sensitive operations
- Origin/Referer validation where appropriate
30. What is WAF?
WAF – Web Application Firewall helps protect web applications by monitoring and filtering HTTP/HTTPS traffic between the application and users.
A WAF may help detect or block attacks such as:
- SQL Injection
- Cross-Site Scripting
- Malicious requests
- File inclusion attempts
- Some automated attacks
A WAF mainly operates at the application layer and should be considered one part of a broader security strategy.
31. What are Encoding, Hashing and Encryption?
Encoding
Encoding converts information from one representation into another format so different systems can process or transfer it.
Examples:
- Base64
- URL encoding
Encoding is not designed to provide security.
Hashing
Hashing converts input data into a fixed-size digest using a hash function.
It is generally one-way.
Uses include:
- Integrity verification
- Password storage when used with suitable password-hashing algorithms
- File verification
Examples:
- SHA-256
- SHA-3
Encryption
Encryption converts readable data (plaintext) into unreadable data (ciphertext) using a cryptographic key.
Authorized parties can decrypt the ciphertext using the appropriate key.
Its main purpose is to protect confidentiality.
32. Difference between Hashing and Encryption
Hashing
- Primarily one-way
- Usually does not use a secret encryption key
- Produces a digest
- Used for integrity and password verification
- Original information is not normally recovered from the hash
Encryption
- Reversible with the appropriate key
- Uses cryptographic keys
- Produces ciphertext
- Used to protect confidentiality
- Ciphertext can be decrypted back into plaintext
33. Explain Salted Hashes
A salt is a unique random value added to a password before password hashing.
Example conceptually:
Password + Salt → Password Hash
Using salts helps ensure that two users with the same password do not automatically have identical stored hashes.
Salting helps defend against precomputed attacks such as rainbow tables.
For password storage, modern password-hashing algorithms such as:
- Argon2
- bcrypt
- scrypt
- PBKDF2
are commonly used.
34. What are the differences between SSL and TLS?
SSL
SSL stands for Secure Sockets Layer.
- SSL is an older cryptographic protocol.
- SSL versions are obsolete and should not be used.
TLS
TLS stands for Transport Layer Security.
- TLS is the successor to SSL.
- TLS provides encryption, authentication and integrity for network communication.
- TLS 1.2 and TLS 1.3 are widely used modern versions.
In everyday conversation, people sometimes still say SSL certificate, although modern secure websites actually use TLS.
35. What is the name of the software that compiles written code?
Compiler
A compiler translates source code written in a programming language into machine code, object code or another lower-level representation.
36. What is the name of the software that translates machine code into assembly language?
Disassembler
A disassembler converts machine instructions into assembly-language representations.
37. What is the difference between Static and Dynamic Malware Analysis?
Static Analysis
Static malware analysis examines malicious software without executing it.
Methods may include:
- File hashing
- Strings analysis
- PE/header analysis
- Disassembly
- Decompilation
- Examining imported functions
Advantages:
- Safer because malware is not executed
- Can reveal internal code structure
- Useful for detailed reverse engineering
Dynamic Analysis
Dynamic analysis examines malware while it is running, usually in an isolated sandbox or controlled environment.
Analysts can observe:
- Processes
- File changes
- Registry changes
- Network traffic
- DNS requests
- Memory activity
- Created services
Both static and dynamic analysis are commonly used together because each provides different information.
38. Which event logs are available by default on Windows?
Common Windows Event Logs include:
- Security
- Application
- System
Additional logs are also available depending on Windows configuration and installed services.
39. With which Security Event ID can a successful logon be detected?
Event ID 4624
Windows Security Event ID 4624 indicates that an account successfully logged on.
40. With which Event ID can failed logons be detected?
Event ID 4625
Windows Security Event ID 4625 indicates that an account failed to log on.
41. Which field of which event should I look at to detect RDP logons?
You can investigate successful RDP logon activity using:
Windows Security Event ID: 4624
Look at the field:
Logon Type = 10
Logon Type 10 generally represents RemoteInteractive, commonly associated with Remote Desktop/RDP logons.
For SOC investigations, it is useful to correlate this with other Remote Desktop and Windows events instead of relying on Event ID 4624 alone.
42. Explain vulnerability, risk and threat
- Vulnerability: Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source. (Source: NIST)
- Risk: The level of impact on agency operations, including mission functions, image or reputation, agency assets, or individuals, resulting from the operation of an information system, considering the potential impact of a threat and the likelihood of that threat occurring. (Source: NIST)
- Threat: Any circumstance or event with the potential to adversely impact organizational operations, organizational assets, individuals, other organizations, or the Nation through a system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. (Source: NIST)
43. What is compliance?
- Following the set of standards authorized by an organization, independent party, or government.
44. What is MITRE ATT&CK?
- MITRE ATT&CK® is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations.
- The ATT&CK knowledge base is used as a foundation for developing specific threat models and methodologies in the private sector, government, and cybersecurity product and service community. (MITRE ATT&CK)
45. Do you have any project that we can look at?
- If you have any project to show, make sure that you prepare it before the interview.
46. Explain 2FA
- 2FA (Two-Factor Authentication) is an extra layer of security used to make sure that people trying to gain access to an online account are who they say they are.
- First, a user enters their username and password.
- Then, instead of immediately gaining access, they are required to provide another piece of information, such as an OTP, authentication app code, security key, or biometric verification.
Want to Build Practical Cybersecurity Skills?
Explore INCRITO’s Cybersecurity learning path and start developing hands-on, career-focused skills.
Button: Explore Cybersecurity Course →
Start with a free demo
Ready to start a career in tech?
Sit in on a free live demo class, meet a trainer and see the placement process before you enrol.
Written by
Monika K


