Why are you interested in this company and this position specifically?
Cybersecurity / InfoSec
Tell me about a project you are proud of and what motivates you in your work.
What are Golden Ticket and Silver Ticket attacks in Kerberos?
What is the 'Protected Users' security group in Windows and what does it do?
What are best practices for securing containers and Kubernetes workloads?
What are domain trusts and what is selective trust in Active Directory?
How would you organize the network architecture (segmentation) for a web application with frontend, backend, and database components?
A phishing email was sent and one employee clicked the link and entered their domain credentials. What are your incident response steps?
Regarding Windows authentication protocols — NTLM v1, NTLM v2, and Kerberos — which is more secure and why?
What is the Zero Trust security concept?
If the frontend is compromised, how would you prevent lateral movement to the database? What architectural patterns could help?
Explain SPF, DKIM, and DMARC — what does each technology do?
How do you use AI tools in your work?
What processes would you set up to manage vulnerabilities in a running web application?
What security measures would you apply to a web application accessible from the internet that handles confidential internal presentations and reports?