Security Research Interview Questions

5,075 security research interview questions shared by candidates

Network Questions: 1) OSI Model and Layers 2) Transport and Nework Layer 3) ICMP & Traceroute working 4) OS Detection using PIng 5) Nmap is which layer tool and its os detection 6) WPA-2 4way handshake 7) ICMP,TCP,IP Header Length 8) SSL Handshake 9) What happens when we type google.com in browser 10) Router working 11) Subnetting 12) Public/Private IP and Ranges 13) Crpytography ( Asym | Sym) 14) Encoding | Hashing | Encryption 15) Pivoting 16)Port Knocking 17) TCP 3-Way Handshake 18) HTTP is stateless and HTTPS is stateful protocol 19) SSH Local Forwarding 20) Scenario Based Question 21) SSH working( Detailed Description) 22) Nmap switches and their working 23) DHCP 24) ARP 25) Mac and Switching 26) Lateral Movement 27) Reverse | Bind Shell 28) Web Shell 29) Network Tools used in recon 30) SOCKS Proxy and its working Web Questions 1) SOP 2)CORS 3)CSP 4) Access Control | IDOR with Mitigation 5) Blind XSS 6) Dom XSS | Source & Sync 7) Template Injection 8) Cookies vs Session 9) Cookies Security Attributes 10) Second Order SQLi and Remediation 11) CSRF | Mitigation 12) Scenario Question (CSRF,XSS,CORS) 13) Anti CSRF Toke Implementation in Response Body | Headers which is secure 14) Recon Approach 15) SQL Testing on Login Page 16) Buisness Logic 17) JWT Basics and Common Attacks 18) Oauth Working 19) Session vs Token Based Authentication Difference 20) Threat | Risk | Vulnerability 21) VA | PT 22) Block vs Stream Ciphers 23) LFI vs RFI 24) XXE | Mitigation 25) SSRF & Blind SSRF 26) RCE 27) Broken Authentication 28) LFI to RCE leading to Log Poisoning 29) HTTP 1.0 vs 1.1 30) Ping Sweep Program (Any Language) C Question can be present in the interview so please prepare well.
avatar

Security Consultant

Interviewed at Payatu Security Consulting

3.9
Aug 11, 2020

Network Questions: 1) OSI Model and Layers 2) Transport and Nework Layer 3) ICMP & Traceroute working 4) OS Detection using PIng 5) Nmap is which layer tool and its os detection 6) WPA-2 4way handshake 7) ICMP,TCP,IP Header Length 8) SSL Handshake 9) What happens when we type google.com in browser 10) Router working 11) Subnetting 12) Public/Private IP and Ranges 13) Crpytography ( Asym | Sym) 14) Encoding | Hashing | Encryption 15) Pivoting 16)Port Knocking 17) TCP 3-Way Handshake 18) HTTP is stateless and HTTPS is stateful protocol 19) SSH Local Forwarding 20) Scenario Based Question 21) SSH working( Detailed Description) 22) Nmap switches and their working 23) DHCP 24) ARP 25) Mac and Switching 26) Lateral Movement 27) Reverse | Bind Shell 28) Web Shell 29) Network Tools used in recon 30) SOCKS Proxy and its working Web Questions 1) SOP 2)CORS 3)CSP 4) Access Control | IDOR with Mitigation 5) Blind XSS 6) Dom XSS | Source & Sync 7) Template Injection 8) Cookies vs Session 9) Cookies Security Attributes 10) Second Order SQLi and Remediation 11) CSRF | Mitigation 12) Scenario Question (CSRF,XSS,CORS) 13) Anti CSRF Toke Implementation in Response Body | Headers which is secure 14) Recon Approach 15) SQL Testing on Login Page 16) Buisness Logic 17) JWT Basics and Common Attacks 18) Oauth Working 19) Session vs Token Based Authentication Difference 20) Threat | Risk | Vulnerability 21) VA | PT 22) Block vs Stream Ciphers 23) LFI vs RFI 24) XXE | Mitigation 25) SSRF & Blind SSRF 26) RCE 27) Broken Authentication 28) LFI to RCE leading to Log Poisoning 29) HTTP 1.0 vs 1.1 30) Ping Sweep Program (Any Language) C Question can be present in the interview so please prepare well.

Viewing 291 - 300 interview questions

Glassdoor has 5,075 interview questions and reports from Security research interviews. Prepare for your interview. Get hired. Love your job.