SOC
Interview Questions
Basic SOC Questions
1. What is SOC?
SOC (Security Operations Center) is a team that monitors, detects, analyzes, and responds to
cyber threats 24/7.
2. What is the role of a SOC Analyst?
Monitor alerts, investigate incidents, analyze logs, and respond to security threats.
3. What are the levels of SOC?
L1 – Monitoring & alert triage
L2 – Investigation & analysis
L3 – Threat hunting & advanced response
4. What is SIEM?
Security Information and Event Management tool that collects and analyzes logs.
5. Name popular SIEM tools.
Splunk, QRadar, ArcSight, LogRhythm, Sentinel.
Networking Questions
6. What is an IP address?
Unique address assigned to devices on a network.
7. Difference between TCP & UDP?
TCP – Reliable, connection-based
UDP – Faster, connectionless
8. What is DNS?
Converts domain name to IP address.
9. What is a Firewall?
Security system that blocks unauthorized traffic.
10. What is VPN?
Secure tunnel to connect private networks.
Security Basics
11. What is Malware?
Malicious software designed to harm systems.
12. Types of malwares?
Virus, Worm, Trojan, Ransomware, Spyware.
13. What is Phishing?
Fake emails/messages to steal data.
14. What is Ransomware?
Malware that locks data and demands money.
15. What is DDoS?
Attack that floods a server with traffic.
SOC Practical Questions
16. What is Log Analysis?
Reviewing logs to detect suspicious activity.
17. What is an Alert?
Notification generated by security tools.
18. What is an Incident?
Confirmed security breach.
19. What is False Positive?
Alert that is not a real threat.
20. What is True Positive?
Alert that indicates real attack.
Tools Questions
21. What is EDR?
Endpoint Detection and Response tool to monitor endpoint activity.
22. Examples of EDR tools?
CrowdStrike, Defender, SentinelOne.
23. What is Antivirus?
Software that detects and removes malware.
24. What are IDS?
Intrusion Detection System that detects attacks.
25. What is IPS?
Intrusion Prevention System that blocks attacks.
Log & Monitoring
26. What logs are important in SOC?
Firewall logs
Window log
Antivirus log
Proxy logs
27. What is Event ID 4625?
Failed login attempt (Windows).
28. What is Event ID 4624?
Successful login.
29. What is Brute Force Attack?
Trying multiple passwords to gain access.
30. How to detect brute force?
Multiple failed logins attempt in logs.
Incident Response
31. What is Incident Response?
Process of handling security incidents.
32. Steps of Incident Response?
Detection
Analysis
Containment
Eradication
Recovery
33. What is Threat Intelligence?
Information about attackers and threats.
34. What is IOC?
Indicator of Compromise (IP, hash, domain).
35. What is MITRE ATT&CK?
Framework that explains attacker techniques.
Email Security
36. What is Spam?
Unwanted emails.
37. What is Email Header Analysis?
Checking email source and route.
38. What is Spoofing?
Fake identity used by attackers.
39. What is DKIM/SPF?
Email authentication methods.
40. What is Phishing URL check?
Verifying if link is malicious.
Real Interview Scenario Questions
41. What will you do if you get a malware alert?
Verify alert
Check logs
Isolate system
Inform team
42. What will you do if a user reports phishing mail?
Analyze email Block sender
Remove mail from all inboxes
43. How do you prioritize alerts?
Based on severity and impact.
44. Difference between Vulnerability & Threat?
Vulnerability – Weakness
Threat – Possible attack
45. What is Patch Management?
Updating systems to fix security bugs.
Advanced Questions
46. What is Zero-Day Attack?
Attack using unknown vulnerability.
47. What is Data Exfiltration?
Stealing sensitive data.
48. What is Lateral Movement?
Attacker moving inside network.
49. What is Privilege Escalation?
Gaining higher access rights.
50. Why should we hire you as a SOC Analyst?
Because I have knowledge of networking, security tools, log analysis, and strong interest in
threat detection.