What is Risk
What is Threat
What is Vulnerability
What is an Exploit
What is an Attack
What is a Zero Day & What is a Zero Day attack
What is VA
What is PT
What is Honeypot and what is Honeynet
What is CIA Triad
OSI Model in detail
5 phases of hacking
How many ports in total
Port no range
Port No 22, 23, 53, 110, 123, 137, 445, 3389 etc
What does port no 0 stand for
TCP v/s UDP
IPv4 v/s IPv6
IPv4 how many classes & IP ranges
TCP flags
3 way handshake : How is connection established and how is connection terminated
What is port scan and network scan
Why Nmap is used. Commands of Nmap
What is Metasploit
What is root kits
What is Trojan
Virus v/s worms
DoS v/s DDoS
XSS CSRF
Session Hijacking
Man in the middle attack
What is Stetnography
Types of firewall
Different Security devices
OWASP Top 10
SQL Injection
Different file hashes in Cryptography
symmetric v/s asymmetric encryption
DNS
DHCP
DNS posioning
Sinkhole
Different type of log sources & it’s functionality & traffic flow (FW, IPS, Proxy, AV, O365 etc).
QRadar / Splunk / ArcSight Architecture
MITRE framework and CKC Phases
CKC in detail
How does ransomware spread
Lateral Movement Propagation
How to detect ransomware & rule condition
WannyCry in detail with detection & mitigation
Kill switch
Other ransomware attack you have come across / read about.
· Phishing attacks
Definition
How to detect phishing
Devices which can detect & fields(information) we can see on those devices.
Detailed analysis of Phishing on a given log Source (Ex: How to detect phishing on Proxy)
How to detect phishing on web applications
· WAF / IPS / other log sources what are Relevant field list / parameter of each log source
· Web Applications
How to detect DoS / DDoS
How to detect any malicious attempts such as SQL injection
Recommendation / Measures to prevent attack
Vulnerability check for a given web app
XSS & types
SQL injection & types along with detection and recommendation.
What is of SOC, SIEM, your role & responsibilities as a Analyst, How you will contribute to this project,
Scope of improvements in SOC and how will to improve them.
One good incident you have analysed or any practical performed in detail
How do you keep yourself updated with latest security breach / news / threat
One Achievement or proud moment of yours
· Any Scenario based question : How to detect / analyse --- Logs sources that detect --- Recommendation
/ Mitigation Steps
1. Brute force attack
2. Multiple virus on same system
3. Vulnerability like log4j
4. SQL injection attack
5. Connection to C&C domain