Interview questions

Cybersecurity analyst screening questions: SOC tiers, SIEM, incidents and clearances

On this page
  1. SOC tiers and neighboring roles: place the candidate first
  2. SIEM, EDR and tools: used, tuned or built
  3. Alert triage and daily work
  4. The incident response story
  5. Certifications: issuers, requirements and how to check
  6. Security clearance questions, worded lawfully
  7. How security candidates overstate experience
  8. Shifts, on-call and logistics
  9. Knockout checklist and scorecard
  10. Questions people ask

Cybersecurity analyst screening questions should establish what the candidate did during an alert or incident, not what their security team owned. Ask which SOC tier they worked, which SIEM and endpoint tools they used every shift, how many alerts they handled and what made them escalate, and get one incident story from first alert to close. Then confirm certifications with the issuer and, for government work, ask about clearances with careful wording. Analysts with real experience name tools, queries and timelines; inflated resumes list frameworks.

Below are the questions with strong answers and red flags, a certification table, lawful clearance wording and a knockout checklist. For contract terms and rates, pair this with IT contractor screening questions.

SOC tiers and neighboring roles: place the candidate first

"Cybersecurity analyst" covers several jobs, and SOC tiers are not standardized between companies. Ask what the candidate's day consisted of rather than which tier label they had.

RoleWhat the work usually isFacts to ask forCommon overstatement
SOC analyst, Tier 1Monitoring the queue, triaging alerts, closing false positives, escalating by playbookAlerts per shift, escalation criteria, tools, shift pattern"Incident response" meaning escalating tickets to someone else
SOC analyst, Tier 2Investigating escalated alerts, scoping incidents, containment actionsIncidents investigated, containment they could take themselves, reports writtenTier 1 work with a Tier 2 title after a reorganization
Tier 3, threat hunter or detection engineerHunting for undetected activity, writing and tuning detectionsDetections written, hunts run, what they found"Threat hunting" meaning running a vendor's saved searches
Incident responderLeading response to confirmed incidents, forensics, coordinating recoveryIncidents led, their role versus outside responders, evidence handlingBeing on the bridge call described as leading the response
Vulnerability management analystScanning, prioritizing and tracking remediationScanner used, asset count, how they prioritized, remediation rates they trackedExporting scan reports described as managing the vulnerability program
GRC or compliance analystPolicies, risk assessments, audits against frameworksFrameworks, audits supported, controls they testedFramework names presented as hands-on security operations

SIEM, EDR and tools: used, tuned or built

Every security resume lists the same tools. The questions below place the candidate on a simple scale: viewed alerts in the tool, investigated with it, tuned it, or built on it.

ClaimQuestionStrong answerRed flag
Splunk"Did you write your own searches? Tell me about one you still remember."Describes a search in plain terms: "failed logins by user across all hosts in 10-minute windows," and why they needed it.Only clicked into alerts or dashboards others built.
Microsoft Sentinel"Did you write KQL queries or analytics rules, or work the incidents they created?"An honest split and one example of each they did.Cannot say where the alerts came from.
QRadar, Elastic, Google Security Operations"Which log sources fed it, and which one caused the most noise?"Names sources (firewall, identity provider, endpoint) and a noisy one they helped tune.No idea what data the SIEM received.
EDR (CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne)"What actions could you take yourself: isolate a host, kill a process, pull files?"Lists actions within their permissions and when they used one.Watched the console but never had permissions, described as EDR response.
SOAR or automation"What did you automate, and what did it save?"A playbook they built: enrich an alert with IP reputation, auto-close a known false positive."Worked with SOAR" meaning the playbooks ran around them.
MITRE ATT&CK"How did your team use it day to day?"Mapped detections or incidents to techniques to find coverage gaps.Can recite the name but not a use.

Alert triage and daily work

QuestionWhat a strong answer sounds likeRed flags
Roughly how many alerts did you handle in a shift, and what share were false positives?A rough number and a view: "Forty to sixty a shift; most were noisy identity alerts we later tuned."No idea of volume.
Walk me through the last alert you escalated. Why that one?The alert, what they checked (user, host, timeline, reputation), and the specific reason it met the escalation bar."It looked suspicious," with nothing they checked.
Tell me about an alert you closed as benign that you later doubted.An honest example and what they changed in how they triage.Never made a wrong call.
What did your playbooks cover, and when did you go off the playbook?Names a few playbooks (phishing, malware, impossible travel) and a case the playbook did not fit.Followed playbooks with no idea why each step existed.
How did you document an investigation, and who read it?Ticket notes with a timeline, evidence, and conclusion that the next shift or an auditor could follow."I closed the ticket."
Tell me about a phishing report you investigated.Checked headers or sender, links or attachments in a sandbox, who else received it, and whether anyone clicked.Deleted the email and moved on.

The incident response story

Ask every candidate: "Tell me about the most serious incident you worked, from the first alert to when it was closed. What did you personally do?" NIST's current incident response guidance, SP 800-61 Revision 3 (finalized April 2025), organizes incident response around the Cybersecurity Framework 2.0 functions, including detect, respond and recover. You do not need the framework to judge the story. Listen for these parts:

  • Detection. How it surfaced: an alert, a user report, a third party. Probe: "What was the very first sign?"
  • Scope. How they worked out what was affected: accounts, hosts, data. Probe: "How did you know it was not wider?"
  • Their actions. What they did with their own hands, separate from the team. Probe: "Which of those steps were yours?"
  • Containment and recovery. What was isolated, reset or restored, and in what order. Probe: "What did you have to get approval for?"
  • Communication. Who they updated and how often. Probe: "Who did you report to during it?"
  • Lessons. A detection added, a control changed, a playbook updated. Probe: "What is different now because of it?"

A strong answer, invented for illustration

"A user reported an MFA prompt they didn't request at 2 a.m. I checked the sign-in logs and saw a successful login from a new country right after, then a mailbox rule forwarding invoices outside. I revoked the sessions, reset the password with the help desk, and removed the rule. Then I searched for the same rule across all mailboxes and found two more. My lead handled the call with finance because one vendor payment had been changed. Afterwards I wrote a detection for new forwarding rules to external domains; it fired twice the next quarter."

Notice the pattern: a timeline, specific actions, a clear line between "I" and "my lead," and a lasting change. Red flags are the opposite: "we contained it quickly," a famous breach from the news retold as their own work, or confidentiality used to avoid every detail. Candidates can keep a client anonymous and still describe their steps.

Certifications: issuers, requirements and how to check

CertificationIssuerWhat it involvesHow to check
Security+CompTIAAn exam covering broad security knowledge. Valid for three years and renewed through CompTIA's continuing education program, per CompTIA.Ask for the PDF certificate or transcript; it carries a verification code, per CompTIA's help center
CySA+ (Cybersecurity Analyst)CompTIAAn exam focused on detection, analysis and response. Also valid for three years, per CompTIA.Same as Security+
CISSPISC2An exam plus a minimum of five years of cumulative, full-time experience in two or more of eight domains; a degree or approved credential can waive one year. Without the experience, passing makes the person an Associate of ISC2, per ISC2.ISC2 member verification (last name and member number)
  • CISSP versus Associate of ISC2. Someone who passed the exam without the experience is an Associate, not a CISSP. Ask "Are you fully certified or an Associate?" for early-career candidates who list CISSP.
  • Expired CompTIA certifications. A three-year validity means a Security+ from several years ago may have lapsed. Ask for the expiry date if the client requires an active certification.
  • Defense roles. The Department of Defense replaced its older 8570 program with DoD Manual 8140.03 in February 2023, and qualifying options are published by work role in the DoD 8140 qualification matrices. Ask the client which work role and qualification the contract specifies rather than guessing.

A certification confirms knowledge, not incident experience. A Tier 2 candidate with CySA+ who cannot tell an incident story is weaker than one with no certification and a clear story.

Security clearance questions, worded lawfully

This section describes rules as commonly summarized, as of September 2026. It is not legal advice. Confirm the requirements with the client's facility security officer and counsel for each role.

For roles on classified government contracts, clearance status is often a true knockout. Ask about it only when the client has confirmed the role requires it, and ask every candidate the same way.

AskAvoidWhy
"This role requires an active Secret clearance. Do you currently hold an active clearance, and at what level?""Have you ever had problems with a background check?"The level and status are what the job needs; investigation details are for the formal process.
"Roughly when was your most recent investigation or reinvestigation?"Questions about finances, foreign contacts, health or past drug use that come up in clearance formsLeave those to the government's process; they are not a recruiter's screening questions.
"The client has confirmed this contract requires US citizenship. Can you meet that requirement?"Asking about citizenship for roles that do not legally require itThe DOJ says an employer may restrict hiring to US citizens only if a law, regulation, executive order or government contract requires it.
"If you do not hold a clearance, the client may sponsor one. Are you willing to go through that process?"Treating "clearable" as a status"Clearable" is a belief, not something you can verify.

Two facts help set expectations with candidates and clients. Under the federal rule for contractors, 32 CFR 117.10, the contractor, not the individual, requests an eligibility determination; requests may not be used to build "a cache of cleared employees"; and a contractor may start the process before hire with a written commitment for employment that begins within 45 days of eligibility being granted. The same section allows non-US citizens only a limited access authorization in rare cases. Verification of an existing clearance is done by the hiring company's security officer in the government's system, not by the recruiter.

How security candidates overstate experience

PatternWhat it looks likeHow to check
Escalation as response"Performed incident response" in a Tier 1 role"What did you do after you escalated?"
Team incident as personal"Responded to a ransomware attack""What were your hands on, and who led?"
Tool list without depthTen SIEM and EDR products"Which one did you use every shift last year?" Ask only about that.
Home lab as productionSplunk or Sentinel used only in a home lab"Was that at work or in a lab?" Labs are good; labeling matters.
Framework as experienceNIST, ISO 27001, MITRE ATT&CK listed as skills"What did you do with it at work?"
Associate as CISSP"CISSP" with two years of experience"Fully certified or Associate of ISC2?" then verify
Clearance inflation"TS/SCI" that lapsed years ago, or "clearable""Is it active today, and when was your last investigation?"

Shifts, on-call and logistics

QuestionWhat a strong answer sounds likeRed flags
The SOC runs 24/7. This role is four 10-hour shifts, rotating to nights every six weeks. Can you work that schedule?Yes, or a clear limit. Describe the schedule and ask; do not ask about family or childcare.Agrees without asking any questions about a schedule they have never worked.
Senior analysts take on-call one week a month. What was your on-call experience, and how often were you paged?Frequency, response expectations, a page that turned out to be serious.Never on call, for a role that requires it.
Parts of this role require being on site in a secure facility. Does that work?A clear answer.Expects remote work for a classified environment.
What salary do you need to make a move?A number or range, including any shift differential they expect. Ask expectations, not current pay; see salary expectation questions.Only a number from a salary site.
Are you legally authorized to work in the US, and will you now or in the future need visa sponsorship?A direct answer to both, asked of everyone for non-cleared roles.None.

Knockout checklist and scorecard

Must-ask on every cybersecurity analyst screen

  • The actual day-to-day work, compared with the role's tier or function.
  • The SIEM and EDR they used every shift, and whether they wrote searches or took actions.
  • Alert volume, the last escalation and why.
  • The incident story, with their own actions separated from the team's.
  • Certifications with issuer, status and expiry; verified if required.
  • Clearance level and status, only if the role requires it, asked the same way for everyone.
  • Shift pattern, on-call, on-site needs, salary expectation, notice, other processes.

Knock out, or confirm with the client before submitting, if:

  • The contract requires an active clearance at a level the candidate does not hold, and the client will not sponsor.
  • A required certification is missing, expired, or an Associate status listed as full CISSP.
  • The role is Tier 2 or above and the candidate cannot describe one investigation they worked beyond escalation.
  • The candidate cannot work the shift or on-call pattern the role requires.
Area1234
Hands-on analysisMonitored dashboardsTriaged and escalatedInvestigated and containedLed response or wrote detections
Tool depthNames onlyWorked alerts in the toolWrote searches or took actionsTuned, automated or built detections
Incident storyNoneTeam story, vague partClear timeline and own actionsOwn actions plus a lasting change
Credentials and clearanceRequired item missingClaimed, not confirmedConfirmedConfirmed, beyond the minimum
Logistics fitDeal-breakerTwo open questionsOne open questionAll aligned

Capture the incident story in the candidate's words; a security manager judges it faster than any certification line. Interview Signal attaches those quotes to each score from the call without a bot joining, which matters when candidates in this field ask who else is listening. Avoid questions that point at age, national origin or religion when discussing shifts; the EEOC notes that such pre-employment inquiries can be used as evidence of discrimination.

Questions people ask

Can a recruiter ask whether a candidate has a security clearance?

Yes, when the role requires one for a government contract. Ask whether they hold an active clearance, at what level, and roughly when their last investigation was, and leave verification to the hiring company's facility security officer. Avoid questions about what came up in their investigation.

What does 'clearable' mean, and can I rely on it?

It is a candidate's own belief that they could be granted a clearance. It is not a status anyone can verify on a screen. A contractor must sponsor the request, so treat 'clearable' as unknown and ask the client whether they will sponsor a new clearance for this role.

Is Security+ enough for a SOC analyst job?

It is a common baseline, and some defense roles list it as a qualifying certification, but it tests broad knowledge rather than hands-on analysis. For Tier 1 roles it is a reasonable filter; for anything above that, ask about alerts they triaged and incidents they worked.

How do I verify a CISSP or CompTIA certification?

For CISSP, use ISC2's member verification with the candidate's last name and member number. For CompTIA certifications, ask the candidate for their PDF certificate or transcript, which carries a verification code CompTIA lets employers check.