Cybersecurity interviews cover both fundamentals and judgement. Expect questions on the CIA triad, authentication versus authorisation and what genuinely counts as MFA, symmetric and asymmetric encryption and correct password storage, the OWASP Top 10 and defences for injection and XSS, IDS versus IPS, phishing and business email compromise, ransomware defence, and zero trust. Employers also probe how you justify security investment to a business. The questions below cover the technical and the strategic.





