Login to manage your account

Please enter a valid email address.
Forgot Password?
Please enter a valid password.
OR

Don't have an account yet? Sign up

Cybersecurity interviews cover both fundamentals and judgement. Expect questions on the CIA triad, authentication versus authorisation and what genuinely counts as MFA, symmetric and asymmetric encryption and correct password storage, the OWASP Top 10 and defences for injection and XSS, IDS versus IPS, phishing and business email compromise, ransomware defence, and zero trust. Employers also probe how you justify security investment to a business. The questions below cover the technical and the strategic.

Cybersecurity MCQ

1.What are the three components of the CIA triad?

2.What is the difference between authentication and authorisation?

3.Which combination genuinely constitutes multi-factor authentication?

4.How should user passwords be stored?

5.What is the practical relationship between symmetric and asymmetric encryption in TLS?

6.What does a digital signature provide?

7.Which is the top risk in the OWASP Top 10?

8.What is the definitive defence against SQL injection?

9.Which type of cross-site scripting is generally most dangerous?

11.What does a Content Security Policy defend against most directly?

12.What does a CSRF attack exploit?

13.What is Server-Side Request Forgery (SSRF)?

14.What is the difference between a vulnerability assessment and a penetration test?

15.What must be agreed in writing before any penetration test?

16.What distinguishes a red team engagement from a penetration test?

17.What is the difference between an IDS and an IPS?

18.What is the main advantage of a stateful firewall over packet filtering?

19.Which attack type causes the greatest financial losses without necessarily using malware?

20.Which control defeats credential phishing even when the user is successfully fooled?

21.What should be the goal of a phishing awareness programme?

22.Which email authentication mechanisms help prevent domain spoofing?

23.What is double extortion ransomware?

24.Which is the single most important technical control for ransomware recovery?

25.Which service should never be exposed directly to the internet?

26.What are the core principles of zero trust architecture?

27.Why did the perimeter security model become insufficient?

28.What is the primary value of a SIEM?

29.Which log source is most valuable to a SIEM?

31.What are the phases of incident response in order?

32.Why should evidence be captured before rebuilding a compromised host?

33.Which vulnerability list is most useful for prioritising patching?

34.How should vulnerabilities be prioritised beyond severity score?

35.What does defence in depth mean?

36.What does the principle of least privilege reduce most directly?

37.Which practice most reduces the risk from a compromised administrator workstation?

38.What does current NIST guidance say about forced periodic password rotation?

39.Why is security which users routinely work around ineffective?

40.How should security investment be justified to a business?

41.What should happen when a business declines to fund a security control?

Login to manage your account

Please enter a valid email address.
Forgot Password?
Please enter a valid password.
OR

Don't have an account yet? Sign up as