-
Website
http://danielmiessler.com/ -
Original page
http://danielmiessler.com/blog/10-questions-to-ask-during-an-information-security-interview -
Subscribe
All Comments -
Community
-
Top Commenters
-
'Dapo Osewa
3 comments · 1 points
-
Maxo
18 comments · 2 points
-
cooperati
127 comments · 2 points
-
dapxin
11 comments · 1 points
-
icepyro
3 comments · 1 points
-
-
Popular Threads
-
Islam: It’s the Intolerance That’s Scary
3 weeks ago · 19 comments
-
Chrome > Firefox
1 week ago · 4 comments
-
Disk Performance: Slicehost vs. Linode
2 weeks ago · 7 comments
-
Creation vs. Collection
2 weeks ago · 5 comments
-
How to Manage a Cisco Device via Console Using a USB Port in OS X
1 week ago · 2 comments
-
Islam: It’s the Intolerance That’s Scary
Don't forget that security is mostly an attitude, or actually a way of life, and only secondly knowledge.
-- Arik
Well said.
My favorite interview bonus question is "how many fire alarm levers did we pass on the way here?"
I'd hire someone who got every technical question wrong but answered that one even in the ball park.
-Dave
Define non-repudiation and give a real world example.
What would you do with a Rainbow Table?
What is a downstream liability?
What is the difference between symmetric and asymmetric cryptography?
...wait for it...
Instead, the message is encrypted with a randomly generated SYMMETRIC key, and *that* key is encrypted using their public key. They then decrypt the symmetric key, and use that to read the encrypted message. Which directly illustrates the positives and negatives of both. You wouldn't want to use asymmetric cryptography to encrypt a very large message due to the time cost, so symmetric cryptography is used instead.
Interesting - I got the Compression vs. Encryption question in the terms of asking about how IPSec is handled once.
I used to get the home computer question.
But after I explain my home lab setup and some of the machines I keep around that run from Linux Appliances, Cobalt RAQ Appliances with CentOS and Solaris, or my Solaris Pizza Box that I installed Red Hat 6.0 on or just my run of the mill PC's with any various OS or some of my favorite tools.
Then we have the Cisco and other vendors gear. I stop after the eyes start to glaze, unless they want to know where I get my bogon lists from or where I find my latest 0-Day Exploits from and how I have acquired so many tools of the trade...
Hmmm...
Well, you know...
How are things going?
Did you ever decide to use Cisco Gear? Get your CCNA yet?
Are you in Orlando this week at SANS?
Later
Where are the answers to all the questions?
Nice compilation of questions....!!
You say, "As weak as the CISSP is as a security certification..."
This cert seems to be der rigeur in the industry for any security position. Almost all the jobs I apply for say it is desirable, required, or you must get certified within 6 months of hire. Why do you have such a low opinion of it? And, if it's so weak, why do they all want you to have it?
these questions sound very basic.... for jr security position.
what questions you would ask for pentester/sr sec analyst position?
thanks
Max