<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>danielmiessler.com - Latest Comments in 25 Questions to Ask During an Information Security Interview</title><link>http://drm.disqus.com/</link><description>https://danielmiessler.com/about/</description><atom:link href="https://drm.disqus.com/25_questions_to_ask_during_an_information_security_interview/latest.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Mon, 29 Aug 2011 17:07:15 -0000</lastBuildDate><item><title>Re: 25 Questions to Ask During an Information Security Interview</title><link>https://danielmiessler.com/blog/25-questions-to-ask-during-an-information-security-interview#comment-298008321</link><description>&lt;p&gt;Wow, that's scary.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Daniel Miessler</dc:creator><pubDate>Mon, 29 Aug 2011 17:07:15 -0000</pubDate></item><item><title>Re: 25 Questions to Ask During an Information Security Interview</title><link>https://danielmiessler.com/blog/25-questions-to-ask-during-an-information-security-interview#comment-297881551</link><description>&lt;p&gt;I am witness to many interviews of infosec professionals.  I've seen these exact questions (literally printed from your website) and asked VERY BADLY.  It's an important point that the interviewer fully understand and be able to answer these questions.  Otherwise, using them is a waste.  I witnessed a developer using these questions to interview an INFOSEC management candidate.  He asked the candidate the ping/port questions and the candidate answered correctly immediately - ICMP.  The interviewer said "no, you have to give me a tcp or udp port number".  The interviewee was clearly frustrated and rolling his eyes and trying to be polite.  I eventually stepped in and told the interviewer to take a break and I'd finish the interview.  Unreal!!!&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Security Monkey</dc:creator><pubDate>Mon, 29 Aug 2011 13:58:55 -0000</pubDate></item><item><title>Re: 25 Questions to Ask During an Information Security Interview</title><link>https://danielmiessler.com/blog/25-questions-to-ask-during-an-information-security-interview#comment-227230196</link><description>&lt;p&gt;I test them in the SANS 504 class" (or at a hackers conventiuon, or I set up a disposable network at home&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.autobidmaster.com/howtobuy-copart-auto-auctions/" rel="nofollow noopener" target="_blank" title="http://www.autobidmaster.com/howtobuy-copart-auto-auctions/"&gt;Car Auctions&lt;/a&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">BuyGiftsItems</dc:creator><pubDate>Thu, 16 Jun 2011 07:28:03 -0000</pubDate></item><item><title>Re: 25 Questions to Ask During an Information Security Interview</title><link>https://danielmiessler.com/blog/25-questions-to-ask-during-an-information-security-interview#comment-197311242</link><description>&lt;p&gt;Create a sandbox environment.. :D  &lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Random Nerd...</dc:creator><pubDate>Wed, 04 May 2011 23:35:43 -0000</pubDate></item><item><title>Re: 25 Questions to Ask During an Information Security Interview</title><link>https://danielmiessler.com/blog/25-questions-to-ask-during-an-information-security-interview#comment-100079557</link><description>&lt;p&gt;Umm, I'm not a security expert (just a random unix admin), but I could answer all of those questions.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jim</dc:creator><pubDate>Sat, 20 Nov 2010 11:45:31 -0000</pubDate></item><item><title>Re: 25 Questions to Ask During an Information Security Interview</title><link>https://danielmiessler.com/blog/25-questions-to-ask-during-an-information-security-interview#comment-83460813</link><description>&lt;p&gt;amazing list of questions!!! &lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ilango Al</dc:creator><pubDate>Sun, 03 Oct 2010 10:12:09 -0000</pubDate></item><item><title>Re: 25 Questions to Ask During an Information Security Interview</title><link>https://danielmiessler.com/blog/25-questions-to-ask-during-an-information-security-interview#comment-50170238</link><description>&lt;p&gt;Here is another question.  "How do you keep up on hacker tools, and how do you test them?".&lt;/p&gt;&lt;p&gt;The lower skill level answer would be, "I don't!  I swore I wouldn't associate with Hackers or use their tools when I got my CISSP!"  The "better" IMO &lt;br&gt;answer would be, "I use a sacrificial lamb computer to get them off The Net"&lt;br&gt;(because a lot of hacker sites will, in fact, hack you while you get the tool).&lt;br&gt;As for testing them, the best answer(s) might be "I test them in the SANS 504 class" (or at a hackers convention, or I set up a disposable network at home (or in a detached lab) so as to not be the cause of bringing down production or personal computers.  Bonus points for things like, "afterwards I do a 6 pass destructive format on my HD, including boot sectors, and reflash my BIOS from a LINUX booted OS disk, stuff like that.&lt;/p&gt;&lt;p&gt;Reading about them on a security site shows less enthusiasm.&lt;/p&gt;&lt;p&gt;"Know thy enemy"&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">dryanhawley</dc:creator><pubDate>Thu, 13 May 2010 16:02:55 -0000</pubDate></item><item><title>Re: 25 Questions to Ask During an Information Security Interview</title><link>https://danielmiessler.com/blog/25-questions-to-ask-during-an-information-security-interview#comment-46417440</link><description>&lt;p&gt;Diffie-Hellman is a Key-agreement scheme, it is not a Key-exchange scheme.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Hasib</dc:creator><pubDate>Sat, 24 Apr 2010 15:34:12 -0000</pubDate></item><item><title>Re: 25 Questions to Ask During an Information Security Interview</title><link>https://danielmiessler.com/blog/25-questions-to-ask-during-an-information-security-interview#comment-11211350</link><description>&lt;p&gt;@Curtis Thank you for that.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Daniel Miessler</dc:creator><pubDate>Sun, 23 Nov 2008 17:05:59 -0000</pubDate></item><item><title>Re: 25 Questions to Ask During an Information Security Interview</title><link>https://danielmiessler.com/blog/25-questions-to-ask-during-an-information-security-interview#comment-11211348</link><description>&lt;p&gt;A network analysis D&amp;amp;D? Ouch.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Nice list, Daniel. I think you should float all the easy questions to the top, so that you can vet the incompetent early in the process.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;What I like to ask a candidate is "what are you best at? what do people come to you about when they need help?" and then drill down into the bits and bytes on that topic. That shows me if they take what they do seriously enough to have an in-depth understanding of it. Also, at some point in time my questions inevitably exceed their knowledge (I might ask about things I don't know about...) and then I expect them to tell me they don't know and will find out. If they try to BS me... NEXT!&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;Also as mentioned I like to ask about the bigger picture, what does it all mean from an organizational point of view.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;-- Arik&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Arik</dc:creator><pubDate>Sun, 23 Nov 2008 16:30:15 -0000</pubDate></item><item><title>Re: 25 Questions to Ask During an Information Security Interview</title><link>https://danielmiessler.com/blog/25-questions-to-ask-during-an-information-security-interview#comment-11211345</link><description>&lt;p&gt;Nice list, lol&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">The Real Steve C</dc:creator><pubDate>Fri, 21 Nov 2008 23:50:59 -0000</pubDate></item><item><title>Re: 25 Questions to Ask During an Information Security Interview</title><link>https://danielmiessler.com/blog/25-questions-to-ask-during-an-information-security-interview#comment-11211344</link><description>&lt;p&gt;This is great stuff!  I've had to argue with seasoned security professionals about DH being subject to MITM.  A great follow up on that, they they miss it, is have them whiteboard for you how it works and then watch to see how they react when you white board the key switch.  If you see the light bulb go on, they may still be OK.  Even professionals take the pre-established trust of a local keystore for granted.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Mark Gamache</dc:creator><pubDate>Fri, 21 Nov 2008 12:10:03 -0000</pubDate></item><item><title>Re: 25 Questions to Ask During an Information Security Interview</title><link>https://danielmiessler.com/blog/25-questions-to-ask-during-an-information-security-interview#comment-11211342</link><description>&lt;p&gt;My favorite question is "Prove to me you can protect my network".  Poor candidates begin speaking about technology and solutions, good candidates talk about their previous experience, and great candidates take a high level view of the issue and speak about how they will help promote change, get management on board and begin to address the true scope of this open ended question.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Scott</dc:creator><pubDate>Fri, 21 Nov 2008 09:02:36 -0000</pubDate></item><item><title>Re: 25 Questions to Ask During an Information Security Interview</title><link>https://danielmiessler.com/blog/25-questions-to-ask-during-an-information-security-interview#comment-11211339</link><description>&lt;p&gt;Nice list. I've weeded people out before with the ping, tracert, and http vs html questions before.  Good stuff!&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">randy</dc:creator><pubDate>Fri, 21 Nov 2008 08:39:25 -0000</pubDate></item></channel></rss>