>_ CYBERVERSE.AI
SOC Analyst interview question
How do you detect C2 beaconing in proxy or firewall logs?
What interviewers are really testing
- Interval-regularity analysis thinking
- Volume and domain-reputation signals
- Practical query ideas
A strong answer framework
- Periodic callbacks: consistent intervals with small jitter
- Small, consistent payload sizes; low-volume heartbeats
- Rare, newly-registered, or low-prevalence destinations
- Cluster by host+destination; compute interval deviation
- Correlate with DNS and process creation before escalating
Follow-ups you should be ready for
- What interval patterns do real beacons use?
- How do you separate beacons from SaaS polling?
More real SOC Analyst interview questions