>_ CYBERVERSE.AI

SOC Analyst interview question

A domain controller is making outbound connections to an external IP on port 443. No maintenance is scheduled. How do you investigate?

What interviewers are really testing

A strong answer framework

  1. Validate: confirm source host, process, user context via EDR/Sysmon
  2. Enrich the destination IP with threat intel and DNS logs
  3. Scope: new services, scheduled tasks, odd logons, other hosts hitting the IP
  4. Contain: block destination, isolate DC, preserve memory and logs
  5. Eradicate: remove persistence, reset creds (KRBTGT if touched), rebuild if needed
  6. Document the timeline and recommend: no direct internet access from DCs

Follow-ups you should be ready for

Reading answers is not the same as defending them.
Practice this question live with an AI interviewer that scores you out of 100.

Practice this question free at CyberVerse AI →

More real SOC Analyst interview questions