>_ CYBERVERSE.AI
SOC Analyst interview question
A workstation is encrypting files and beaconing outbound. Walk me through your ransomware response.
What interviewers are really testing
- Containment before curiosity - isolate first
- Evidence preservation and scope assessment
- Recovery realism: backups, verification, lessons
A strong answer framework
- Isolate the host from the network (keep power on to preserve memory)
- Confirm scope: other hosts, file shares, backup infrastructure
- Identify entry vector: phishing, RDP, vulnerable service
- Preserve evidence: memory and disk images, relevant logs
- Eradicate: reimage, rotate credentials, patch the entry vector
- Verify backups offline before recovery; involve IR, legal, comms
Follow-ups you should be ready for
- Do you pay the ransom? Who decides?
- How do you verify backups are clean?
- What changes if a server is hit instead of a workstation?
More real SOC Analyst interview questions