Security Interview Questions
Questions Answers Views Company eMail

 Why would you want to use SSH from a Windows pc?

1 850

What’s the difference between Symmetric and Asymmetric encryption?

1 474

What is SSL and why is it not enough when it comes to encryption?

1 747

 How would you find out what a POST code means?

1 537

 What is the difference between a Black Hat and a White Hat?

1 525

You need to reset a password-protected BIOS configuration. What do you do?

1 380

What is XSS?

1 491

How would you login to Active Directory from a Linux or Mac box?


 What are salted hashes?

1 436

What do you think of social networking sites such as Facebook and LinkedIn?

1 432

What are the three ways to authenticate a person?

1 1351

How would you judge if a remote server is running IIS or Apache?

1 1049

What is data protection in transit vs data protection at rest?

1 833

 You see a user logging in as root to perform basic functions. Is this a problem?

1 898

How do you protect your home Wireless Access Point?

1 447

Un-Answered Questions { Security }

1. Assume that passwords are selected from four-character combination of 26 alphabetic characters. Assume that an adversary is able to attempt passwords at a rate of one per second. a. Assuming no feedback to the adversary until each attempt has been completed, what is the expected time to recover the correct password? b. Assuming feedback to the adversary flagging an error as each incorrect character is entered, what is the expected time to discover the correct password?


I run an SMB. I have 4 people in my entire company and a web-based store. I don’t have the time, patience or manpower to have a computer guy. Why should I care about exploits and computer jibberish?


A phonetic password generator picks two segments randomly for each six-letter password. The form of each segment is CVC (consonant, vowel, consonant), where V= < a, e, i, o, u > and C = (V.) ̅ What is the total password population? What is the probability of an adversary guessing a password correctly?


I’m the CEO of a Fortune 500 company. I make more in an afternoon than you make in a year. I don’t care about this stupid security stuff, it just costs time and money and slows everything down. Why should I care about this junk?


What is residual risk?


Explain what is Brute Force Hack?


 Explain what is DOS (Denial of service) attack? What are the common forms of DOS attack?


How would you permanently remove the threat of data falling into the wrong hands?


How would you login to Active Directory from a Linux or Mac box?


 What is Exfiltration?


explain step by step role design process in sap security


What is dora process in DHCP and how it works?


what is the use of scul transaction in sap security in ecc server?


 What is footprinting in ethical hacking? What is the techniques used for footprinting?


what is the role in sap security?