Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 25 guests online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Career Centralarrow Questions asked in my interview
Ethical Hacker Community Forums
November 20, 2008, 04:11:29 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1] 2   Go Down
  Print  
Author Topic: Questions asked in my interview  (Read 14894 times)
0 Members and 1 Guest are viewing this topic.
blackazarro
Full Member
***
Offline Offline

Posts: 221



View Profile
« on: September 01, 2007, 05:04:25 AM »

Hello everyone, last week or so I saw a local advertisement for a job opening as an Information Security Specialist. The job description included knowledge of TCP/IP, Security Monitoring/Analysis, Pentesting, Computer Forensic, configuring and administering Firewall/NIDS and etc. The company that posted the ad is a well known financial corporation where I live and well... I decided to submit my resume and see what it has to offer.

That same week I quickly received a call from the company and a date was schedule for the interview. In my day of the interview I met with the CISO (Chief Information Security Officer) and the following technical were asked:

- Explain TCP/IP and mention its layers.
- Explain layer 2 of the OSI model.
- Explain layer 3 of the OSI model.
- Difference between TCP and UDP.
- Difference between Telnet and SSH.
- How does SSH encrypts the data?
- Explain how fragmentation occurs within a network.
- Define Malware?
- What is a sniffer and what is it used for?
- What is Netcat and what is it used for?
- What is a Buffer Overflow and what is it used for?
- The interviewer drew a diagram on a piece of paper consisting of two machines in a LAN, a Gateway and a Web Server in the Internet hosting a financial site via HTTPS. Explain how an attacker (Machine A) could sniff traffic from victim (Machine B) and is the attacker able to see the encrypted data and how was this accomplished. How can the victim know that he was being attacked by the attacker?

I did pretty good and answered all the questions. He was somewhat impressed. He told me that I was the first to answer all the questions and that I'm the person he was looking for. He went on saying that these questions were easy, however, the candidates he interviewed that day were having difficulty answering them.

Well, now I just have to wait and see if I get the job offer and if the salary and compensation package is better than my current job.
« Last Edit: September 01, 2007, 05:06:14 AM by blackazarro » Logged

Security+, OSCP, CEH
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2347


Editor-In-Chief


View Profile WWW
« Reply #1 on: September 01, 2007, 06:48:16 PM »

Great post.

Not only is it great to see that there are employers out there checking candidates properly, but it is also good to know what they're asking.

There will always be the braindump type of mentality that will memorize the questions you posted before they go into their next interview, but I think most here will understand that the questions to these basic questions need to be known.

Is it necessary to know everything about a job before you go for it... no. But there should be some good general knowledge going in.

Keep us posted. We're all interested in how this turns out.

Don
Logged

CISSP, MCSE, CEH, Security+ SME
BillV
Hero Member
*****
Offline Offline

Posts: 862


View Profile
« Reply #2 on: September 02, 2007, 02:40:42 PM »

Wow, yeah that's really interesting.

Out of curiosity, were you asked about your certifications at all? I've seen either in other posts here, or elsewhere, that sometimes people don't understand the CEH and may question it. Just wondering if the CISO had asked about that or the OSCP at all and what that conversation included.

Good luck with the job and all, hope it works out! Keep us informed Smiley
Logged
blackazarro
Full Member
***
Offline Offline

Posts: 221



View Profile
« Reply #3 on: September 02, 2007, 06:15:56 PM »

Hey thanks...

and yeah, the CISO did recognized all of my certs and especially the OSCP. He mentioned that he uses BackTrack for his pentesting and he knew about Offensive Security 101 course. Other than that he really didn't delve into asking about my certs, he just started blasting technical questions at me. However, it appeared that he does value certs. This was evident in their job posting. It mentioned that they would preferred a candidate with a CISSP cert. I don't have this yet but I'm definitely going to take it in the near future. Hopefully, with the certs I currently hold will make up for the lack of the CISSP.

The CISO was not the only person I was interviewed, I also met with one of their company's HR managers. Now she was really intrigued about my certs and ask a lot of questions about it. Like for example, where have I taken the courses and what the certifications meant. Surprisingly, she was so interested because she has a son that just recently graduated from College majoring in Computer Science. She one way or another acknowledged that having certifications is important for today's IT professional. She than began asking for my advice for her son on how to obtain certifications. I basically gave pointers on local technical schools that offer certification review courses and importantly pointing out to her that the certs I hold pertains to security. I wanted to clarify this so I told her that her son should go after certifications that are based on his interest and focus solely on those that are relevant to the career path he wants to take. She didn't mention to me if her son was into Computer Security. Anyways, the interview with HR went smoothly and I was fortunate to had been interview by someone who was down to earth and had interest in the subject matter.

Well now I just have to wait and see if they send me a job offer. I will definitely keep you guys posted.
« Last Edit: September 11, 2007, 02:24:29 PM by blackazarro » Logged

Security+, OSCP, CEH
oleDB
Full Member
***
Offline Offline

Posts: 231



View Profile WWW
« Reply #4 on: September 07, 2007, 03:51:39 PM »

Sounds like you have something promising going, congrats! let us know how it turns out.

I recently interviewed for a security opening and for the first time ever I was given a written Perl exam. Some of it was really basic, but there were large sections of code and sytax that I had to analyze and write out what it was doing and also I had to write out code myself. I think I got about an 80% on it, however what was odd, what that nowhere in the Job req did it mention perl.
Kinda of strange, and the panel interviews were just a nonstop technical barrage of really specific questions, not just explain what a firewall is or something lame like that. I was so impressed with their interview, it would be really hard to turn down an offer from them if I got it. Oh well, will wait and see.
Logged
blackazarro
Full Member
***
Offline Offline

Posts: 221



View Profile
« Reply #5 on: September 11, 2007, 02:06:55 PM »


Good luck oleDB! I hope everything goes well for you. The job does sound promising.

Well, anyways, today I received a call from the HR manager and she said I was chosen for the job position. She set an appointment to discuss salary and such. Let see how it goes. Got to polish my negotiating skills, lol.



Logged

Security+, OSCP, CEH
oleDB
Full Member
***
Offline Offline

Posts: 231



View Profile WWW
« Reply #6 on: September 11, 2007, 02:25:44 PM »

Awesome, congrats!
Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2347


Editor-In-Chief


View Profile WWW
« Reply #7 on: September 11, 2007, 03:11:57 PM »

Congrats!!
Cool
Don
Logged

CISSP, MCSE, CEH, Security+ SME
blackazarro
Full Member
***
Offline Offline

Posts: 221



View Profile
« Reply #8 on: September 11, 2007, 05:04:54 PM »


Thanks!!  Grin
Logged

Security+, OSCP, CEH
oasis_inin
Newbie
*
Offline Offline

Posts: 20


View Profile
« Reply #9 on: September 13, 2007, 11:35:29 AM »

Many Congrats!!!!!!!!!! Smiley
Logged

CISSP, MCSE Sec, Security +
studying for C|EH
blackazarro
Full Member
***
Offline Offline

Posts: 221



View Profile
« Reply #10 on: September 13, 2007, 12:51:45 PM »


Thanks again, I'm currently at the negotiating table. Let see what happens.
Logged

Security+, OSCP, CEH
squidmaster
Newbie
*
Offline Offline

Posts: 21


View Profile
« Reply #11 on: September 13, 2007, 06:30:20 PM »

Good luck mate!

That was a much harder job interview than mine.
Mine was: I walk in.
"How are you doing?"
"Greatttt... So you know about computers?"
"Yes sir I do."
"Greatttt.... So when can you start?"

and I have just moved up from there.
Logged
blackazarro
Full Member
***
Offline Offline

Posts: 221



View Profile
« Reply #12 on: September 26, 2007, 12:46:15 PM »


Finally after some negotiating I got the job!! I'm excited and looking forward to work for this company. Their security department is new and a lot of work needs to be done. Let see how it goes.
Logged

Security+, OSCP, CEH
LK
Newbie
*
Offline Offline

Posts: 20


View Profile
« Reply #13 on: September 26, 2007, 02:43:24 PM »

Congratulations blackzarro!

Good luck with your new position!

Logged

Security+,OSCP
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2347


Editor-In-Chief


View Profile WWW
« Reply #14 on: September 26, 2007, 04:17:41 PM »

Well done.

Sounds like there's an article in there somewhere...  Undecided

Don
Logged

CISSP, MCSE, CEH, Security+ SME
Pages: [1] 2   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.047 seconds with 24 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.