Easy to average cyber security questions. Some questions are scenario-based, Questions like the difference between session fixation and session hijacking. 2) what are the tools used 3) Is HTTP a stateless or stateful protocol and why? 3) Different options on Burpsuite 4) What steps do you follow for security testing? 5) can you perform DDOS attack with Burpsuite and how? 6)Explain roles and responsibilities 7)Types of penetration testing 9) Why do we use Nmap? 10) XSS and Types 11) if a website allows forward and back ward navigation, what type of vulnerability it has?
Penetration Testing Interview Questions
28 penetration testing interview questions shared by candidates
As I said, most of em where from my resume (what ever tools I know/used, how they work etc.). And some general questions (whats and hows about cyber security methods, techniques, attacks types etc.)
Tell me about that how will you perform IDOR testing for the web application.
Can u explain me about privilege escalation?
Symmetric vs Asymmetric cryptography? Encryption vs Signing? Is it possible for encryption to take place without signing?
Web authentication,SSRF,CSRF,Scripting,Java code review,XSS,TLS handshake,encryption.Needed to have a very deep understanding of those.
Tell me more about yourself.
Tell me about your workflow.
SQL injection and XSS cause and fix
What is XSS and how to mitigate it
Viewing 11 - 20 interview questions