Computer Security Interview Questions

 
1.
What is a Firewall?
2.
What is Spyware?
3.
How can I avoid computer viruses?
4.
What is computer impersonation?
5.
What are privileges (user rights)?
6.
What is this (X) IDS signature mean?
7.
What is an ACL (Access Control List)?
8.
What makes a strong password?
9.
How can I avoid Spyware?
10.
How can I protect my home computer?
11.
I have been hearing a lot about firewalls, but I am not sure what it is or if I need it. Can you help?
12.
SEM/SIM Security information management questions
13.
Use the out put from any network security scanner, which ever network security scanner is used by the interviewer
14.
Where do I get patches, or, what is a Service Pack or a Hot Fix?
15.
What is a SID (Security ID)?
16.
What is an ACE (Access Control Entry)?
17.
What is SRM (Security Reference Monitor)?
18.
What is SAM (Security Account Manager)?
19.
What is an access token?
20.
Are there any NT based viruses, or can NT be susceptible for other viruses?
21.
Are there any known problems with the screen saver / screen lock program?
22.
Can my page file hold sensitive data?
23.
Administrator account
24.
Is it possible to use packet filters on an NT machine?
25.
What is Authenticode?
26.
What servers have TCP ports opened on my NT system? Or: Is netstat broken?
27.
What is a NULL session?
28.
FTP server security
29.
What is Shutdown.exe?
30.
There are several security issues related to ODBC usage
31.
By default, all auditing in Windows NT is turned off. You have to manually turn on auditing on whatever object you want audited. First off, you should have a policy for
32.
What is CryptoAPI?
33.
How do we �lock down� a new system?
34.
Password Management questions
35.
Software Maintenance questions
36.
Physical Security questions
37.
Wireless Security questions
38.
Intrusion Detection and Recovery questions
39.
Current Awareness of Security Issues questions
40.
What is to worry about Web Security?
41.
Are some operating systems more secure to use as platforms for Web servers than others?
42.
Are CGI scripts insecure?
43.
What general security precautions should I take?
44.
What is the URLScan Security Tool?
45.
What is the HFNetChk Security Tool?
46.
What do you see as the most critical and current threats effecting Internet accessible websites?
47.
What do you see as challenges to successfully deploying/monitoring web intrusion detection?
48.
What are the most important steps you would recommend for securing a new web server? Web application?
49.
What are some examples of you how you would attempt to gain access?
50.
What does this log entry indicate? How could you identify what the contents are of the hacked.htm file that the attacker is trying to upload?
51.
I am new to the Internet and have been hearing a lot about viruses. I am not exactly sure what they are. Can you help?
52.
What is the security threat level today at the Internet Storm Center (ISC)?
53.
Checking on the interviewees knowledge of legal issues and information security
54.
How well the person can do architecture from scratch?
55.
What is LSA (Local Security Authority)?
56.
What is a secure channel?
57.
Host security
58.
How do I get my computer C2-level secure, or, what is c2config?
59.
User security?
60.
Guest account
61.
Is NT susceptible to SYN flood attacks?
62.
What ports must I enable to let NBT (NetBios over TCP/IP) through my firewall?
63.
What should I think about when using SNMP?
64.
What are giant packets? Or, is Windows NT susceptible to the PING attack?
65.
Web server security
66.
What is Rollback.exe?
67.
What is AFTP, NVAlert and NVRunCmd?
68.
There are a number of things to do to get better security on remote connections
69.
Can I grant access to someone to view or change the logfiles?
70.
Where is the password that I configure a service to start with stored?
71.
Securing New Systems questions
72.
Anti-Virus questions
73.
Backups questions
74.
Network Security questions
75.
Data Security questions
76.
Disaster Recovery Planning questions
77.
Security interview questions for network admin questions
78.
Exactly what security risks are we talking about?
79.
Are some Web server software programs more secure than others?
80.
Are server-side includes insecure?
81.
How do I secure Windows 2000 and IIS 5.0?
82.
What is the IIS Lockdown Tool?
83.
What is the Microsoft Baseline Security Analyzer?
84.
What online resources do you use to keep abreast of web security issues? Can you give an example of a recent web security vulnerability or threat?
85.
Imagine that we are running an Apache reverse proxy server and one of the servers we are proxy for is a Windows IIS server. What does the log entry suggest has happened?
86.
What application generated the log file entry below? What type of attack is this?
87.
The file is called logon_validate and a typical logon request looks like this?
88.
How can I secure my client computers against my users?