<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: IT/Information Security Interview Questions</title>
	<atom:link href="http://www.myinfosecjob.com/2010/03/itinformation-security-interview-questions/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.myinfosecjob.com/2010/03/itinformation-security-interview-questions/</link>
	<description>Your reliable source for Information Security - Risk Management - Compliance jobs around the world</description>
	<lastBuildDate>Wed, 04 Apr 2012 20:04:59 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Goli</title>
		<link>http://www.myinfosecjob.com/2010/03/itinformation-security-interview-questions/comment-page-1/#comment-5425</link>
		<dc:creator>Goli</dc:creator>
		<pubDate>Tue, 14 Feb 2012 17:33:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.myinfosecjob.com/?p=2026#comment-5425</guid>
		<description>I was asked these questions: 

- what is CSRF attack? 
- what is the difference of pen testing and vulnerability assessment? 
- what is the security implication of using mobile devices for enterprises? 
- what security threats the social networking sites bring to enterprises? 
- How do you convince the managers at the client company that they need to adhere to some security standards or best practices?</description>
		<content:encoded><![CDATA[<p>I was asked these questions: </p>
<p>- what is CSRF attack?<br />
- what is the difference of pen testing and vulnerability assessment?<br />
- what is the security implication of using mobile devices for enterprises?<br />
- what security threats the social networking sites bring to enterprises?<br />
- How do you convince the managers at the client company that they need to adhere to some security standards or best practices?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Riyaz</title>
		<link>http://www.myinfosecjob.com/2010/03/itinformation-security-interview-questions/comment-page-1/#comment-5422</link>
		<dc:creator>Riyaz</dc:creator>
		<pubDate>Wed, 25 Jan 2012 14:31:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.myinfosecjob.com/?p=2026#comment-5422</guid>
		<description>Very informative, keep up the good work Folks....</description>
		<content:encoded><![CDATA[<p>Very informative, keep up the good work Folks&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Samarth</title>
		<link>http://www.myinfosecjob.com/2010/03/itinformation-security-interview-questions/comment-page-1/#comment-5421</link>
		<dc:creator>Samarth</dc:creator>
		<pubDate>Sun, 22 Jan 2012 16:12:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.myinfosecjob.com/?p=2026#comment-5421</guid>
		<description>Hi,

I am student of Information security. One day when I was preparing for jobs interview I came across your articles. These are very helpful and knowledgeable for some one in this field. Thanks for sharing your experience.
Keep up the good work.

Samarth Sharma</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>I am student of Information security. One day when I was preparing for jobs interview I came across your articles. These are very helpful and knowledgeable for some one in this field. Thanks for sharing your experience.<br />
Keep up the good work.</p>
<p>Samarth Sharma</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Samarth</title>
		<link>http://www.myinfosecjob.com/2010/03/itinformation-security-interview-questions/comment-page-1/#comment-5420</link>
		<dc:creator>Samarth</dc:creator>
		<pubDate>Sun, 22 Jan 2012 16:09:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.myinfosecjob.com/?p=2026#comment-5420</guid>
		<description>Hi,

I am student of Information security. One day when I was preparing for jobs interview I came across your articles. These are very helpful and knowledgeable for some one in this field. Thanks for hiring for experience.
Keep up the good work.

Samarth Sharma</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>I am student of Information security. One day when I was preparing for jobs interview I came across your articles. These are very helpful and knowledgeable for some one in this field. Thanks for hiring for experience.<br />
Keep up the good work.</p>
<p>Samarth Sharma</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: varun</title>
		<link>http://www.myinfosecjob.com/2010/03/itinformation-security-interview-questions/comment-page-1/#comment-5394</link>
		<dc:creator>varun</dc:creator>
		<pubDate>Sat, 19 Nov 2011 01:06:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.myinfosecjob.com/?p=2026#comment-5394</guid>
		<description>really a good blog
Thnks so much</description>
		<content:encoded><![CDATA[<p>really a good blog<br />
Thnks so much</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeff</title>
		<link>http://www.myinfosecjob.com/2010/03/itinformation-security-interview-questions/comment-page-1/#comment-4263</link>
		<dc:creator>Jeff</dc:creator>
		<pubDate>Fri, 30 Sep 2011 16:54:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.myinfosecjob.com/?p=2026#comment-4263</guid>
		<description>Description of a TCP 3-way Handshake:
the three-way (or 3-step) handshake occurs:

1. SYN: The active open is performed by the client sending a SYN to the server. It sets the segment&#039;s sequence number to a random value A.
2. SYN-ACK: In response, the server replies with a SYN-ACK. The acknowledgment number is set to one more than the received sequence number (A + 1), and the sequence number that the server chooses for the packet is another random number, B.
  3.  ACK: Finally, the client sends an ACK back to the server. The sequence number is set to the received acknowledgement value i.e. A + 1, and the acknowledgement number is set to one more than the received sequence number i.e. B + 1.

At this point, both the client and server have received an acknowledgment of the connection.</description>
		<content:encoded><![CDATA[<p>Description of a TCP 3-way Handshake:<br />
the three-way (or 3-step) handshake occurs:</p>
<p>1. SYN: The active open is performed by the client sending a SYN to the server. It sets the segment&#8217;s sequence number to a random value A.<br />
2. SYN-ACK: In response, the server replies with a SYN-ACK. The acknowledgment number is set to one more than the received sequence number (A + 1), and the sequence number that the server chooses for the packet is another random number, B.<br />
  3.  ACK: Finally, the client sends an ACK back to the server. The sequence number is set to the received acknowledgement value i.e. A + 1, and the acknowledgement number is set to one more than the received sequence number i.e. B + 1.</p>
<p>At this point, both the client and server have received an acknowledgment of the connection.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Unemployed Guy</title>
		<link>http://www.myinfosecjob.com/2010/03/itinformation-security-interview-questions/comment-page-1/#comment-2876</link>
		<dc:creator>Unemployed Guy</dc:creator>
		<pubDate>Sat, 20 Aug 2011 23:07:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.myinfosecjob.com/?p=2026#comment-2876</guid>
		<description>Thanks for the post Adriano, I think I came across this site just on time! 

I REALLY HAVE A QUESTION) I am going to have an Interview with a COO over the phone with a InfoSec company!!!!!!!  I have no idea how the phone interview with a hiring manager would convey my qualification? Can someone help?? 

I hope someone can answer my question
------------------------------------------------------------------------------------------------------------------------------------------

@Mark: I found your questions very interesting and I totally agree with you, “Your question covers a broad spectrum in the area of Networking/ Security” I personally would answer it in scenario format.

In my career I’ve interviewed handful of Tire 1 and 2 Desktop Support personnel. What I used and will always ask are

1)	 Would you please explain what happens when computer user hit the browser and type www.google.com”, or 
2)	 would you please explain as much detail as you can what will happen when you hit the Send button on your email”</description>
		<content:encoded><![CDATA[<p>Thanks for the post Adriano, I think I came across this site just on time! </p>
<p>I REALLY HAVE A QUESTION) I am going to have an Interview with a COO over the phone with a InfoSec company!!!!!!!  I have no idea how the phone interview with a hiring manager would convey my qualification? Can someone help?? </p>
<p>I hope someone can answer my question<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>@Mark: I found your questions very interesting and I totally agree with you, “Your question covers a broad spectrum in the area of Networking/ Security” I personally would answer it in scenario format.</p>
<p>In my career I’ve interviewed handful of Tire 1 and 2 Desktop Support personnel. What I used and will always ask are</p>
<p>1)	 Would you please explain what happens when computer user hit the browser and type <a href="http://www.google.com”" rel="nofollow">http://www.google.com”</a>, or<br />
2)	 would you please explain as much detail as you can what will happen when you hit the Send button on your email”</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: saravanan</title>
		<link>http://www.myinfosecjob.com/2010/03/itinformation-security-interview-questions/comment-page-1/#comment-2710</link>
		<dc:creator>saravanan</dc:creator>
		<pubDate>Sun, 14 Aug 2011 04:53:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.myinfosecjob.com/?p=2026#comment-2710</guid>
		<description>As the name says TCP 3 Way Handshake is a process of securely accessing a network connection between a Host machine and a Server for reliable connectivity. 
this can be done by sending TCP SYN (synchronize) request from a Host machine to a remote server 
the server in return will send back SYN ACK packet and wait for ACK packet from the sender
once the ACK packet is received by the server the connection is established.</description>
		<content:encoded><![CDATA[<p>As the name says TCP 3 Way Handshake is a process of securely accessing a network connection between a Host machine and a Server for reliable connectivity.<br />
this can be done by sending TCP SYN (synchronize) request from a Host machine to a remote server<br />
the server in return will send back SYN ACK packet and wait for ACK packet from the sender<br />
once the ACK packet is received by the server the connection is established.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adriano Dias Leite</title>
		<link>http://www.myinfosecjob.com/2010/03/itinformation-security-interview-questions/comment-page-1/#comment-2706</link>
		<dc:creator>Adriano Dias Leite</dc:creator>
		<pubDate>Sat, 13 Aug 2011 01:18:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.myinfosecjob.com/?p=2026#comment-2706</guid>
		<description>Great points, Mark! 
That&#039;s definitely a good strategy to &quot;extract the juice&quot; from someone! :)

Adriano</description>
		<content:encoded><![CDATA[<p>Great points, Mark!<br />
That&#8217;s definitely a good strategy to &#8220;extract the juice&#8221; from someone! <img src='http://www.myinfosecjob.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Adriano</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://www.myinfosecjob.com/2010/03/itinformation-security-interview-questions/comment-page-1/#comment-2704</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Thu, 11 Aug 2011 23:50:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.myinfosecjob.com/?p=2026#comment-2704</guid>
		<description>After a few &quot;softball&quot; questions, like &quot;describe TCP 3-way handshake&quot;, &quot;describe OSI Model&quot;, and &quot;PID for init (linux)&quot;, I generally use a compund question that really helps me understand that level of understanding a candidate has with Infosec (question set provided to me by one of my Mentors...thanks Dave).

This 3 part question can only be useful if the &quot;OSI Model&quot; question is answered correctly. If not, the interview is pretty much over.

Question 1 of 3: 
What&#039;s the difference between vulnerability and mitigation? (sounds simple enough, but it gets better).

Question 2 of 3:
Give me an example of a vulnerability at each layer of the OSI reference model.

Question 3 of 3:
Give me a type of mitigation for each of the vulnerabilities you have just provided.

I have rarely come across an individual who can handle these questions off the top of their head. I&#039;ve been in this industry for over 10 years and I have to sit down and think about them carefully. The point is to observe how the candidate can deduce the correct responses and show their depth across the OSI layers. As each layer delves into various areas of infrastructure and applications, this knowledge really shows someone&#039;s &quot;chops&quot; in the industry.

I never expect someone to knock them out, but obviously the more responses provided the more rounded the candidate is.

Mark</description>
		<content:encoded><![CDATA[<p>After a few &#8220;softball&#8221; questions, like &#8220;describe TCP 3-way handshake&#8221;, &#8220;describe OSI Model&#8221;, and &#8220;PID for init (linux)&#8221;, I generally use a compund question that really helps me understand that level of understanding a candidate has with Infosec (question set provided to me by one of my Mentors&#8230;thanks Dave).</p>
<p>This 3 part question can only be useful if the &#8220;OSI Model&#8221; question is answered correctly. If not, the interview is pretty much over.</p>
<p>Question 1 of 3:<br />
What&#8217;s the difference between vulnerability and mitigation? (sounds simple enough, but it gets better).</p>
<p>Question 2 of 3:<br />
Give me an example of a vulnerability at each layer of the OSI reference model.</p>
<p>Question 3 of 3:<br />
Give me a type of mitigation for each of the vulnerabilities you have just provided.</p>
<p>I have rarely come across an individual who can handle these questions off the top of their head. I&#8217;ve been in this industry for over 10 years and I have to sit down and think about them carefully. The point is to observe how the candidate can deduce the correct responses and show their depth across the OSI layers. As each layer delves into various areas of infrastructure and applications, this knowledge really shows someone&#8217;s &#8220;chops&#8221; in the industry.</p>
<p>I never expect someone to knock them out, but obviously the more responses provided the more rounded the candidate is.</p>
<p>Mark</p>
]]></content:encoded>
	</item>
</channel>
</rss>

