Why pre-screen security interns before the interview
Interns in this field arrive with either coursework or a home lab, and the difference matters less than one thing: whether they understand that scanning something without permission is not learning, it is an offence. Beyond that, the useful signal is whether the fundamentals are understood rather than memorised. A short screen tests both, and asks what they would do on finding something suspicious.
What actually matters when screening Cyber Security Analyst Intern candidates
- 01
Technical depth
Check hands-on exposure beyond coursework: Splunk or Wireshark labs, TryHackMe or Hack The Box paths, Security+ progress, Nmap scans, and reading a Windows Event log or firewall rule.
- 02
Real incidents and findings
Probe any real triage work: phishing reports escalated, home lab intrusion detection setups, CTF write-ups, university SOC placements, or vulnerability scans they ran and documented.
- 03
Risk judgement
Assess how they rank findings: can they explain why a critical CVSS score may still be low priority, or which phishing report warrants waking someone up?
- 04
Getting things fixed
Look for follow-through on remediation: patch tickets chased, awareness training material written, documentation updated, or a lab misconfiguration they reported and confirmed was fixed.
Pre-screening questions to ask Cyber Security Analyst Intern candidates
12 questions grouped by what they test. Ask the same set in every screen and score answers on a consistent scale, or send them as an async video screen and compare answers side by side.
What they have done
3 questions01Can you describe projects or coursework you have completed relating to security?
Listen forA home lab, capture the flag participation or a project they built, described with genuine detail.
Coursework listed with no practical work, or projects described without any technical specifics.
02Do you have any prior experience in cyber security?
Listen forHonest framing of limited experience, with what they have learned independently described clearly.
Experience overstated for the level, or claims that do not match the technical answers given.
03Do you have experience with penetration testing tools, and in what setting?
Listen forTools used in a home lab or a deliberately vulnerable environment, with permission clearly understood.
Any scanning or testing of systems they did not own or have written permission to test.
Fundamentals understood
4 questions04Can you explain what a firewall does?
Listen forAn explanation in their own words covering rules and traffic direction, rather than a memorised definition.
A recited definition with no understanding, or firewalls described as blocking all threats.
05Can you explain what a virtual private network is and how it works?
Listen forTunnelling and encryption explained plainly, with an accurate view of what it does and does not protect.
Described as making someone anonymous, or the endpoints of the protection not understood.
06Do you know what intrusion detection and prevention systems do?
Listen forThe difference between detecting and blocking understood, with false positives recognised as a real problem.
The two conflated, or no awareness that these systems generate noise as well as signal.
07How familiar are you with encryption and where it is used?
Listen forSymmetric and asymmetric distinguished, with an understanding of what encryption does not protect against.
Encryption treated as a general solution, or key management not recognised as the hard part.
Escalates rather than acts
2 questions08How would you handle a situation where you detected a potential security threat?
Listen forReport and escalate immediately, preserving evidence and not acting alone on a live system.
Investigating further alone, or taking action on production systems without authorisation.
09What do you understand by ethical hacking?
Listen forWritten authorisation and defined scope raised immediately as what makes testing legitimate.
Ethics framed as intent rather than permission, or scope treated as flexible.
Authorisation understood
3 questions10How comfortable are you writing up findings for a non-technical audience?
Listen forWillingness to write clearly about the consequence rather than the technique, with examples if any exist.
Writing dismissed as unimportant, or explanations that stay technical regardless of audience.
11How do you keep up with security developments and new threats?
Listen forSpecific sources they actually follow, with a recent issue they can discuss in their own words.
Generic sources named, or an inability to discuss anything recent in any detail.
12Are you familiar with any security frameworks or standards?
Listen forAwareness of what a framework is for, with honesty about the depth of their familiarity.
Frameworks listed with no understanding, or depth claimed that the answers do not support.
How to score responses
Score every candidate on the same four criteria immediately after the screen. At this stage you are shortlisting for panel interviews, not making the final call.
Technical depth
35%5Names specific tools used, walks through a log or packet capture they analysed, and links findings to MITRE ATT&CK techniques.
Real incidents and findings
30%5Describes a concrete alert or CTF challenge end to end, including what indicators they checked and what the outcome was.
Risk judgement
20%5Separates severity from business impact, asks about asset value and exposure, and admits when a call needs escalation to a senior analyst.
Getting things fixed
15%5Shows they tracked an issue until closed, wrote it up clearly for a non-security reader, and verified the fix rather than assuming it.
The one thing that matters at this level is understanding that testing needs permission. A one-way video screen checks it.
Try it on HirevireScreening FAQ
Process basics
How long should a pre-screening round for an intern take?
Ten minutes across eight questions, answered async. Enough to establish what they have built or studied, test the fundamentals, and check their instincts about authorisation and escalation.
How much should certifications count at this level?
Less than curiosity and judgement. Entry-level certifications show someone can pass an exam. A home lab, a capture the flag record or a project shows they actually enjoy the work.
Evaluating answers
What is the strongest signal when screening an intern here?
Escalating rather than investigating alone. Interns with sound instincts report what they find and stop. Anyone who describes digging further on their own initiative needs close supervision.
What should worry me in an answer?
Any suggestion of scanning or testing systems without permission, however casually described. That instinct at intern level becomes a serious liability once someone has real access.
























