Pre-Screening Interview Questions to Ask a Cyber Security Analyst Intern

Last updated on

At intern level nobody has incident experience, so the useful signal is fundamentals and judgement. These questions test both, plus whether they understand authorisation.

TL;DR, what to screen for

The best pre-screening questions for a cyber security analyst intern test four things: what they have actually built or broken rather than certifications collected, whether the fundamentals are genuinely understood, whether they escalate rather than act alone, and whether they understand that testing requires permission. Ask what they would do on finding something.

  • What they have done
  • Fundamentals understood
  • Escalates rather than acts
  • Authorisation understood

Why pre-screen security interns before the interview

Interns in this field arrive with either coursework or a home lab, and the difference matters less than one thing: whether they understand that scanning something without permission is not learning, it is an offence. Beyond that, the useful signal is whether the fundamentals are understood rather than memorised. A short screen tests both, and asks what they would do on finding something suspicious.

What actually matters when screening Cyber Security Analyst Intern candidates

  1. 01

    Technical depth

    Check hands-on exposure beyond coursework: Splunk or Wireshark labs, TryHackMe or Hack The Box paths, Security+ progress, Nmap scans, and reading a Windows Event log or firewall rule.

  2. 02

    Real incidents and findings

    Probe any real triage work: phishing reports escalated, home lab intrusion detection setups, CTF write-ups, university SOC placements, or vulnerability scans they ran and documented.

  3. 03

    Risk judgement

    Assess how they rank findings: can they explain why a critical CVSS score may still be low priority, or which phishing report warrants waking someone up?

  4. 04

    Getting things fixed

    Look for follow-through on remediation: patch tickets chased, awareness training material written, documentation updated, or a lab misconfiguration they reported and confirmed was fixed.

Pre-screening questions to ask Cyber Security Analyst Intern candidates

12 questions grouped by what they test. Ask the same set in every screen and score answers on a consistent scale, or send them as an async video screen and compare answers side by side.

What they have done

3 questions
  1. 01Can you describe projects or coursework you have completed relating to security?

    Listen for

    A home lab, capture the flag participation or a project they built, described with genuine detail.

    Coursework listed with no practical work, or projects described without any technical specifics.

  2. 02Do you have any prior experience in cyber security?

    Listen for

    Honest framing of limited experience, with what they have learned independently described clearly.

    Experience overstated for the level, or claims that do not match the technical answers given.

  3. 03Do you have experience with penetration testing tools, and in what setting?

    Listen for

    Tools used in a home lab or a deliberately vulnerable environment, with permission clearly understood.

    Any scanning or testing of systems they did not own or have written permission to test.

Fundamentals understood

4 questions
  1. 04Can you explain what a firewall does?

    Listen for

    An explanation in their own words covering rules and traffic direction, rather than a memorised definition.

    A recited definition with no understanding, or firewalls described as blocking all threats.

  2. 05Can you explain what a virtual private network is and how it works?

    Listen for

    Tunnelling and encryption explained plainly, with an accurate view of what it does and does not protect.

    Described as making someone anonymous, or the endpoints of the protection not understood.

  3. 06Do you know what intrusion detection and prevention systems do?

    Listen for

    The difference between detecting and blocking understood, with false positives recognised as a real problem.

    The two conflated, or no awareness that these systems generate noise as well as signal.

  4. 07How familiar are you with encryption and where it is used?

    Listen for

    Symmetric and asymmetric distinguished, with an understanding of what encryption does not protect against.

    Encryption treated as a general solution, or key management not recognised as the hard part.

Escalates rather than acts

2 questions
  1. 08How would you handle a situation where you detected a potential security threat?

    Listen for

    Report and escalate immediately, preserving evidence and not acting alone on a live system.

    Investigating further alone, or taking action on production systems without authorisation.

  2. 09What do you understand by ethical hacking?

    Listen for

    Written authorisation and defined scope raised immediately as what makes testing legitimate.

    Ethics framed as intent rather than permission, or scope treated as flexible.

Authorisation understood

3 questions
  1. 10How comfortable are you writing up findings for a non-technical audience?

    Listen for

    Willingness to write clearly about the consequence rather than the technique, with examples if any exist.

    Writing dismissed as unimportant, or explanations that stay technical regardless of audience.

  2. 11How do you keep up with security developments and new threats?

    Listen for

    Specific sources they actually follow, with a recent issue they can discuss in their own words.

    Generic sources named, or an inability to discuss anything recent in any detail.

  3. 12Are you familiar with any security frameworks or standards?

    Listen for

    Awareness of what a framework is for, with honesty about the depth of their familiarity.

    Frameworks listed with no understanding, or depth claimed that the answers do not support.

How to score responses

Score every candidate on the same four criteria immediately after the screen. At this stage you are shortlisting for panel interviews, not making the final call.

  1. Technical depth

    35%

    5Names specific tools used, walks through a log or packet capture they analysed, and links findings to MITRE ATT&CK techniques.

  2. Real incidents and findings

    30%

    5Describes a concrete alert or CTF challenge end to end, including what indicators they checked and what the outcome was.

  3. Risk judgement

    20%

    5Separates severity from business impact, asks about asset value and exposure, and admits when a call needs escalation to a senior analyst.

  4. Getting things fixed

    15%

    5Shows they tracked an issue until closed, wrote it up clearly for a non-security reader, and verified the fix rather than assuming it.

The one thing that matters at this level is understanding that testing needs permission. A one-way video screen checks it.

Try it on Hirevire

Screening FAQ

Process basics

How long should a pre-screening round for an intern take?

Ten minutes across eight questions, answered async. Enough to establish what they have built or studied, test the fundamentals, and check their instincts about authorisation and escalation.

How much should certifications count at this level?

Less than curiosity and judgement. Entry-level certifications show someone can pass an exam. A home lab, a capture the flag record or a project shows they actually enjoy the work.

Evaluating answers

What is the strongest signal when screening an intern here?

Escalating rather than investigating alone. Interns with sound instincts report what they find and stop. Anyone who describes digging further on their own initiative needs close supervision.

What should worry me in an answer?

Any suggestion of scanning or testing systems without permission, however casually described. That instinct at intern level becomes a serious liability once someone has real access.

Go deeper on this role

Sanat Hegde
Sanat Hegde
Founder, Hirevire

Sanat has been hiring since 2012 and watching the recruitment industry change up close ever since, and turned that screening process into Hirevire's video screening platform. LinkedIn

Trusted by 500+ Companies

Screen Cyber Security Analyst Intern candidates on Hirevire

Turn this question list into an async video screen in minutes. Every applicant answers the same fundamentals, judgement and authorisation questions on camera, so you compare instincts rather than certificates.