Capability evidence
Assess one defensive question from source coverage to an owned response.
A dashboard tour and alert count are weak hiring evidence. Use a case with an incomplete asset record, a delayed source, a plausible benign explanation, a vulnerable component and a containment option that could harm the service.
01Assets, identities, telemetry, logging, and detection coverage
Provide conflicting inventories, several log sources and a request for complete monitoring. Ask the person to define the questions the evidence can and cannot answer.
Confirm: The person begins with protected business and service outcomes; maps assets, versions, owners, identities, privileges, data, dependencies, environments and trust boundaries; distinguishes inventory presence from current deployment and exposure; identifies endpoint, identity, network, DNS, cloud control plane, application, API, database, data access, security tool, supplier and physical signals according to risk; gives each source a purpose and owner; records event producer, collection path, schema, normalization, timestamp semantics, timezone, clock quality, correlation identifiers, retention, expected volume, latency, loss, access and integrity controls; avoids secrets and unnecessary content; protects logs from unauthorized change; monitors collector and source health; defines blind spots and degraded operation; links telemetry to specific threat and incident questions; and tests that representative safe activity reaches the expected detection and investigation path.
02Detection hypotheses, triage, investigation, and evidence
Provide a noisy rule, several related identities, incomplete logs and a recent approved change. Ask for an investigation that keeps observation separate from conclusion.
Confirm: The person states the behavior or control failure a detection seeks rather than relying on a signature name; records scope, required sources, analytic logic, baseline, expected false positives, severity, confidence and escalation; distinguishes raw event, enriched event, alert, case and confirmed incident; deduplicates without erasing recurrence; validates source health before trusting absence; checks asset identity role geography time change and business context; pivots across independent endpoint identity network cloud application and data evidence; preserves original records, queries and collection time; builds a normalized timeline while retaining source timestamps; distinguishes observation, indicator, hypothesis, corroborated finding, alternative explanation and attribution; limits collection to the mandate; records missing or contradictory evidence; communicates confidence and potential impact; and closes or escalates with a reason that another analyst can reproduce.
03Vulnerability, exposure, threat, and remediation analysis
Provide a scanner export, vendor advisory, base severity score, exploitation signal and incomplete deployment data. Ask what should actually happen next.
Confirm: The person confirms product, component, version, package, location and asset ownership; distinguishes installed from loaded, reachable, exposed and exploitable; validates scan identity and evidence; checks vendor status, configuration, compensating controls, privileges, attack path, data and operational consequence; uses CVE and weakness identifiers as references rather than local proof; separates CVSS Base, Threat, Environmental and Supplemental context; treats known exploitation and EPSS as distinct prioritization inputs rather than certainties; records source version and time; identifies affected population and inventory gaps; proposes update, configuration, isolation, monitoring, acceptance or replacement options with dependencies and side effects; assigns remediation and exception authority; verifies the deployed correction and control state; monitors for attempted exploitation where proportionate; and updates the asset, case and risk record instead of closing on ticket status alone.
04Incident coordination, authorized response, recovery, and learning
Provide a suspected compromise, fragile service, customer impact, legal uncertainty and pressure to disconnect systems immediately. Ask for safe next actions and an evidence-preserving handoff.
Confirm: The person applies the organization's declaration and severity criteria; establishes incident command, scope, objectives, communication channels, roles and decision log; preserves volatile and durable evidence under the approved legal and privacy process; restricts access and uses an agreed information-sharing marking; identifies affected identities assets data dependencies and time window; proposes reversible containment options with operational and evidential tradeoffs; never changes production beyond authority; records actions actors times and observed effects; supports eradication and correction without confusing symptom removal with cause; verifies identity, configuration, vulnerability and persistence conditions; monitors for recurrence; confirms restoration, backlog, customer and control state with owners; distinguishes technical recovery from legal notification and public communication; records residual uncertainty; conducts a blameless evidence-led review; improves telemetry detections architecture access runbooks exercises and training; and demonstrates continuity before closing the incident.