Treat it as a joint investigation with legal and HR from the first hour, because insider cases carry employment and privacy consequences that a purely technical response can wreck. Preserve evidence before you poke at anything, then review only what you are authorized to review: file access and volume anomalies, cloud sync and personal storage uploads, removable media, mail forwarding and print logs. Report observed facts, never conclusions about intent.
Why interviewers ask this
Interviewers use this to test restraint and process, not tooling. They want you to involve legal and HR early, preserve before investigating, stay inside your authorized scope, and avoid tipping off the subject. They also listen for whether you can separate observed activity from claims about motive, since that distinction often decides whether your work survives an employment tribunal or a court.
How to structure your answer
- Start with authorization, preservation and who else must be in the room.
- List the data sources you review and in what order.
- Emphasize keeping the investigation quiet and tightly scoped.
- Report observations and evidence, never conclusions about motive.
Example answer
The first call is not technical. I notify legal and HR and confirm what I am authorized to look at, because in some jurisdictions reading personal content on a corporate device without the right basis gets the whole investigation thrown out. Then preservation: image the endpoint, preserve the mailbox and cloud storage in place with a legal hold, and freeze log retention for the relevant sources before anything ages out. Then review, quietly, with case access restricted, because if the subject notices, the evidence tends to evaporate. I look at file access volume against their own baseline, cloud sync clients and uploads to personal storage, removable media insertion and copy events, mail forwarding rules and large outbound attachments, and print jobs. My write up says what happened and when, with hashes and timestamps: this account copied these files to this device at this time. I do not write that they intended to steal anything, because that is for HR and legal, and I have seen a case collapse when an analyst editorialized.
Walking into this interview soon? GhostPilot listens to your live call, spots the question the moment it is asked, and puts a structured answer on your screen in real time. Try it on your next mock, or grab a $29 Session Pass, no subscription, for the real thing.
See how it worksFollow-up questions to expect
- What would you do differently if the person still has two weeks left?
- How do you handle data on a personal device they used for work?
- What controls would you put in place to catch this earlier next time?
Related cybersecurity analyst questions
Your interviewer will ask their own version of this. Paste your actual job description into the free Question Predictor and get the 20 questions that role is most likely to ask, with what each one is really probing.
Predict my questions