Cybersecurity Analyst Interview Question

A user reports a suspicious email. Walk me through your analysis.

What the interviewer is probing, how to structure your answer, and a spoken example you can adapt.

Quick answer

Work from the headers outward, in a safe environment. Check the sending path, SPF, DKIM and DMARC results, envelope versus display sender, and any reply to mismatch. Detonate links and attachments in a sandbox, never on your workstation. Extract indicators, then search mail logs for everyone else who received it and whether anyone clicked or authenticated. Contain by purging the message and blocking the infrastructure.

Why interviewers ask this

The interviewer is checking safe handling habits, header literacy, and whether you think past the single reported email to organizational scope. Many candidates analyze the sample and stop there. The strong answer pivots quickly to the question that actually matters: who else received it and who interacted with it. They also want the response actions you can take yourself versus what needs mail administrator support.

How to structure your answer

  • State your handling precautions before you touch the sample.
  • Read authentication results and the sender path first.
  • Detonate and extract indicators in an isolated environment.
  • Pivot immediately to organizational scope and containment.

Example answer

Spoken example, first person

I never open it on my own box. I pull the original message with full headers from the mail platform, and I detonate anything live in a sandbox virtual machine with network capture running. Headers first: SPF, DKIM and DMARC results, the received chain, whether the envelope sender matches the display name, and whether the reply to address is a lookalike domain. Most credential phishing I have seen passes SPF because it is sent from a compromised legitimate tenant, so a pass on its own proves nothing. Then links: expand shorteners, follow redirect chains, and check whether the landing page is a harvester mimicking our own login page. Then I flip to scope, which matters more than the sample: search mail logs for the sender, subject and URL to find everyone who received it, check proxy logs for clicks, and check sign in logs for authentications from that infrastructure. Purge from all mailboxes, block the domain, reset anyone who authenticated.

Walking into this interview soon? GhostPilot listens to your live call, spots the question the moment it is asked, and puts a structured answer on your screen in real time. Try it on your next mock, or grab a $29 Session Pass, no subscription, for the real thing.

See how it works

Follow-up questions to expect

  • What do you do if three users already entered credentials?
  • How do you tell a credential harvester from a malware delivery page?
  • How do you handle a phishing report that turns out to be a real vendor email?

Related cybersecurity analyst questions

Your interviewer will ask their own version of this. Paste your actual job description into the free Question Predictor and get the 20 questions that role is most likely to ask, with what each one is really probing.

Predict my questions

Rehearse the hard questions before they are asked

Practise with a live copilot, then walk in ready. A $29 Session Pass gets you through the interview with no subscription and no lock-in.

Get GhostPilot