Cybersecurity Analyst Interview Question

Which metrics would you report on to show the SOC is doing its job?

What the interviewer is probing, how to structure your answer, and a spoken example you can adapt.

Quick answer

Report outcome metrics alongside activity. Useful ones are time to detect and time to contain by severity, the proportion of incidents found by your own detections versus reported from outside, validated detection coverage against your priority techniques, false positive rate per rule, and the age of open risk exceptions. Avoid raw alert counts and tickets closed as headline numbers, since they reward noise over security outcomes.

Why interviewers ask this

This checks whether you can think like the person paying for the team. Interviewers want metrics that drive behavior in the right direction, plus an explicit statement of which numbers are gameable. Self detection rate is the strongest single answer because it measures the thing the function exists for. They also listen for whether you would report a bad month honestly rather than curating the dashboard.

How to structure your answer

  • Lead with one outcome metric that captures the mission.
  • Add supporting operational metrics with clear definitions.
  • Name the vanity metrics you would refuse to headline and why.
  • Say how you would present a bad month.

Example answer

Spoken example, first person

My headline is the proportion of incidents we detected ourselves versus ones we learned about from a user, a customer, a vendor or law enforcement. That single number says whether the function is working. Underneath it, time to detect and time to contain split by severity, because averaging a phishing report with a ransomware attempt hides everything that matters. Then coverage against the techniques we decided were priorities for our threat model, graded from validation testing rather than self assessment, and false positive rate per rule so tuning work has a number attached to it. I deliberately avoid leading with alert volume or tickets closed, because those rise when the environment gets noisier, and I have watched a team be congratulated for a metric that was pure telemetry regression. When a month is bad I present it with the reason and the fix, because the moment you curate the dashboard you lose the ability to ask for budget with a straight face.

Walking into this interview soon? GhostPilot listens to your live call, spots the question the moment it is asked, and puts a structured answer on your screen in real time. Try it on your next mock, or grab a $29 Session Pass, no subscription, for the real thing.

See how it works

Follow-up questions to expect

  • How do you set a target for time to contain?
  • How would you measure the value of threat hunting?
  • What would you report weekly versus quarterly?

Related cybersecurity analyst questions

Your interviewer will ask their own version of this. Paste your actual job description into the free Question Predictor and get the 20 questions that role is most likely to ask, with what each one is really probing.

Predict my questions

Rehearse the hard questions before they are asked

Practise with a live copilot, then walk in ready. A $29 Session Pass gets you through the interview with no subscription and no lock-in.

Get GhostPilot