Ravindra BagaleCourses & study guides

46. General Interview Q and A

46.8 SOC, IR, Hardening and Cryptography Questions

Logs, triage, contain, patch, crypto hygiene – SOC language. Ghabru naka.

Q71. What does a SOC do?

A Security Operations Center monitors alerts, triages incidents, coordinates response, and improves detections. Tier-1 may enrich and escalate; seniors hunt and tune. I describe calm process, not movie hacking.

Q72. What is the incident response lifecycle you follow?

Common model: prepare, identify, contain, eradicate, recover, lessons learned. I do not reboot wipe first if forensics matter. For Sahyadri lab IR drills I snapshot and preserve logs before big changes when practising.

Q73. How do you triage a brute-force SSH alert?

Check source IP reputation and volume, confirm if any login succeeded, block or rate-limit as policy allows, verify key-only config, and document. If success occurred, assume credential risk and escalate.

Q74. Why are immutable logs important?

Attackers delete local logs. Shipping to a write-once or tightly controlled SIEM/archive keeps evidence. CloudTrail to a locked bucket is the AWS version of that idea.

Q75. Name Linux hardening steps you can recite.

SSH keys only, fail2ban or equivalent, firewalld/ufw allow-list, timely sudo yum update, SELinux/AppArmor awareness, minimal packages, separate admin accounts, and monitoring. Suricata/Snort awareness for IDS.

Q76. Hashing versus encryption – interview clarity?

Hashing is one-way fingerprinting for passwords or integrity (store bcrypt/Argon2 password hashes, not MD5). Encryption is reversible with keys for confidentiality. I never say "encrypt passwords with MD5".

Q77. What is AES-GCM associated with?

Modern authenticated encryption for data – confidentiality plus integrity. I mention algorithms at concept level and stress key management (KMS, HSM, rotation) more than trivia.

Q78. Why disable old TLS versions?

Ancient protocols have known weaknesses. I configure servers for TLS 1.2/1.3 and strong ciphers, then test with lab tools. Certificates and protocols both matter.

Q79. What is the difference between symmetric and asymmetric crypto?

Symmetric uses one shared key (fast for bulk data). Asymmetric uses key pairs (TLS handshake, signing). Real systems combine both. PKI binds identities to public keys via certificates.

Q80. How do you explain fail2ban quickly?

It watches logs for repeated failures and temporarily bans IPs via firewall rules. It reduces noisy SSH brute force on my lab EC2. It is not a substitute for key-only auth and SG allow-lists.

Red team (attacker) does Blue team (defender) detects / stops
Deletes local logs after foothold Central immutable logging; alert on log clearing
Brutes SSH / sprays passwords MFA; key auth; fail2ban; SG; passwordless admin paths

Ravindra Bagale's Tip

Students IR madhe "mi reboot kela" first step mhantat. Evidence udte. Interview madhe contain + preserve + then eradicate order sanga. He lakshat theva.

Lab

On OWN Amazon Linux: enable fail2ban for sshd in lab, generate failed logins from Kali host-only only, show ban in logs, screenshot for notes. Then unban your Kali IP.