Ravindra BagaleCourses & study guides

47. Interview Questions Asked in MNC Interviews

47.8 Scenario and HR + Technical Mix

Scenarios + HR – TCS-style mix. Swatahchya shabdat, ethics intact.

Q61. Scenario: Sahyadri Pune EC2 shows thousands of failed SSH attempts. Steps?

I check whether any login succeeded, tighten SG to known IPs, confirm key-only SSH, consider fail2ban, review GuardDuty/CloudTrail if on, and communicate plainly to owner Shahrukh. Document timeline.

Q62. Scenario: Incomplete alert data is escalated to you – what do you do?

(Theme pattern: Wipro-style ownership scenarios discussed in public career posts — treat as frequently asked across MNC interviews, candidate-reported.) I proceed with what I have, list missing fields, pull related logs myself, set a timebox, and escalate upward if crown jewels may be involved. I do not freeze waiting for a perfect ticket.

Q63. Scenario: Privileged account shows unusual activity. Investigation outline?

Frequently asked across MNC interviews (candidate-reported). Verify with the human owner out-of-band if possible, check MFA status, recent failures/successes, source IPs, impossible travel, concurrent sessions, and EDR on endpoints used. Contain by disabling/resetting per playbook when suspicion is high.

Q64. HR: Why should we hire you for a cyber/SOC role?

(Theme: TCS Smart Hiring HR — candidate-reported.) I bring ethics-first habits, solid networking and Linux foundations, OWN-lab evidence of Build-Hack-Fix, and clear communication for shift handoffs. I learn tools quickly because I understand the problems they solve.

Q65. HR: What if we assign you a role other than cybersecurity?

(Theme: TCS Smart Hiring HR — candidate-reported.) I stay professional: I can add value in adjacent IT while I keep building security skills, and I would ask how the role connects to security later. I do not threaten to walk out in the interview.

Q66. HR + tech: Are you comfortable with shifts / any location?

(Theme: TCS-style HR — candidate-reported.) I answer honestly about constraints, show I understand SOC may need coverage, and ask about shift patterns and handover quality. Honesty beats a fake "anywhere forever" that collapses in month one.

Q67. Scenario: Interviewer asks you to scan their production Wi-Fi during the interview.

I refuse politely. I only scan with written authorisation. I offer methodology discussion or screenshots from my host-only lab instead. Ethics over theatre.

Q68. Explain a two-minute Build-Hack-Fix story for MNC interviews.

I built a weak PHP order lookup for fictional Sahyadri Traders on host-only 192.168.56.50, proved SQL injection from Kali 192.168.56.10, fixed it with prepared statements and tight firewall rules, and retested until the old payload failed. I only attacked my VM.

Red team (attacker) does Blue team (defender) detects / stops
Pressures live production scan in interview Candidate refuses; good employers respect that
Hides gaps with buzzwords STAR + OWN-lab proof + clear "I have not done X in production"

Ravindra Bagale's Tip

HR round madhe students "sirf cyber nahi tar nako" abrupt mhantat. Soft bridge: value aata + security path pudhe. Technical scenario madhe freeze nako – missing data list kara ani move. Samjla ka?

Lab

Time-box 25 minutes: write STAR for Q61 and spoken script for Q64/Q65. Record once privately; remove filler words. Peer review with Ravina.