General attack knowledge questions
In this section, you will see some of the attack knowledge questions that might be asked in a SOC Analyst interview.
What is a botnet?
A botnet is composed of hijacked computers that are used to perform several tasks, including attacks such as DDoS. Some notable botnet infrastructures are Mirai, which hijacked IoT devices, and Emotet.
What are the most common types of attacks that threaten enterprise data security?
The answer to this will change as time progresses and new threats emerge, but in general, it includes things such as malware/ransomware, DDoS/DoS attacks, phishing/business email compromise (BEC), credential stuffing, and web application attacks. Threat actors also use generative AI to build more sophisticated phishing attacks.
The Verizon Data Breach Investigations Report (DBIR) is a good source of information for the most prevalent attacks.
To read more about DBIR, please check out https://www.verizon.com...