<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: 10 Questions To Ask During An Information Security Interview</title>
	<atom:link href="http://dmiessler.com/blog/10-questions-to-ask-during-an-information-security-interview/feed" rel="self" type="application/rss+xml" />
	<link>http://dmiessler.com/blog/10-questions-to-ask-during-an-information-security-interview</link>
	<description>in search of intervals</description>
	<pubDate>Tue, 18 Nov 2008 15:18:18 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7-bleeding</generator>
		<item>
		<title>By: Max</title>
		<link>http://dmiessler.com/blog/10-questions-to-ask-during-an-information-security-interview#comment-223569</link>
		<dc:creator>Max</dc:creator>
		<pubDate>Fri, 07 Nov 2008 01:57:28 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1061#comment-223569</guid>
		<description>&lt;p&gt;these questions sound very basic.... for jr security position.&lt;/p&gt;

&lt;p&gt;what questions you would ask for pentester/sr sec analyst position?&lt;/p&gt;

&lt;p&gt;thanks
Max&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>these questions sound very basic&#8230;. for jr security position.</p>

<p>what questions you would ask for pentester/sr sec analyst position?</p>

<p>thanks
Max</p>]]></content:encoded>
	</item>
	<item>
		<title>By: James</title>
		<link>http://dmiessler.com/blog/10-questions-to-ask-during-an-information-security-interview#comment-216643</link>
		<dc:creator>James</dc:creator>
		<pubDate>Sun, 19 Oct 2008 03:13:11 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1061#comment-216643</guid>
		<description>&lt;p&gt;You say, "As weak as the CISSP is as a security certification..."&lt;/p&gt;

&lt;p&gt;This cert seems to be der rigeur in the industry for any security position. Almost all the jobs I apply for say it is desirable, required, or you must get certified within 6 months of hire. Why do you have such a low opinion of it? And, if it's so weak, why do they all want you to have it?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>You say, &#8220;As weak as the CISSP is as a security certification&#8230;&#8221;</p>

<p>This cert seems to be der rigeur in the industry for any security position. Almost all the jobs I apply for say it is desirable, required, or you must get certified within 6 months of hire. Why do you have such a low opinion of it? And, if it&#8217;s so weak, why do they all want you to have it?</p>]]></content:encoded>
	</item>
	<item>
		<title>By: ash</title>
		<link>http://dmiessler.com/blog/10-questions-to-ask-during-an-information-security-interview#comment-180368</link>
		<dc:creator>ash</dc:creator>
		<pubDate>Tue, 26 Aug 2008 14:04:16 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1061#comment-180368</guid>
		<description>&lt;p&gt;Nice compilation of questions....!!&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Nice compilation of questions&#8230;.!!</p>]]></content:encoded>
	</item>
	<item>
		<title>By: knight</title>
		<link>http://dmiessler.com/blog/10-questions-to-ask-during-an-information-security-interview#comment-160051</link>
		<dc:creator>knight</dc:creator>
		<pubDate>Mon, 14 Jul 2008 05:23:05 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1061#comment-160051</guid>
		<description>&lt;p&gt;Where are the answers to all the questions?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Where are the answers to all the questions?</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Define Panic Attack</title>
		<link>http://dmiessler.com/blog/10-questions-to-ask-during-an-information-security-interview#comment-129865</link>
		<dc:creator>Define Panic Attack</dc:creator>
		<pubDate>Fri, 21 Mar 2008 21:26:29 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1061#comment-129865</guid>
		<description>&lt;p&gt;&lt;strong&gt;Define Panic Attack...&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This article sounds well, but how everything is related together?...&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p><strong>Define Panic Attack&#8230;</strong></p>

<p>This article sounds well, but how everything is related together?&#8230;</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Darby Weaver</title>
		<link>http://dmiessler.com/blog/10-questions-to-ask-during-an-information-security-interview#comment-23147</link>
		<dc:creator>Darby Weaver</dc:creator>
		<pubDate>Sat, 13 Jan 2007 10:13:41 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1061#comment-23147</guid>
		<description>&lt;p&gt;Hmmm...&lt;/p&gt;

&lt;p&gt;Interesting - I got the Compression vs. Encryption question in the terms of asking about how IPSec is handled once.&lt;/p&gt;

&lt;p&gt;I used to get the home computer question.&lt;/p&gt;

&lt;p&gt;But after I explain my home lab setup and some of the machines I keep around that run from Linux Appliances, Cobalt RAQ Appliances with CentOS and Solaris, or my Solaris Pizza Box that I installed Red Hat 6.0 on or just my run of the mill PC's with any various OS or some of my favorite tools.&lt;/p&gt;

&lt;p&gt;Then we have the Cisco and other vendors gear.  I stop after the eyes start to glaze, unless they want to know where I get my bogon lists from or where I find my latest 0-Day Exploits from and how I have acquired so many tools of the trade...&lt;/p&gt;

&lt;p&gt;Hmmm...&lt;/p&gt;

&lt;p&gt;Well, you know...&lt;/p&gt;

&lt;p&gt;How are things going?&lt;/p&gt;

&lt;p&gt;Did you ever decide to use Cisco Gear?  Get your CCNA yet?&lt;/p&gt;

&lt;p&gt;Are you in Orlando this week at SANS?&lt;/p&gt;

&lt;p&gt;Later&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Hmmm&#8230;</p>

<p>Interesting - I got the Compression vs. Encryption question in the terms of asking about how IPSec is handled once.</p>

<p>I used to get the home computer question.</p>

<p>But after I explain my home lab setup and some of the machines I keep around that run from Linux Appliances, Cobalt RAQ Appliances with CentOS and Solaris, or my Solaris Pizza Box that I installed Red Hat 6.0 on or just my run of the mill PC&#8217;s with any various OS or some of my favorite tools.</p>

<p>Then we have the Cisco and other vendors gear.  I stop after the eyes start to glaze, unless they want to know where I get my bogon lists from or where I find my latest 0-Day Exploits from and how I have acquired so many tools of the trade&#8230;</p>

<p>Hmmm&#8230;</p>

<p>Well, you know&#8230;</p>

<p>How are things going?</p>

<p>Did you ever decide to use Cisco Gear?  Get your CCNA yet?</p>

<p>Are you in Orlando this week at SANS?</p>

<p>Later</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Waleed Alrodhan - Information Security Blog </title>
		<link>http://dmiessler.com/blog/10-questions-to-ask-during-an-information-security-interview#comment-22213</link>
		<dc:creator>Waleed Alrodhan - Information Security Blog </dc:creator>
		<pubDate>Tue, 09 Jan 2007 23:43:08 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1061#comment-22213</guid>
		<description>&lt;p&gt;[...] &lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] </p>]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel</title>
		<link>http://dmiessler.com/blog/10-questions-to-ask-during-an-information-security-interview#comment-22117</link>
		<dc:creator>Daniel</dc:creator>
		<pubDate>Tue, 09 Jan 2007 15:59:23 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1061#comment-22117</guid>
		<description>&lt;p&gt;Nice ones, Michael. For the crypto one I usually as them to describe exactly what happens when you send a message that's both signed and encrypted using PGP -- specifically relating to the cryptography. What I look for in the response is the not-so-well-known fact that the message is actually not encrypted with the other person's public key.&lt;/p&gt;

&lt;p&gt;...wait for it...&lt;/p&gt;

&lt;p&gt;Instead, the message is encrypted with a randomly generated SYMMETRIC key, and &lt;em&gt;that&lt;/em&gt; key is encrypted using their public key. They then decrypt the symmetric key, and use that to read the encrypted message. Which directly illustrates the positives and negatives of both. You wouldn't want to use asymmetric cryptography to encrypt a very large message due to the time cost, so symmetric cryptography is used instead.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Nice ones, Michael. For the crypto one I usually as them to describe exactly what happens when you send a message that&#8217;s both signed and encrypted using PGP &#8212; specifically relating to the cryptography. What I look for in the response is the not-so-well-known fact that the message is actually not encrypted with the other person&#8217;s public key.</p>

<p>&#8230;wait for it&#8230;</p>

<p>Instead, the message is encrypted with a randomly generated SYMMETRIC key, and <em>that</em> key is encrypted using their public key. They then decrypt the symmetric key, and use that to read the encrypted message. Which directly illustrates the positives and negatives of both. You wouldn&#8217;t want to use asymmetric cryptography to encrypt a very large message due to the time cost, so symmetric cryptography is used instead.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Michael S Black</title>
		<link>http://dmiessler.com/blog/10-questions-to-ask-during-an-information-security-interview#comment-22104</link>
		<dc:creator>Michael S Black</dc:creator>
		<pubDate>Tue, 09 Jan 2007 13:51:06 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1061#comment-22104</guid>
		<description>&lt;p&gt;Here is a few we use:&lt;/p&gt;

&lt;p&gt;Define non-repudiation and give a real world example.&lt;/p&gt;

&lt;p&gt;What would you do with a Rainbow Table?&lt;/p&gt;

&lt;p&gt;What is a downstream liability?&lt;/p&gt;

&lt;p&gt;What is the difference between symmetric and asymmetric cryptography?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Here is a few we use:</p>

<p>Define non-repudiation and give a real world example.</p>

<p>What would you do with a Rainbow Table?</p>

<p>What is a downstream liability?</p>

<p>What is the difference between symmetric and asymmetric cryptography?</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Cybercrime Law</title>
		<link>http://dmiessler.com/blog/10-questions-to-ask-during-an-information-security-interview#comment-21986</link>
		<dc:creator>Cybercrime Law</dc:creator>
		<pubDate>Tue, 09 Jan 2007 00:46:15 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1061#comment-21986</guid>
		<description>&lt;p&gt;&lt;strong&gt;10 Questions To Ask During An Information Security Interview...&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Daniel Miessler has compiled a list of 10 questions that should be asked of a candidate for a security (or even any IT position.) Although not perfect, this list should provide a good starting point for an employer trying to understand whether the cand...&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p><strong>10 Questions To Ask During An Information Security Interview&#8230;</strong></p>

<p>Daniel Miessler has compiled a list of 10 questions that should be asked of a candidate for a security (or even any IT position.) Although not perfect, this list should provide a good starting point for an employer trying to understand whether the cand&#8230;</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Philip</title>
		<link>http://dmiessler.com/blog/10-questions-to-ask-during-an-information-security-interview#comment-21932</link>
		<dc:creator>Philip</dc:creator>
		<pubDate>Mon, 08 Jan 2007 12:16:18 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1061#comment-21932</guid>
		<description>&lt;p&gt;Wow.  Some of these are good.  When I came to the interview for my current job, my boss had about 15 sheets of questions that are standard.  I cannot remember them all now, but I was so nervous.  We ended up hiring a guy who was straight out of college and has no Linux experience (he had heard of it before).  It is really hurting.  We have had to teach about the world all over again.  He really doesn't know that much about the deep parts of Windows.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Wow.  Some of these are good.  When I came to the interview for my current job, my boss had about 15 sheets of questions that are standard.  I cannot remember them all now, but I was so nervous.  We ended up hiring a guy who was straight out of college and has no Linux experience (he had heard of it before).  It is really hurting.  We have had to teach about the world all over again.  He really doesn&#8217;t know that much about the deep parts of Windows.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Wonk</title>
		<link>http://dmiessler.com/blog/10-questions-to-ask-during-an-information-security-interview#comment-21929</link>
		<dc:creator>Wonk</dc:creator>
		<pubDate>Mon, 08 Jan 2007 12:09:26 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1061#comment-21929</guid>
		<description>&lt;p&gt;I think one could also argue for number 2 that encrypting before compressing would tend to reduce the possibility of known plaintext attacks.  But, as you say, there's not any point in compressing data once it's been encrypted.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I think one could also argue for number 2 that encrypting before compressing would tend to reduce the possibility of known plaintext attacks.  But, as you say, there&#8217;s not any point in compressing data once it&#8217;s been encrypted.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Dave</title>
		<link>http://dmiessler.com/blog/10-questions-to-ask-during-an-information-security-interview#comment-21884</link>
		<dc:creator>Dave</dc:creator>
		<pubDate>Mon, 08 Jan 2007 03:10:47 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1061#comment-21884</guid>
		<description>&lt;p&gt;"Don’t forget that security is mostly an attitude, or actually a way of life, and only secondly knowledge."&lt;/p&gt;

&lt;p&gt;Well said.&lt;/p&gt;

&lt;p&gt;My favorite interview bonus question is "how many fire alarm levers did we pass on the way here?"&lt;/p&gt;

&lt;p&gt;I'd hire someone who got every technical question wrong but answered that one even in the ball park.&lt;/p&gt;

&lt;p&gt;-Dave&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>&#8220;Don’t forget that security is mostly an attitude, or actually a way of life, and only secondly knowledge.&#8221;</p>

<p>Well said.</p>

<p>My favorite interview bonus question is &#8220;how many fire alarm levers did we pass on the way here?&#8221;</p>

<p>I&#8217;d hire someone who got every technical question wrong but answered that one even in the ball park.</p>

<p>-Dave</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Arik</title>
		<link>http://dmiessler.com/blog/10-questions-to-ask-during-an-information-security-interview#comment-21862</link>
		<dc:creator>Arik</dc:creator>
		<pubDate>Mon, 08 Jan 2007 01:18:20 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1061#comment-21862</guid>
		<description>&lt;p&gt;I was once asked which is stronger - RSA with a 8192 bit key or AES with 128 bit key&lt;/p&gt;

&lt;p&gt;Don't forget that security is mostly an attitude, or actually a way of life, and only secondly knowledge.&lt;/p&gt;

&lt;p&gt;-- Arik&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I was once asked which is stronger - RSA with a 8192 bit key or AES with 128 bit key</p>

<p>Don&#8217;t forget that security is mostly an attitude, or actually a way of life, and only secondly knowledge.</p>

<p>&#8211; Arik</p>]]></content:encoded>
	</item>
</channel>
</rss>
