System Auditor

  Home  Audit  System Auditor


“System Auditor Frequently Asked Questions in various System Auditor job interviews by interviewer. The set of questions are here to ensures that you offer a perfect answer posed to you. So get preparation for your new job interview”



54 System Auditor Questions And Answers

41⟩ Tell me what’s more secure, SSL or HTTPS?

Trick question: these are not mutually exclusive. Look for a smile like they caught you in the cookie jar. If they’re confused, then this should be for an extremely junior position.

 167 views

42⟩ Suppose if you had to both encrypt and compress data during transmission, which would you do first, and why?

If they don’t know the answer immediately it’s ok. The key is how they react. Do they panic, or do they enjoy the challenge and think through it? I was asked this question during an interview at Cisco. I told the interviewer that I didn’t know the answer but that I needed just a few seconds to figure it out. I thought out loud and within 10 seconds gave him my answer: “Compress then encrypt. If you encrypt first you’ll have nothing but random data to work with, which will destroy any potential benefit from compression.

 209 views

44⟩ Explain me how do you minimize the risk for errors in your work?

As an accountant, you are held to a high standard and the margin for error is tiny. Small mistakes can lead to large financial issues.

“Respond to this question by describing any times you’ve caught errors before submitting work,”. “Emphasize the importance of checking your work and establishing checks and balances within a team.”

 174 views

45⟩ Explain me how do you feel your job as a government auditor differs from that of a private sector auditor?

First of all, there is a sense of working for the public good as a government auditor. I’ve also served as a private auditor and did many internal audits to ensure the business was in sound financial health. This served an important function in helping the business stay afloat, but it didn’t necessarily involve an entire population. There is a kind of sacred trust in dealing with public money, and perhaps, a greater propensity of some non-profits or government agencies, to lose track of money, because it is being provided. A government audit requires a certain amount of discipline in investigating whether funds earmarked for one purpose were used properly. Elections have been won and lost based on the use of public funds, so it is vital to our public life as citizens.

 183 views

46⟩ Do you know what’s the goal of information security within an organization?

This is a big one. What I look for is one of two approaches; the first is the über-lockdown approach, i.e. “To control access to information as much as possible, sir!” While admirable, this again shows a bit of immaturity. Not really in a bad way, just not quite what I’m looking for. A much better answer in my view is something along the lines of, “To help the organization succeed.”

This type of response shows that the individual understands that business is there to make money, and that we are there to help them do that. It is this sort of perspective that I think represents the highest level of security understanding—-a realization that security is there for the company and not the other way around.

 167 views

48⟩ Tell me how does one defend against CSRF?

Nonces required by the server for each page or each request is an accepted, albeit not foolproof, method. Again, we’re looking for recognition and basic understanding here–not a full, expert level dissertation on the subject. Adjust expectations according to the position you’re hiring for.

 171 views

50⟩ Explain me where do you get your security news from?

Here I’m looking to see how in tune they are with the security community. Answers I’m looking for include things like Team Cymru, Reddit, Twitter, etc. The exact sources don’t really matter. What does matter is that he doesn’t respond with, “I go to the CNET website.”, or, “I wait until someone tells me about events.”. It’s these types of answers that will tell you he’s likely not on top of things.

 189 views

51⟩ Explain me a time when you made a mistake on the job?

Early in my career, I made a mistake on a report and denied a client their claim on the grounds that the car accident appeared to be a result of their negligence as opposed to the negligence of the other party. I found out later that I was too quick to make that decision. I had not spoken to the police first, who later informed me that the evidence I was looking at was taken after the vehicles had been moved from the scene. They showed me photographs of the vehicle immediately after it had happened, which clearly showed the other party was at fault. I was too quick on the draw, and I learned that every case requires due diligence.

 144 views

52⟩ Explain me what’s the difference between a threat, vulnerability, and a risk?

As weak as the CISSP is as a security certification it does teach some good concepts. Knowing basics like risk, vulnerability, threat, exposure, etc. (and being able to differentiate them) is important for a security professional. Ask as many of these as you’d like, but keep in mind that there are a few differing schools on this. Just look for solid answers that are self-consistent.

 154 views

54⟩ Tell me what is salting, and why is it used?

You purposely want to give the question without context. If they know what salting is just by name, they’ve either studied well or have actually been exposed to this stuff for a while.

 176 views