From our research
What this interview looks like
Indian employers hire for these roles through an HR screen, a hiring-manager round on your actual work, a technical round led by a lead or architect (often with a hands-on scenario such as an outage, an alert, a crash log or a ticket), a behavioural round and a final HR discussion, spread across several days and sometimes preceded by an online test or lab. Security roles often add a CISO or security-head conversation; support roles add a customer-handling or call simulation. ExamPilot compresses this into one 17-minute panel: HR screen, hiring manager, role or technical lead, STAR behavioural round and closing. You get a scored report on role knowledge, problem solving, communication and attitude, with specific feedback on each technical scenario and every behavioural answer.
How it is weighted
Pass/fail per round in real life, often including an alert-triage or CTF-style practical and, for senior roles, a CISO conversation; scored here against the corporate rubric.
Who this is for
SOC analysts (L1 to L3), incident responders, penetration testers and application security engineers, and GRC or cloud-security professionals, including freshers with CEH, CompTIA Security+ or a cyber-security degree and IT or network professionals moving into security.
The panel focuses on
- Alert triage in a SIEM: true positive, false positive, escalation
- OWASP Top 10 and how you would actually exploit and then fix a finding
- ISO 27001, SOC 2 and the DPDP Act as a control owner, not a checklist reader
- Cloud misconfigurations and identity as the new perimeter
- Explaining risk to a business owner in plain words
- Ethics, scope and disclosure in offensive security
Step 1
Pick your domain
The expert on the panel probes these areas at the level of this role. Optional here; you can choose during setup.
Step 2
Choose how you want to be interviewed
1:1 interview
One interviewer runs every round and adapts the focus as you go. Lower pressure; ideal for a first attempt.
Mr. Arvind Raghavan
Hiring manager
Panel interview · 3 members
Most realisticEach member leads their own round and hands over to the next. They hear each other, so a weak answer will be revisited.
Ms. Neha Kulkarni
HR member
Mr. Arvind Raghavan
Hiring manager
Ms. Ananya Sen
Technical lead
What to expect
5 rounds · 17 minutes
A private-sector hiring loop compressed into one sitting, the way most Indian companies run it: HR screen → hiring-manager round on your actual work → role/technical round led by a lead → communication & behavioural (STAR) round → closing on expectations and your questions. Works for software, product, sales, finance, HR, support and campus hiring by swapping the role bank.
- Round 1
HR screen
· 3:00Understand background, motivation for this role and company, and basic logistics; check that the resume story holds together.
Ms. Neha Kulkarni2–3 questionsup to 1 follow-up each - Round 2
Hiring-manager round
· 4:00Assess ownership, judgement and how the candidate actually works: what they shipped, closed or ran, their specific part, and how they would approach this job.
Mr. Arvind Raghavan2–3 questionsup to 2 follow-ups each - Round 3
Role / technical round
· 5:00Test role knowledge and problem-solving in the chosen specialisation: fundamentals, one scenario to think through aloud, and trade-offs.
Ms. Ananya Sen3–4 questionsup to 2 follow-ups each - Round 4
Communication & behavioural round
· 3:00Assess collaboration, conflict handling, resilience and clarity of expression through Situation–Task–Action–Result examples.
Mr. Arvind Raghavan2–2 questionsup to 1 follow-up each - Round 5
Expectations & closing
· 2:00Cover practical expectations and let the candidate ask questions; close professionally.
Ms. Neha Kulkarni1–2 questions
Sample questions
Infra / Security / Mobile / IT Security interview questions
Questions panels commonly ask in the Infra / Security / Mobile / IT Security interview, with what a strong answer covers. Practise them aloud with the AI panel.
- SOC triage
A SIEM alert shows multiple failed logins followed by a successful login from a foreign IP on a finance user's account. How do you triage it?
What a strong answer covers
Check the user's normal location and devices, the IP reputation, MFA status, impossible travel, and what the account did after login. Contact the user, reset credentials if suspicious and escalate as per playbook. Document the case. Avoid closing it as a false positive without checking post-login activity.
- Application security
Explain SQL injection as if you were testing a login page, and then tell me how the developer should fix it.
What a strong answer covers
Describe how unsanitised input can change the query, how a tester would safely confirm it within scope, and the fix with parameterised queries, input validation, least-privilege database accounts and error handling. Avoid demonstrating attacks outside authorised scope.
- Ethics
During a penetration test you find a critical vulnerability outside the agreed scope. What do you do?
What a strong answer covers
Stop testing that asset, document what you observed, inform the client contact promptly and follow the rules of engagement. Do not exploit it further. Avoid continuing to test because it might be impressive.
- Cloud security
An S3 bucket containing customer documents is found to be publicly readable. What are your immediate steps?
What a strong answer covers
Restrict access immediately, check logs for access, assess the data exposed, inform stakeholders, follow incident response and breach notification obligations including those under the DPDP Act, and fix root cause with policies and guardrails. Avoid only fixing permissions without investigating exposure.
- GRC
As a control owner for ISO 27001, how would you prove to an auditor that access reviews actually happen?
What a strong answer covers
Show the policy, a schedule, evidence of reviews with sign-offs, actions taken on findings and system logs. Explain how you would fix gaps. Avoid presenting only a policy document without evidence of operation.
- Risk communication
Explain the risk of an unpatched VPN appliance to the CFO in two minutes.
What a strong answer covers
Use plain language: what could happen, the likelihood, business impact such as data theft or ransomware, cost of fixing versus not, and a clear recommendation. Avoid technical jargon and CVE numbers.
- Identity
Why is identity often called the new perimeter in cloud security?
What a strong answer covers
Explain that users and services access cloud resources from anywhere, so strong identity controls such as MFA, least privilege, conditional access and monitoring matter more than network boundaries. Avoid stating network security no longer matters.
- Incident response
Walk me through how you would respond to a suspected ransomware infection on one employee's laptop.
What a strong answer covers
Isolate the device, preserve evidence, identify the strain, check spread, inform incident response leads, restore from clean backups and communicate with stakeholders. Avoid paying ransom or shutting systems down without guidance.
- Hands-on proof
You are a fresher with CEH. What have you done hands-on beyond the certification?
What a strong answer covers
Describe concrete practice: platforms such as TryHackMe or Hack The Box, a home lab with a SIEM or vulnerable VMs, CTF results, responsible bug-bounty reports, or a college project, and one specific thing you learned from it. Be honest about depth. Avoid implying the certificate alone makes you job-ready.
Reading is not rehearsing. Answer these out loud to an AI Infra / Security / Mobile / IT Security panel that follows up like the real one.
Practise these questionsMeet the panel
Your AI interviewers
Distinct personas, voices and questioning styles, briefed on this role.
Ms. Neha Kulkarni
ChairHR member
HR business partner, IT services
Friendly, efficient, detail-checking.
Female voice · 4 languages
Mr. Arvind Raghavan
Hiring manager
Chief Information Security Officer, mid-size fintech; ex-Big Four cyber practice
Calm, business-minded, intolerant of jargon without judgement.
Male voice · 4 languages
Ms. Ananya Sen
Technical lead
Staff engineer / technical lead
Curious, precise, collaborative.
Female voice · 3 languages
Languages
Answer in the language you think in
The panel asks in your chosen language. Switch mid-answer if you like.
- English
- Hinglish (Hindi + English)Hinglish
How scoring works
A report you can act on
Every round is scored on the rubric
Each interviewer scores only the criteria their round covers. Weights add up to your overall score out of 100.
Only what you actually said counts
Feedback quotes your own answers. Rounds you skip show as “Not assessed” rather than a zero.
Communication is always measured
Fluency, clarity, confidence and structure are tracked across the whole interview, in any language.
Pass mark, then a plan
You see the pass mark for this interview, your gaps, and the courses that close them fastest.
Scored on
- Role knowledge30%
Depth and accuracy of role/domain knowledge; understands the tools, concepts and trade-offs of the job; grounds claims in real work.
- Problem solving & structure25%
Breaks problems down, asks clarifying questions, reasons about trade-offs and edge cases, structures answers (context, action, result).
- Communication25%
Clear, concise, confident; listens and answers the question asked; adapts the explanation to the listener; professional register.
- Culture & attitude20%
Ownership, honesty about limits, coachability, collaboration, motivation for this role and realistic expectations.
Pass mark 65 / 100 · Corporate interview — HR, hiring manager & role round (panel)
Keep exploring