資安面試問題 · Security Interview Questions¶
A curated, open-source collection of questions asked in interviews for security roles — with answers — to help people breaking into the security field. 這裡整理了一些在面試和準備資安相關職位時可能會問到的問題與解答,希望能幫助想踏入資安圈的人更順利地找到工作。
Contribute on GitHub Search the questions
Browse by topic¶
-
Application Security
XSS, CSRF, SSRF, SQL injection, CSP, buffer overflows, and web attack defenses.
-
Encryption & Authentication
Handshakes, HMAC, Kerberos, sessions & cookies, and MFA methods.
-
Network & Network Security
OSI model, TCP/UDP, DNS, firewalls, TLS, traceroute, and Nmap.
-
Cryptography
Symmetric vs asymmetric, TLS, cipher modes, IVs, forward secrecy, HSM/TPM.
-
Security & Risk Management
Risk vs vulnerability, quantifying risk, risk appetite, and chain of custody.
-
Security Ops & Incident Response
Detection, IoCs, forensics, investigation methodology, and DevOps tooling.
-
Penetration Testing
Attack surfaces, remote control, spoofing, tooling, and malware reversing.
-
Threat Modeling
STRIDE, DREAD, and worked threat-modeling exercises.
-
System Admin
Windows & *nix internals, hardening, cloud IaaS/PaaS/SaaS.
-
Security-Related Coding
Data structures, algorithms, and security-themed coding challenges.
-
Behavioral Questions
Behavioral prompts mapped to Amazon's Leadership Principles.
-
Interview & Study Tips
How to prepare, what to say, and how to study — from Grace Nolan.
Contributing 一起貢獻¶
Help make this better
- Add a question or answer — open a Pull Request in the matching topic. 有想分享的面試問題或補充答案,歡迎直接建 Pull Request。
- Spot a mistake — open an Issue if a classification, question, or answer is wrong. 分類、題目或答案有錯,歡迎建 Issue。
- Suggest better structure — start a Discussion. 如果覺得分類有誤或能更好地分類,歡迎在 Discussions 討論。
Most content is in English and based on experience with US security roles — translations into Mandarin and other languages are very welcome.
License & credits¶
Great thanks to Grace Nolan for sharing her Interview Study Notes and allowing their integration here.
Content on this site is licensed under CC BY-SA 4.0.