A penetration tester (or ethical hacker) simulates real attacks to find and safely demonstrate weaknesses before criminals do. Pen-test interviews are technical and practical: expect to explain methodology, reason about specific vulnerabilities, and — crucially — show you understand scope, ethics and reporting. Many employers also set a practical challenge or discuss a CTF you have done.
What pen-test interviews assess
Employers want three things: technical depth (do you understand how attacks work?), methodology (are you systematic and safe?), and professionalism (can you scope engagements, stay within authorisation and write a report a client can act on?). Raw hacking skill without professionalism is a red flag.
Methodology questions
- Walk me through the phases of a penetration test. Scoping and rules of engagement → reconnaissance → scanning/enumeration → exploitation → post-exploitation → reporting → retest.
- What is the difference between a vulnerability scan and a penetration test? Automated detection vs manual, goal-driven exploitation with business context.
- What are black-box, grey-box and white-box testing?
- How do you stay within scope and authorisation? This is both technical and ethical — get it right.
Web application questions
- Explain the OWASP Top 10. Be ready to discuss injection, broken access control, and misconfiguration in depth.
- How does SQL injection work and how do you remediate it? Parameterised queries, least privilege, input validation.
- Explain XSS and its types. Stored, reflected, DOM-based — and the impact of each.
- What is CSRF and how do anti-CSRF tokens help?
- What is SSRF and why has it become so impactful in cloud environments?
Network and infrastructure questions
- How would you enumerate a target network? Discuss Nmap techniques, service/version detection, and being noisy vs stealthy.
- Explain a typical Active Directory attack path. For example: initial foothold → Kerberoasting → privilege escalation → lateral movement → domain dominance.
- What is the difference between a reverse shell and a bind shell?
- How does pass-the-hash work?
Post-exploitation and reporting
- You have gained access. What now? Demonstrate impact safely, maintain access only within scope, and document everything.
- What makes a good penetration test report? Clear executive summary, risk-rated findings, reproducible steps, and actionable remediation — written for both technical and non-technical readers.
- How do you rate the severity of a finding? Reference CVSS and business context.
Ethics and professionalism
- What would you do if you found something out of scope? Stop, document, and communicate with the client — never proceed without authorisation.
- How do you handle sensitive data discovered during a test?
- Why is legal authorisation (a signed scope) essential before testing?
Behavioural questions
- Describe a challenging box or engagement and how you approached it.
- How do you keep your skills sharp? Hack The Box, TryHackMe, CVE research, and building tooling. Structure these with the STAR method.
How to prepare
Do labs and CTFs, keep a portfolio of write-ups, and practise explaining an attack path clearly and calmly. Ground your fundamentals with our network security and SOC analyst guides, and see the cyber security career path for where pen-testing leads.
Practise this with Missiora
Reading about questions is not the same as answering them under pressure. Rehearse a realistic, role-specific mock with AI Interview™, decode a real job advert with Job Intelligence™, close skill gaps with Career Coach, and build verifiable proof of your progress in your Career Passport™. If you know who is interviewing you, Interview Panel Intelligence™ helps you prepare for their likely focus. See the parent guide, Cyber Security Interview Questions, for the full picture.
