CrowdStrike logo

CrowdStrike Security Analyst Interview Questions
& Process

Real candidates share what happened, how many rounds they had,
and how the experience turned out.

Based on 15 interview experiences · FREE TO READ

2.5 Rounds average
Average Typical difficulty
66.7% Positive experience

Candidate interview experiences

First-hand accounts from people who interviewed at CrowdStrike.

Showing 3 of 15
CrowdStrike logo
CrowdStrike

Vulnerability Management Analyst

Engineering · a year ago

Mid Difficult Positive experience Accept offer 5 rounds
Interview process
Recruiter call Phone screen Technical screen Take home Presentation
Interview formats
Behavioral Technical Presentation

So, I had 5 interviews total. First, it was with the internal recruiter, then I spoke with someone who would be a senior in the same role. After that, I had an interview with my potential manager. Then came a practical assessment and presentation, which took a good chunk of time over a week. The last interview was with the CISO, which was pretty much just a formality to check communication and personality.

Confirmed questions3 questions
  • Given these non-ideal circumstances, what's your assessment?
  • How would you handle these conflicting vulnerability assessment indicators?
  • Describe your thought process when faced with these vulnerability assessment indicators during the presentation.
CrowdStrike logo
CrowdStrike

Cybersecurity Analyst

Engineering · more than a year ago

Entry Average Negative experience No offer 3 rounds
Interview process
Technical screen Phone screen Onsite
Interview formats
Technical Behavioral

The interview process started with an initial cybersecurity test for screening, followed by a phone screening. After that, I had interviews with two current employees, and then I was ghosted with no update on my application! Overall, it was a pretty standard experience.

Confirmed questions2 questions
  • Can you introduce yourself?
  • What are your defining characteristics?
CrowdStrike logo
CrowdStrike

Cyber Security Analyst

Engineering

Intern Average Positive experience No offer 4 rounds
Interview process
Recruiter call Technical screen Take home Onsite Offer
Interview formats
Behavioral Technical Coding

I found the cyber security role on LinkedIn and applied. About a week later, they reached out for an interview scheduled for the very next day, giving me only 24 hours to prepare, which was a bit rushed. Since I was applying late, I guess that's understandable. The interview was conducted via Zoom without video. They asked some general interview questions along with some basic technical questions related to cyber security. At that point, I didn't have much knowledge in cyber security, so I didn't perform well. My initial thought was that the internship would provide a learning opportunity, as the job posting didn't mention requiring prior knowledge, but it turned out a good amount of foundational knowledge was necessary. I was informed a week later that I wasn't selected due to my insufficient cyber security knowledge. Had I progressed, the next step would have been a Host Forensics challenge, involving the analysis of CSV files that were essentially a forensic image of a computer hard drive. This task would require identifying issues within the data, such as open processes, driver information, and file system details. Following the successful completion of that challenge, a final interview would take place, after which an offer would be extended.

Confirmed questions3 questions
  • Can you explain what phishing and spear phishing are?
  • From a general standpoint, what are the steps an attacker would typically follow to infiltrate a network?
  • Could you tell me something about yourself?

CrowdStrike Security Analyst Interview Questions

Quoted word for word from CrowdStrike interview reports.

What steps would you take if a customer reported that an external IP was connected by an internal IP and the firewall flagged it as malicious?

Read reports

From a general standpoint, what are the steps an attacker would typically follow to infiltrate a network?

Read reports

Regarding a missed pen test reported by a customer, what are the potential causes and what would be the appropriate response?

Read report

How would you handle these conflicting vulnerability assessment indicators?

Read report

What's your plan when a customer reports that their EDR failed to detect malware?

Read report

What was your motivation for completing a double degree?

Read report

Formats, difficulty and experience

Across all 15 CrowdStrike interview reports.

Interview formats

Technical 43.3%
Behavioral 40%
Coding 10%
Presentation 3.3%
Case 3.3%

Interview difficulty

Easy 6.7%
Average 73.3%
Difficult 20%

Candidate experience

Positive 66.7%
Neutral 20%
Negative 13.3%