
Mandiant Interview Questions
& Process
Real candidates share what happened, how many rounds they had,
and how the experience turned out.
Based on 13 interview experiences · FREE TO READ
Which role are you interviewing for?
6 roles · 13 reportsCandidate interview experiences
First-hand accounts from people who interviewed at Mandiant.
Red Team Consultant
I only had an initial phone interview, but the recruiter was super nice and made me feel really comfortable. She asked a few questions about my work history and some technical questions. She also told me a bit about the company and the benefits they offer. Then she explained the next steps, and that was pretty much it.
- Can you tell me about your work history?
- What distinguishes a vulnerability assessment from a penetration test?
Cyber Defense Operations Consultant
Applied online and got an email from a recruiter soon after. Had an initial chat with the recruiter, then an interview with the hiring manager. The hiring manager thought I was a good fit and sent me back to the recruiter who became really unresponsive, taking about a week to reply to any emails. The recruiter would ask for my availability for the week, I'd give it, and then he'd email the next week asking again. I decided not to move forward.
- Can you describe your typical incident response processes?
- How would you approach triaging malware?
- Could you analyze small code samples to determine their purpose?
Associate Consultant
First, we had an initial interview where the interviewer went over my resume and experience. Then came the second interview, which was a technical interview. The interviewer asked basic networking questions, like explaining how a webpage gets to you and what ARP is, plus some forensics topics. What was weird was that the interviewer would interrupt me while I was answering to clarify my answer, even though I was right. This made me doubt myself and think I was wrong, but my explanation was indeed correct. It also felt like the interviewer was just reading off an answer sheet and wanted me to give exact answers. When I asked the interviewer questions, it was obvious he wasn't as confident because he started deviating from his script.
- Can you describe all the NTFS timestamps?
Cyber Security Instructor
I had a phone screen with the recruiter, about 30 minutes. After that, I had another phone screen with the hiring manager, which was about 45-60 minutes. Then, there was a 90-minute phone screen with a panel, including the hiring manager and some potential colleagues. Next, I had to present a Mandiant slide deck where they had removed the speaker notes. Finally, I gave a presentation on a topic I'm really passionate about. I was all set to get an offer, but then Google's acquisition of Mandiant happened, and they just went quiet. No real explanation, just told me to check back in a few weeks.
- Regarding technical interview with the hiring manager, can you explain the distinction between TLS and SSL?
- Could you detail the inner workings of SSL?
- What methods are available to verify the validity of a certificate?
Mandiant Interview Questions
Quoted word for word from Mandiant interview reports.
“What distinguishes a vulnerability assessment from a penetration test?”
Read reports →“What are alternative data streams?”
Read reports →“What are the common ports and numbers?”
Read reports →“What methods are available to verify the validity of a certificate?”
Read reports →“Can you describe all the NTFS timestamps?”
Read report →“On a Windows system, where should one search for evidence of persistence?”
Read report →“Explain the various registry hives and their respective use cases.”
Read report →“Could you describe alternative data streams?”
Read report →“Can you list some indicators of compromise?”
Read report →Formats, difficulty and experience
Across all 13 Mandiant interview reports.