Open cardosec

18 cards · Foundations, Practitioner, Applied, Advanced, Expert

Blue team / DFIR interview questions and practice topics

Blue team, detection and incident response (DFIR): triage, log sources, SIEM detections, memory and disk forensics, and talking through an incident while it is happening.

Each card is a topic to explain out loud against the clock: 10 are real interview questions, the rest are concepts, live incidents and deep dives. Open one to see what a strong answer covers, or open cardosec and pick Blue team / DFIR as a focus.

L1 Foundations What it is

L2 Practitioner How it works

L3 Applied Abuse and defence in real systems

L4 Advanced Edge cases, bypasses, trade-offs

L5 Expert Research-grade, architecture-level

Other domains

Web AppSec · Network · Identity & AD · Cloud · Cryptography · Malware & intel · Famous breaches · GRC · AI security