- Walk me through the full lifecycle of a log, from creation at the source to normalization and ingestion into a SIEM - Regarding EDR sensors: if the console shows the sensor as healthy or functioning correctly, but the endpoint is not reporting properly and may not actually be protected, what steps would you take to identify and resolve the issue? - A user requests that an application be whitelisted and insists it is safe. How would you validate the request? Would your approach change if the application could impact a production environment? - Describe how you would explain a technical security issue or recommendation to someone without a technical background
Check out your Company Bowl for anonymous work chats.