Ethical Hacking Interview Questions 2026
20 real ethical hacking interview questions with detailed answers — covering reconnaissance, web app exploitation (OWASP Top 10), Active Directory pen-testing (Kerberoasting, BloodHound), exploit development (buffer overflows, heap), mobile app pen-testing, cloud security, methodology + reporting, OSCP exam strategy, and behavioural questions. Compiled from interview rounds at Bangalore pen-test hiring partners.
Curated by Vikas Swami (Dual CCIE #22239) — 18 years of training and placing ethical hackers.
Reconnaissance
Q. Difference between active and passive reconnaissance. Which to use first?▾
Q. Walk me through subdomain enumeration for a target.▾
Web App
Q. Find SQL injection in a parameter that's not obvious. How?▾
Q. Explain SSRF and how to escalate to RCE.▾
Q. Explain prototype pollution and give a real exploitation chain.▾
Active Directory
Q. Explain Kerberoasting attack with full chain.▾
Q. What is BloodHound and how do you use it in AD pen-test?▾
Q. Explain Pass-the-Hash, Pass-the-Ticket, and Pass-the-Key.▾
Exploit Dev
Q. Walk through a buffer overflow exploit on Linux x86_64.▾
Q. Difference between heap and stack overflow exploitation?▾
Mobile
Q. Walk me through pen-testing an Android banking app.▾
Cloud Pen-Test
Q. How would you test an AWS environment for security issues?▾
Methodology
Q. Walk me through your pen-test methodology for a black-box engagement.▾
Q. How do you write a pen-test report that gets paid?▾
Tools
Q. List the top 10 tools every ethical hacker should master in 2026.▾
OSCP
Q. What's different about OSCP exam compared to certifications like CEH?▾
Q. OSCP exam strategy — how to manage 24 hours?▾
Behavioural
Q. Tell me about the most interesting bug or attack chain you've found.▾
Q. How do you stay current with new vulnerabilities and attack techniques?▾
Q. Why do you want to work at our company specifically (vs other pen-test firms)?▾
Want personalised mock interview practice?
Our 8-month flagship includes 100+ scenario-based mock interview sessions. ₹6-14 LPA placement floor for ethical hackers with verified internship.