All language subtitles for 1. Important Fundamental Interview questions Part1

af Afrikaans
ak Akan
sq Albanian
am Amharic
ar Arabic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew Download
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
id Indonesian
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranî)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal)
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

Hello, everyone.

So in this video, we are going to talk about fundamental questions.

Part one, basically, we have divided this fundamental questions because there are 55 questions and

we have divided it in two parts.

So let me start with what is an IPO and how does it differ from ideas?

Basically, this question always asked by the interviewer.

So let's see what exactly the IPS IP is.

Is nothing but intrusion prevention system and ideas is intrusion detection system.

Now what is the difference between the both of them?

Definitely both are the part of the network infrastructure, but how it differs.

So ideas, let's talk about the ideas.

So it is generally used for the detection of any you can see detection of traffic, right?

So whatever the traffic is flowing in your environment, it is coming to ideas.

So once it will detect something, it will send to the administrator and whatever that misses have to

do, they will do an intrusion prevention system.

We can say that there is a, you know, particular signature on which if there is something suspicious

found in the traffic related to that signature, then Ipfs is going to block that.

So this is the basic difference between these tools apart from that.

The main difference if we talk about so ideas is one of the monitoring system or and while IPC is a

control system.

So apart from that, you can just read out more information here.

Now, second question, which is one of the important, which is generally asked by the interviewer.

Explain risk, vulnerability and threat.

So here is a very easy way to learn this.

Risk, vulnerability and threat.

So let's say threat.

Threat is nothing but, you know, attack.

Or you can say a bad actor.

So this is what a threat.

So usually threat.

Exploit a one.

One liberty.

One liberty means the weakness, weakness, whatever.

The weakness of the organization through which a threat can enter.

So a threat exploits of one liberty and can damage or destroy an asset.

Vulnerability refers to a weakness in your hardware, software or procedures.

And this refers to the potential for loss or damage or destroyed assets.

So threat is nothing but a bad actor.

Vulnerability is the weakness and risk is referred to the whatever the loss already has been occurred

in your organization or whatever the damage.

So this is the basically the difference between risk, vulnerability and threat.

Moving to this part, what is the difference between asymmetry and symmetric encryption and which one

is better?

So definitely we'll talk about some asymmetric encryption.

So symmetric and give should generally use the same key for both encryption and decryption.

So let's say if there is some private and public.

Both are generally same, right?

So they will use for the encryption same key, public key and for the decryption they are going to use

again public key.

Whereas in asymmetric we have two keys, private and public key.

Now here, with the help of public key, we are going to encrypt the data, whereas with the help of

private key, we are going to decrypt it.

Right.

So usually what happens in asymmetric encryption, it takes much time because we have to encrypt, then

we have to decrypt it as well if we have to send it.

Right.

So it is taking much time then submitting encryption and that's why the symmetric encryption is faster,

whereas the asymmetric encryption is slow, but asymmetric encryption is much more secure than the symmetric

encryption.

That's why asymmetric I'm talking about this answer, which one is better?

So that's why asymmetric encryption is much better.

Now what is excesses?

How will you mitigated excesses when I hope you have done some bug bounty or something?

And you might have heard this exercise, right?

And if you are fresher, then definitely I would suggest to you again that you can just go on Udemy.

There will be a course of cyber community bug bounty or offensive hunting codes, so you can take that

course.

That is a very minimum price maybe, I guess 360 you can directly contact me on cyber community and

we'll give you a link of 30 ₹60.

Now what is access to?

Access is in ultimate cross-site scripting in which we generally we use JavaScript only within web application.

So the easiest way to explain this is a case when a user interface script in the client side.

Now here one.

One main thing to remember is that the interviewer can ask that what exactly the access attack is.

So you can tell them that accesses is a client side attack, right?

Exercise is a client side attack right now.

What we can do to mitigate this, generally what we can do, we can input the validation, we can use

it, we can implement a CSP that is content security policy.

We can sanitize the input.

These, these three things we can do as a mitigation part.

What is the difference between encryption and hashing?

So generally encryption is a two way, two way and we can say reversible hashing is non reversible.

Why I'm saying this because you know, once there is a data, we are we are encrypting it right and

then we are decrypting it.

That's why it's reversible.

Whereas hashing is not because once the hash, you know, once the any file we got the hash value for

that, it is not going to reverse that.

It is not going to to reverse all data of that file.

Right.

So but hashing can be correct using rainbow tables and collision tags and encryption.

What encryption ensures it ensures confidentiality, whereas hashing ensures integrity.

Integrity means there is no modification of sorry.

There is no modification.

Modification of data.

Now what is creative?

I have also discussed CSR of In Bug Bounty, so you can go through that course as well.

Now cross-site scripting a request rate of OCD is a web application in which the server does not check

whether request came from a trusted client or not.

So let me give you an example.

Right, right.

So.

Let's say there is a web application, right?

And you are one of the user.

I'm another user.

So what I will do, I'm changing something on my account on that web application.

I'm changing in my profile section.

Now, with the help of brute force.

I have taken all those things and I'm sending one of the HTML file and you are directly clicking on

that.

So all changes, whatever I have done in my account that is also reflecting in in your account.

Right.

So this is what I see as RDF.

And actually the server is not knowing that from where exactly it is coming.

So it is thinking that you are the person who is doing it.

So that's why from my point of view, CSV is a server side attack but some somewhere it is also written

as a client side attack because generally it is happened due to the mistake of client or we can say

a victim.

Now the difference between Texas and Seattle is we have discussed both of them.

I hope you understand exercise is much more dangerous than CSR because it's a client side attack.

Right?

And it can steal your credentials, password or whatever, the very important data you can say.

So this is what the difference.

And you can read more things with the help of this video file now is the access client said okay we

have already discussed this one now what is IOC so indicator of compromise?

So let's say you have seen hash value IP domain you are a user is and now if these are malicious these

are suspicious then it means these are the indicators of showing something is malicious, something

is suspicious.

So that's why we call it indicator of compromise, just for generally to know all those things.

We we see that whether the IP is malicious or not, whether the domain you are l user isn't or you can

say the hash values malicious or not.

Okay.

Now antivirus versus idea.

This is one of the important question.

Believe me, guys, I have given a lot of interviews and I have take the feedback from my seniors,

my juniors and everybody tell that they always ask this question antivirus versus EDR.

Maybe they will ask you about firewall versus antivirus versus EDR.

So you can also go through my YouTube channel and you will also get the whole video of that.

Now, area is all definitely we know it's an endpoint detection response.

Right?

And it works on real time monitoring and detection of threats.

So it's a behavior based, right?

It is behavior based.

Whereas antivirus is your signature based means there is some predefined signatures.

And on those basis, antivirus is detecting the suspicious traffic.

Or you can see the malware.

Whereas EDR is the real time monitoring, it's a behaviour based so there is inbuilt sandbox and they

are going to analyze each and everything that what actually the pattern analysis that what actually

the pattern is happening.

So that's what basic difference between ADR and antivirus.

Now, here is one question.

Do I need both?

Well, our area is also having the signature.

You know, there is predefined signatures, but along with that, it is having the.

Behavior analysis, you can say, right, so it is sufficient, but you can even keep both the idea

and antivirus.

But it is sufficient for the organization.

What is a firewall?

A firewall is a network security system that monitors and controls incoming and outgoing network traffic

based on the predefined security rules.

It means there is a particular predefined rules and on those basis.

It is taking the or you can directly saying you can directly say it filtering the traffic on the basis

of predefined security rules.

Now.

What is the difference between IPS and firewall?

So the main difference being that firewall performs actions such as blocking and filtering of traffic.

And while an IPS detects an alert system engine or you can stop prevent the attacks as part of the configuration.

So generally, if if the interviewer is, you know, he's expecting more answers from you so you can

add here more things like a firewall generally captures the header IPS captures the.

Bailer So Pharrell, what, what actually Pharrell captures in the header form they capture, you know,

IP addresses, source IP, destination IP, port numbers, domain URL, these things they capture,

whereas IP is capture IP check whether there is something known malware, something known suspicious

thing is there in that payload or not.

So on those bases, if there is something malicious, they will detect it and they will block it.

Now question number 13, what is a security misconfiguration?

So security misconfiguration is a vulnerability when a device or against the application network is

configured in a way that can be exploited by an attacker to take advantage of it.

So this can be as simple as leaving the default username password engine.

So only this question.

This is very less chances of asking this question by the interview, but they can ask this question.

So you should remember that what actually the other security misconfiguration.

Now.

What is a black hat?

White hat and grey hat.

Now, let me complete this in a very beautiful manner.

So Black Hat is nothing but a hacker who has no no authority.

But he is hacking.

Right.

Whereas White Hatter is also known as the, you can say, ethical hacker who have the legal authority

to perform the actions.

And Grey Decker is just a combination of black and white head echo.

Now.

Question 15 How do you keep yourself updated with the information security news?

So guys, this one is very important because definitely they are basically these two questions which

I'm marking.

These questions are two questions are very important because definitely they will ask you that how you

keep yourself updated.

So you can you can start reading the blogs such as trend micro blogs.

I can use ZB hackers, you know, and apart from that, they can also also name some reason that I can

explain in brief.

Right.

So if you are reading something, you are updating your self, then definitely you should be aware about

the latest vulnerability, recent attack.

So for example, as far as I'm making this video, so the recent attack is, you know, is spring for

one liberty or and you can also include the law lock for the liberty.

So these are the some recent attacks.

You should focus on these two questions now.

What is CIA?

CIA is nothing.

But, you know, our trade, you can say confidentiality, integrity, availability.

Now, what is confidentiality?

Keeping the information secret integrity is nothing but keeping the information unaltered.

Unaltered means there will be there should be no modification.

Availability information is available to the authorized parties at all times.

Now hear ideas, verses and ideas and which one is better and why.

So what is ideas?

Is a host intrusion detection system and idea.

See is network intrusion detection system.

Now, the difference here is that maintaining the ideas is, you know, very tough because we will get

a lot of traffic with that from ideas, whereas managing their needs is too easy.

So as for the enterprise, an idea is preferred as ideas is difficult to manage.

So this is what the basic difference.

And you can read more things on Google here.

What is what is scanning?

What is scanning is the process of sending messages.

In order to gather information gathered.

Information means requirements for the requirements we use for scanning.

Write about the network system and definitely which body actually is open so that they can they can

think about entering from that port number in the organisation.

So this is what the port is scanning.

Now what is the difference between V and PD?

There is some you can say the minor difference.

So one assessment is an approach used to find flaws.

In an application network.

Whereas penetration testing is the practice of finding exploitable vulnerabilities like a real attacker

do.

So via is like traveling on the subway surface where Speedy is digging it for a gold.

Now let's move to question number 21.

And this is one of the important questions.

Can you name some response codes from a Web application?

Well, yes.

See, you might have seen 201 200 code, right?

301 302 error code 404.

Right.

So what exactly.

Those things.

Right.

So if there is some something error is coming or something go astray as gdb code is starting from one

and then accesses maybe 0110 whatever up to 199.

Then it's information, responses and the code, which is starting from two.

Then it means the success is starting from three.

It means redirection.

Starting from four blindside error and starting from fifth is server side error rate.

Now, when do you use stress or stress?

Now what exactly?

That is why we are using it, actually.

So let's say if you are not able to ping any destination, then here we can use a trace or trace route

or you can say that trace.

And this will definitely help us to identify where the connection is, stops or gets broken where.

Right.

So and it will also help us to know that whether it's a it's a firewall, whether it's ISP, whether

it's a router, etc., etc..

So with the help of this trace route or trace it, we will get to know where exactly the connection

is breaking.

Lidos and it's mitigation so severe, we know it's a distributed denial of service, right?

So when a network goes, our application is flooded with a large number of requests, which is which

which is not designed to handle making the server unavailable to legitimate requests.

So let's, let's take an example.

Let's.

There is a web server and they it can only take 100 requests per minute.

Right now, you are a hacker and you just.

You are doing the DDoS attack and you are requesting 200 or let's say 101.

Right.

That's 101 request per minute.

Then what will happen?

The the server is not going to reply to the legitimate person who is asking for something.

Right.

So this is what the DDoS it means the flooding of the traffic far after you can say more than the bandwidth

of the server.

So this can be mitigated.

This can be mitigated with the help of a scrubbing center.

And scrubbing center is nothing but one of the center which generally block the traffic of the doors.

And it only filters the legitimate it it passes through only legitimate traffic.

What is RAF?

RAF is nothing but a web application firewall, so it is used to protect the application by filtering

legitimate traffic from malicious traffic.

So if there is a lot of traffic coming, then it will only filter that legitimate traffic and malicious

traffic it is going to filter out.

There can be either a box type or cloud based.

How do you handle antivirus alerts?

This can be asked by the interview, so check the policy for the EVI and then alert.

If the alert is for a legitimate file, then it can be whitelisted, right?

And if it is malicious, then definitely we need to quarantine or we we are going to delete it.

So the hash of the file can be checked for depredation on various websites like VirusTotal, malware,

etc..

So see, let's say if there is a file of BitTorrent, right?

And definitely the hash value is going to generate for that.

So you can directly check the hash, whether it's malicious or not, you can check for that file whether

there is something or not.

So if it is legitimate, legitimate, you can whitelist.

If it is malicious, you can delete it.

Blue teaming versus red teaming.

So every teaming is an attacker and a blue teaming is defender.

So being on the red team seems fun, but being in the blue team is difficult.

As you need to understand the text and metrology, the red teams may flow.

So as a blue team you have to defend all those attacks with the help of tools, with the help of your

knowledge, with the help of your investigations.

Next question.

We have what is a false positive and false a negative in case of ideas?

Which one is more acceptable?

Right.

So when the device generated an alert for an intrusion, that it has actually not happened.

So what exactly the false word is positive is right.

So let's say you have set one of the rules.

Right.

But let's say for brute force that there is a logic that there is ten failures for a minute.

Right.

But alert is generating generated four, five, five failures for a minute, then definitely it's a

false positive because we didn't set up a rule for that.

And it is a false positive.

Now, what is that false?

Negative.

So now if the device has not generated any alert and then the intrusion has actually happened, then

this is the case of false negative.

Well, false positives are more acceptable.

False negatives will led to intrusion happening without getting noticed.

Now, let's see the last question.

What is the data leakage?

So data leakage or we simply call it DLP.

How will you detect and prevent it?

Well, organizations are using different types of DLP.

Many companies are providing it, let's say McCafé, providing the DLP.

So we can use the DLP software.

Right.

Just to check whether if if there is some person who is sending the confidential or sensitive data outside

the organization or not.

So it ensures that the data is not leaking.

So that's it, guys, and we'll meet in the next video.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.