SOC Pre-Interview Checklist
Mental readiness, vocabulary comfort, and scenario preparation checklists for both entry-level (L1) and experienced (L2/L3) SOC candidates.
This will open your print dialog. Print as usual, or select "Save as PDF" to download.
SOC Pre-Interview Checklist
First SOC Shift Companion Guide
For Entry-Level SOC Candidates (SOC L1)
Goal: Show coachability, judgment, and foundational awareness
1. Mental Readiness Check
Before the interview, make sure you can say these out loud without hesitation:
- "An alert is not an incident."
- "Triage is about prioritization, not fixing."
- "Escalation is a strength, not a failure."
- "I'm comfortable working in uncertainty."
If any of these feel awkward, practice until they don't.
2. Vocabulary Comfort (Not Definitions)
You don't need textbook definitions, but you should be comfortable using these terms naturally:
- Alert, event, false positive, true positive
- Triage, ticket, escalation
- Phishing, authentication failure
- Monitoring, shift handover
If you can explain each in one plain sentence, you're ready.
3. Scenario Readiness
Be prepared to answer without tools:
- "What do you do when you see many alerts at once?"
- "What do you do if you don't understand an alert?"
- "When would you ask for help?"
Your answers should emphasize pattern recognition, documentation, and asking questions early.
4. Resume Alignment Check
Review your resume and remove or rephrase anything that sounds like:
- Tool obsession → Replace with "Supported triage"
- Solo heroics → Replace with "Documented findings"
- Cert bragging without context → Replace with "Assisted with investigations"
5. Red-Flag Self-Audit
Make sure you do NOT say:
- "I just block it"
- "I investigate everything myself"
- "I want to be a hacker"
If you're unsure, default to: "I document, ask questions, and escalate."
6. One Safe Closing Sentence
Have this ready:
- "I'm focused on learning how to think like an analyst, communicate clearly, and support the team."
For Experienced SOC Candidates (SOC L2 / L3)
Goal: Show maturity, leadership, and disciplined decision-making
1. Role Calibration Check
Know exactly what level you're interviewing for. Ask yourself:
- Am I expected to triage or decide containment?
- Am I supporting DFIR or leading it?
- Am I improving detection or just responding?
Tailor every answer to that scope.
2. Decision-Making Readiness
Be ready to talk through:
- Why you didn't escalate immediately
- Why you did escalate early
- When you chose containment over eradication
- When you slowed down for evidence
Avoid absolutes. Use phrases like: "Based on available evidence…", "Given uncertainty…", "To preserve evidence…"
3. Evidence & Process Discipline
Make sure you can clearly explain:
- Why reimaging is sometimes delayed
- Why documentation matters even when "nothing happened"
- How post-incident reviews drive maturity
If you can't articulate this calmly, it's a risk.
4. Leadership & Team Signals
Be prepared to demonstrate:
- Mentoring junior analysts
- Improving playbooks or SOPs
- Helping reduce alert fatigue
- Leading calm response under pressure
Avoid: "That's an L1 problem" or "I just handled it myself"
5. Detection & Improvement Mindset
Expect questions like:
- "What did you change after the incident?"
- "How do you reduce false positives?"
- "How do you balance noise vs visibility?"
Your answers should focus on rule tuning, use-case gaps, and lessons learned.
6. Professional Language Audit
Scan your talking points for:
- Overconfidence
- Dismissiveness
- Blame-shifting
Replace with collaborative, evidence-based language.