The short answer: penetration tester (ethical hacker) interviews test methodology, technical breadth, judgment and reporting. Expect questions on how a pentest differs from a vulnerability scan and a red team, the phases of a test (NIST SP 800-115 describes planning, discovery, attack and reporting), scope and authorization, networking and enumeration, web vulnerabilities (the OWASP Top 10:2025), Active Directory, privilege escalation, cloud misconfigurations, and how you write findings. Many teams add a hands-on lab or a report review, and almost all ask an ethics scenario. Explain your reasoning out loud: interviewers care more about how you think than whether you remember a tool flag.
The role and the market
Penetration testers are usually counted among information security analysts by the U.S. Bureau of Labor Statistics, which reports a median annual wage of $129,180 in May 2025 and projects employment to grow 21% from 2025 to 2035, much faster than average.
Methodology questions
“What’s the difference between a penetration test, a vulnerability scan and a red team exercise?”
A vulnerability scan is automated and identifies possible weaknesses. A penetration test goes further: NIST SP 800-115 notes that while scanners check only for the possible existence of a vulnerability, the attack phase of a penetration test exploits it to confirm it exists. A red team exercise emulates a realistic adversary over a longer period to test detection and response, usually with fewer people aware of it.
“Walk me through the phases of a penetration test.”
NIST SP 800-115 describes four phases:
- Planning: rules of engagement, scope, goals and written management approval.
- Discovery: information gathering and scanning, then vulnerability analysis.
- Attack: verifying vulnerabilities by attempting to exploit them, often looping back to discovery as new access reveals more.
- Reporting: which happens alongside the other phases and ends with findings and mitigation recommendations.
“What are black-box, grey-box and white-box tests?”
The tester has no prior knowledge (black box), partial knowledge such as a user account (grey box), or full knowledge such as source code and architecture (white box). Grey box is common because it uses limited time efficiently.
“What goes into rules of engagement?”
Scope (in-scope and out-of-scope systems), testing windows, allowed techniques (for example, whether denial-of-service or social engineering is allowed), data handling, emergency contacts, and what to do if you find a critical issue or evidence of a prior compromise. Always get written authorization before testing.
Network and enumeration questions
- “Explain the TCP three-way handshake.” SYN, SYN-ACK, ACK. Follow-up: a SYN (“half-open”) scan sends a SYN and reads the response without completing the handshake.
- “What would you look for on an internal network?” Live hosts, open ports and services and their versions, file shares, default credentials, outdated software, and name resolution or authentication protocols that can be abused.
- “How do you avoid disrupting production?” Agree on testing windows, throttle scans, avoid risky exploits on fragile systems, and communicate with the client’s contact.
Web application questions
The OWASP Top 10:2025 lists: A01 Broken Access Control, A02 Security Misconfiguration, A03 Software Supply Chain Failures, A04 Cryptographic Failures, A05 Injection, A06 Insecure Design, A07 Authentication Failures, A08 Software or Data Integrity Failures, A09 Security Logging and Alerting Failures, and A10 Mishandling of Exceptional Conditions. Be ready to explain several in depth.
- “How would you test for broken access control?” Use two accounts with different roles and try to access the other’s data or functions directly, for example by changing an ID in a request (an insecure direct object reference) or calling an admin endpoint as a regular user.
- “Explain SQL injection and how to prevent it.” User input changes the structure of a database query. Prevention: parameterized queries, input validation, least-privilege database accounts.
- “What are the types of cross-site scripting?” Reflected, stored and DOM-based. Prevention: context-aware output encoding, a Content Security Policy, and safe frameworks.
- “What is server-side request forgery (SSRF), and why is it dangerous in the cloud?” The server can be made to send requests to internal systems, including cloud metadata services that may expose credentials.
Active Directory, privilege escalation and cloud
- “How would you approach an Active Directory environment?” Enumerate users, groups, permissions and trust relationships, map attack paths to high-value groups, and look for weak service account passwords, excessive permissions and credential reuse. Explain the concepts (for example, why service accounts with weak passwords are a risk) rather than reciting commands.
- “How do you approach privilege escalation on Linux or Windows?” Check misconfigurations first: overly broad sudo rights, misconfigured services and scheduled tasks, writable paths, stored credentials and missing patches.
- “What do you check in a cloud environment?” Identity and access management (over-permissive roles and keys), publicly exposed storage, security group rules, logging, and secrets in code or configuration.
Reporting questions
“How do you write a finding?”
A clear title, severity (often using CVSS plus business context), affected assets, a description, step-by-step reproduction, evidence (screenshots, requests), business impact, and specific remediation. The executive summary explains the overall risk in plain language for leadership.
“How would you explain a critical finding to a non-technical manager?”
Start with the impact (“an attacker could read every customer’s records”), how likely it is, and what to do first, without jargon.
Ethics and judgment scenarios
- “You find a critical vulnerability on day one. What do you do?” Follow the rules of engagement: notify the client’s contact promptly rather than waiting for the final report.
- “You find evidence that someone else has already compromised the system.” Stop, preserve evidence, and notify the client immediately; it’s now an incident.
- “You discover a system that looks related but isn’t in scope.” Don’t test it. Note it and ask the client.
- “You come across sensitive personal data.” Access only what you need to prove the issue, don’t copy or keep it beyond what’s agreed, and report it.
The practical assessment
Many teams give a lab, a capture-the-flag-style challenge or a take-home test, followed by a review of your report. Narrate your approach, document as you go, and prioritize clear, reproducible findings over volume. Certifications are often requested, but hands-on evidence such as write-ups and lab work helps you stand out.
Behavioral questions
- “Tell me about a finding you’re proud of and how it was fixed.”
- “Tell me about a time a developer disagreed with your finding.”
- “How do you keep your skills current?”
Related guides: security engineer interview questions, security architect interview questions and DevSecOps engineer interview questions.
Frequently asked questions
What questions are asked in a penetration tester interview?
What are the phases of a penetration test?
What is the OWASP Top 10:2025?
Is a penetration tester the same as an ethical hacker?
What should I do if I find a critical vulnerability during a test?
Sources
- National Institute of Standards and Technology, SP 800-115, Technical Guide to Information Security Testing and Assessment (September 2008). Read on 1 October 2026.
- OWASP, OWASP Top 10:2025. Read on 1 October 2026.
- U.S. Bureau of Labor Statistics, Information Security Analysts, Occupational Outlook Handbook. Read on 1 October 2026.