Which user applications have you found are most susceptible to being hacked?
If you were to look at data going back for the last 10 years, you'd find that a majority of applications that were hacked are in the banking and finance industry. This is important because if the employment prospect you are applying to is in this industry, you'll likely be asked this question. Answering this question with knowledge about what type of applications get hacked the most will help the interviewer understand the depth of your knowledge on this subject. A good way to start answering these types of questions is to give examples of recent hacks in the industry of the company you are interviewing with. To really show your knowledge on this topic, give the interviewer a brief on what industries made changes that were implemented to avoid this from happening again.
"It's been my experience that the banking and finance industry has been especially targeted by hackers the most. One of the biggest reasons is obviously financial gain. Hackers seem to find vulnerabilities within banking apps and exploit them. It's estimated that 85% of web apps that are tested have flaws that hackers were able to penetrate. Using apps on your mobile phone can be risky especially if you do any sort of financial transactions. As a company policy, we have implemented two-factor authentication for all our users. This has helped reduce hacking attempts within our corporate environment significantly. We also encourage our users to update their devices on a weekly basis too."
"I've seen cases where individuals get tricked into handing over (not literally) sensitive banking or other information that eventually gets forwarded to an attacker. Protecting my mobile phone from being hacked is very important to me because I know that it is more vulnerable than a desktop, laptop, or another mobile device. One of the measures I use is to keep my phone away from public Wi-Fi. There are a couple of other ways a hacker can easily exploit vulnerabilities in a mobile phone. They can....
1.) Implement a phishing attack or infect a user with malware to gain access.
2.) Write cross-site scripting and using SQL injections to obtain access to a database then remotely run commands."
The interviewer will ask you this question for two reasons. First, they are genuinely interested in the applications that tend to be hacked and want to see if their organization uses any of these. The second is to check your knowledge about cyber security and determine if you understand which are the most vulnerable applications. They expect you to know this and be able to describe your strategy for protecting these applications and the organization's entire IT infrastructure.
Unlock all 47 Cyber Security questions
Prepare for technical scenarios and security assessments that interviewers prioritize.
Get Started