Upload Button Icon Add office photos
Engaged Employer

i

This company page is being actively managed by Cigniti Technologies Team. If you also belong to the team, you can get access from here

Cigniti Technologies Verified Tick

Compare button icon Compare button icon Compare

Filter interviews by

Cigniti Technologies Information Security Consultant Interview Questions, Process, and Tips

Updated 19 Feb 2023

Cigniti Technologies Information Security Consultant Interview Experiences

1 interview found

Interview experience
2
Poor
Difficulty level
Moderate
Process Duration
2-4 weeks
Result
No response

I applied via Naukri.com and was interviewed in Jan 2023. There were 3 interview rounds.

Round 1 - Resume Shortlist 
Pro Tip by AmbitionBox:
Keep your resume crisp and to the point. A recruiter looks at your resume for an average of 6 seconds, make sure to leave the best impression.
View all tips
Round 2 - Technical 

(7 Questions)

  • Q1. What is Blind XSS? What is the technique to find one?
  • Ans. 

    Blind XSS is a type of XSS attack where the attacker does not receive the output of the injected script.

    • Blind XSS is also known as non-persistent XSS.

    • It is difficult to detect as the attacker does not receive any feedback.

    • One technique to find Blind XSS is to use a tool like Burp Suite to inject a payload and monitor the server response.

    • Another technique is to use a third-party service like XSS Hunter to track the payl...

  • Answered by AI
  • Q2. What is your favorite vulnerability? explain that
  • Ans. 

    My favorite vulnerability is SQL injection.

    • SQL injection is a type of attack where an attacker injects malicious SQL code into a database query.

    • It can be used to steal sensitive information, modify or delete data, or even take control of the entire database.

    • Preventing SQL injection involves using parameterized queries, input validation, and proper error handling.

    • Examples of high-profile SQL injection attacks include th...

  • Answered by AI
  • Q3. What is CRLF? explain that
  • Ans. 

    CRLF stands for Carriage Return Line Feed. It is a sequence of characters used to represent a line break in text files.

    • CRLF consists of two ASCII control characters: CR (carriage return) and LF (line feed).

    • It is commonly used in HTTP headers to separate lines of text.

    • CRLF can be exploited by attackers to inject malicious code or perform attacks such as HTTP response splitting.

    • To prevent such attacks, input validation a...

  • Answered by AI
  • Q4. How many XSS are there? what will be the mitigation?
  • Ans. 

    There are numerous types of XSS attacks. Mitigation involves input validation and output encoding.

    • There are three main types of XSS attacks: stored, reflected, and DOM-based.

    • Mitigation involves input validation to ensure that user input is safe and output encoding to prevent malicious code from being executed.

    • Examples of input validation include limiting the length of input and restricting the types of characters that ...

  • Answered by AI
  • Q5. Explain the process of SQLi. Mitigation?
  • Ans. 

    SQLi is a type of injection attack where an attacker injects malicious SQL code into a vulnerable application to gain unauthorized access to sensitive data.

    • SQLi involves exploiting vulnerabilities in web applications that allow user input to be executed as SQL commands

    • Attackers can use SQLi to bypass authentication, access sensitive data, modify or delete data, and even take control of the entire database

    • Mitigation tec...

  • Answered by AI
  • Q6. Explain the process of CSRF
  • Ans. 

    CSRF is a type of attack where a malicious website tricks a user into performing an action on a different website.

    • The attacker creates a website with a form that submits a request to the target website

    • The user visits the attacker's website and submits the form, unknowingly performing an action on the target website

    • The target website cannot distinguish between a legitimate request and the forged request from the attacke...

  • Answered by AI
  • Q7. What will be the best way to send CSRF token in the Clint Server communication?
  • Ans. 

    The best way to send CSRF token in client-server communication is through HTTP headers.

    • HTTP headers are the most secure way to send CSRF tokens.

    • The token should be sent in the 'X-CSRF-Token' header.

    • The header should be set to 'SameSite=Strict' to prevent cross-site request forgery attacks.

    • The token should be regenerated for each session to prevent replay attacks.

  • Answered by AI
Round 3 - Technical 

(3 Questions)

  • Q1. Help me understand If I need to take over a higher-privilege account with an existing lower-privilege account what are the options available?
  • Ans. 

    Options to take over a higher-privilege account with an existing lower-privilege account.

    • Use privilege escalation techniques to gain higher privileges

    • Exploit vulnerabilities in the system to gain access to higher-privilege accounts

    • Use social engineering to obtain login credentials for higher-privilege accounts

    • Use brute-force attacks to crack passwords for higher-privilege accounts

  • Answered by AI
  • Q2. Some scenario-based questions that are going to land take over an account with XSS
  • Q3. Different types of XSS
  • Ans. 

    XSS or Cross-Site Scripting is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.

    • Reflected XSS: The attacker injects a script that is reflected back to the user through a search query or form input.

    • Stored XSS: The attacker injects a script that is stored on the server and executed whenever the user visits the affected page.

    • DOM-based XSS: The attacker...

  • Answered by AI

Interview Preparation Tips

Interview preparation tips for other job seekers - I was interviewed by Cigniti and their client Linde, the second interview was organized by Linde. Both interviews cleared, but because of the time delay by Linde, the Final interview was not scheduled till now, now it's almost one month. If anyone get this kind of opportunity from Cigniti think before you accept the offer, in the end, they will not take responsibility for your time and effort. Because of the incident, I loose one of the good opportunities from another organization.

Skills evaluated in this interview

Interview questions from similar companies

Interview experience
5
Excellent
Difficulty level
Moderate
Process Duration
2-4 weeks
Result
Selected Selected

I applied via Naukri.com and was interviewed in May 2024. There was 1 interview round.

Round 1 - Technical 

(2 Questions)

  • Q1. SIEM architecture
  • Q2. API integration

I applied via Naukri.com and was interviewed in Jul 2022. There were 2 interview rounds.

Round 1 - Resume Shortlist 
Pro Tip by AmbitionBox:
Keep your resume crisp and to the point. A recruiter looks at your resume for an average of 6 seconds, make sure to leave the best impression.
View all tips
Round 2 - One-on-one 

(1 Question)

  • Q1. What are the types of risks?
  • Ans. 

    There are several types of risks, including physical, financial, reputational, and cybersecurity risks.

    • Physical risks: hazards that can cause physical harm or damage to property

    • Financial risks: potential losses or negative impacts on financial performance

    • Reputational risks: damage to a company's reputation or brand image

    • Cybersecurity risks: threats to the confidentiality, integrity, and availability of information and ...

  • Answered by AI

Interview Preparation Tips

Interview preparation tips for other job seekers - The organization is kind of okay for information security, you may reach your saturation point quickly.

Cigniti Technologies Interview FAQs

How many rounds are there in Cigniti Technologies Information Security Consultant interview?
Cigniti Technologies interview process usually has 3 rounds. The most common rounds in the Cigniti Technologies interview process are Technical and Resume Shortlist.
What are the top questions asked in Cigniti Technologies Information Security Consultant interview?

Some of the top questions asked at the Cigniti Technologies Information Security Consultant interview -

  1. Help me understand If I need to take over a higher-privilege account with an ex...read more
  2. What is Blind XSS? What is the technique to find o...read more
  3. What will be the best way to send CSRF token in the Clint Server communicati...read more

Tell us how to improve this page.

Cigniti Technologies Information Security Consultant Interview Process

based on 1 interview

Interview experience

2
  
Poor
View more

Interview Questions from Similar Companies

TCS Interview Questions
3.7
 • 10.4k Interviews
Infosys Interview Questions
3.6
 • 7.6k Interviews
Wipro Interview Questions
3.7
 • 5.6k Interviews
Tech Mahindra Interview Questions
3.5
 • 3.8k Interviews
HCLTech Interview Questions
3.5
 • 3.8k Interviews
LTIMindtree Interview Questions
3.8
 • 3k Interviews
Mphasis Interview Questions
3.4
 • 806 Interviews
KPIT Technologies Interview Questions
3.4
 • 294 Interviews
CitiusTech Interview Questions
3.4
 • 268 Interviews
View all
Senior Test Engineer
607 salaries
unlock blur

₹5.5 L/yr - ₹17.5 L/yr

Senior Engineer
510 salaries
unlock blur

₹6.5 L/yr - ₹25 L/yr

Test Lead
395 salaries
unlock blur

₹6.8 L/yr - ₹27 L/yr

Test Engineer
356 salaries
unlock blur

₹4 L/yr - ₹13.1 L/yr

Senior Software Engineer
262 salaries
unlock blur

₹5.8 L/yr - ₹23 L/yr

Explore more salaries
Compare Cigniti Technologies with

TCS

3.7
Compare

Wipro

3.7
Compare

Infosys

3.6
Compare

HCLTech

3.5
Compare
Did you find this page helpful?
Yes No
write
Share an Interview