Help desk • Desktop support • Accounts and access • Phishing • 2026

IT Support Interview Questions

30 questions What each one tests, an answer frame, a spoken answer 34 min read

This page is for help desk and desktop support interviews, from first-line roles to experienced analysts. Most rounds test two things at once: whether you fix problems in a calm, logical order, and whether users walk away feeling looked after. Expect a few questions on why you chose this work, hands-on scenarios like a PC that won't boot or an account that keeps locking, some Active Directory and email basics, and stories about angry users, mistakes and escalations. Each question shows what the interviewer is really checking, a shape for your answer and a short answer you could say out loud. Swap in your own stories and the tools you actually used.

Search all questions by round, difficulty and level, or save the ones you want to practise.

Motivation 3 questions

Easy Screening round Fresher, Mid-level Practice question

1. Walk me through how you ended up in IT support, and what you actually enjoy about fixing things for people.

What the interviewer is really testing:
Whether you chose support on purpose and like both halves of it: the puzzle and the person waiting on the other end.
Answer frame:

Path: the short version, one or two steps that brought you here.

What you enjoy: name the specific part, such as tracing a cause or calming a stressed user.

Next: why this desk is the right next step.

Sample spoken answer:

"I was the person in my family and my friends' group who got called whenever a laptop stopped working, and I realised I liked it more than I let on. At college I took a part-time job at the campus help desk, mostly resetting passwords and fixing Wi-Fi on student laptops. What hooked me was the moment you find the real cause, like the time a whole lab couldn't print and it turned out to be one stuck job blocking the queue. I also like that the person usually leaves less stressed than they arrived. I want a proper service desk role now because I'd like to work on a wider range of problems, learn Active Directory and email admin properly, and grow into second-line work over time."

Red flag to avoid:

Saying support is just a way in until something better comes along, with nothing you enjoy about the work itself.

They may ask next:
  • Which kind of ticket do you find least interesting, and how do you still do it well?
  • Where would you like to be in two or three years?
Say it in 60 seconds
Easy Screening round Fresher, Mid-level, Senior Practice question

2. Beyond fixing broken computers, what do you think a good help desk does for the rest of the company?

What the interviewer is really testing:
Whether you see support as keeping people productive and the company safe, not just closing tickets.
Answer frame:

Keeps work moving: every ticket is someone who can't do their job right now.

Front door: users judge the whole IT team by the desk.

Early warning and safety: spotting patterns, outages and phishing before they spread.

Sample spoken answer:

"I think the main job is keeping people able to do their work. Behind every ticket is someone who's stuck, so a fast, clear fix matters more than a perfect one delivered tomorrow. The desk is also the front door of IT. Most staff never meet the network or server teams, so how we answer the phone is how they judge IT as a whole. And the desk is an early warning system. If five people call about the same error in ten minutes, we're often the first to know there's an outage, and we're usually the first to hear about a suspicious email. A good desk notices those patterns, passes them on quickly, and writes things down so the same problem gets solved faster next time."

Red flag to avoid:

Describing the job only as resetting passwords and closing tickets fast, with no mention of the people or the business.

They may ask next:
  • How would you know whether a help desk is doing a good job?
  • What do users find most frustrating about IT, in your experience?
Say it in 60 seconds
Easy Screening round Fresher Practice question

3. Outside of a job, what have you set up, broken or fixed yourself that taught you something useful for support work?

What the interviewer is really testing:
Whether your interest goes beyond a course, and whether you learn by doing and can explain what you learned.
Answer frame:

What you built or fixed: one concrete project, small is fine.

What went wrong: the problem you hit.

What it taught you: the skill that carries into a help desk.

Sample spoken answer:

"Last year I set up a small lab on an old desktop with a free virtualisation tool. I built a Windows Server trial as a domain controller and joined a Windows client to it, then made users, groups and a couple of group policies. The part that taught me the most was when my client couldn't join the domain at all. After a while I found it was pointing at my home router for DNS instead of the domain controller, so it couldn't find the domain. Fixing that made DNS click for me in a way the course never did. I also rebuilt my parents' laptop when it got very slow, which taught me to back up first and ask what they actually use before wiping anything."

Red flag to avoid:

Listing certificates or courses with no hands-on example, or a story you can't explain when asked one layer deeper.

They may ask next:
  • What would you set up next in that lab, and why?
  • How did you work out that DNS was the problem?
Say it in 60 seconds

Troubleshooting 8 questions

Easy Role knowledge round Fresher, Mid-level Practice question

4. When a ticket comes in and you have no idea what's causing it yet, what's your general troubleshooting approach?

What the interviewer is really testing:
Whether you work in a repeatable order instead of guessing, and whether you check what changed and confirm the fix.
Answer frame:

Gather: exact error, who is affected, when it started, what changed.

Scope and test: one user or many, then test the likeliest cause first, one change at a time.

Fix, confirm, record: check with the user it works, then write up cause and fix.

Sample spoken answer:

"I start by getting the facts instead of guessing. What exactly happens, is there an error message, when did it start, and did anything change, like an update, a new password or a move to another desk. Then I work out the scope. If it's one person it's probably their device or account, and if it's a whole team I'm looking at something shared like a server, the network or a service outage. After that I test the most likely and cheapest cause first and change one thing at a time, so I know what actually fixed it. Once it works I ask the user to confirm it on their side, not just take my word for it. Then I write up the cause and the fix in the ticket so the next person has a head start."

Red flag to avoid:

Jumping straight to reinstalling or reimaging without asking a single question or checking scope.

They may ask next:
  • What do you do when the user can't tell you what changed?
  • How do you know when to stop and escalate?
Say it in 60 seconds
Medium Role knowledge round Fresher, Mid-level Practice question

5. A user says their desktop PC won't start this morning. Talk me through how you'd narrow it down.

What the interviewer is really testing:
Whether you can split 'won't start' into no power, no display, and no operating system, because each points to a different fix.
Answer frame:

No power: no lights or fans, so check cable, socket, power strip and power supply.

Power but no picture: check monitor, its cable and input, then beeps or lights that suggest a hardware fault.

Stops before Windows: boot device errors, a USB stick left in, failing disk, or startup repair.

Sample spoken answer:

"First I'd ask what 'won't start' means, because users use it for three different problems. If there are no lights and no fans at all, it's power: I'd check the cable is seated, the wall socket works, the power strip is switched on, and try a known good cable. If the PC powers up but the screen stays black, I'd check the monitor is on, the cable is in the right port and the input is set correctly, which fixes more of these than you'd think. If it beeps or shows diagnostic lights, that usually points to memory or other hardware, so I'd escalate or swap the unit. If it gets past that but says no boot device, I'd check for a USB stick left in, then the boot order, and then the disk itself. If Windows starts loading and fails, I'd try the built-in startup repair or safe mode, and ask whether an update ran overnight."

Red flag to avoid:

Treating every 'won't start' the same way and heading straight for a reimage without checking cables or the monitor.

They may ask next:
  • What would you do first if you suspect the hard drive is failing?
  • How would you handle this if the user has an important file on that machine and a deadline today?
Say it in 60 seconds
Medium Role knowledge round Fresher, Mid-level Practice question

6. Someone says their laptop has got really slow over the past week. What do you look at, and in what order?

What the interviewer is really testing:
Whether you measure before acting, separate the laptop from the network or an app, and look for what changed.
Answer frame:

Clarify: slow at everything, or one app, website or shared drive.

Measure: Task Manager for CPU, memory and disk, plus free disk space and time since last restart.

Causes: startup programs, pending updates, a new app, malware, or hardware that is simply too small.

Sample spoken answer:

"I'd first ask what's slow. If it's only one web app or the shared drive, that's likely the network or the server, not the laptop, and I'd check whether colleagues see the same. If everything is slow, I'd open Task Manager and see what's using the CPU, memory and disk. A process stuck at high usage usually tells the story. I'd check free disk space, because a nearly full drive slows everything down, and how long since the last restart, since some people never restart. Then I'd look at what changed this week: a new program, a big update half installed, a lot of new startup apps or browser extensions. I'd run a malware scan to rule that out. If it's an older laptop with little memory and a spinning disk, the honest answer might be an upgrade, and I'd raise that with the user's manager."

Red flag to avoid:

Saying you'd just run a cleanup tool or reinstall Windows without looking at what is actually using the resources.

They may ask next:
  • Task Manager shows the disk at maximum but nothing obvious is using it. What next?
  • How would you explain to the user why restarting actually helps?
Say it in 60 seconds
Medium Role knowledge round Fresher, Mid-level Practice question

7. One computer in the office has no internet, but everyone sitting around it is fine. How do you find the cause?

What the interviewer is really testing:
Whether you test the network step by step from the cable up, and can read an IP address to tell a DHCP problem from a DNS one.
Answer frame:

Physical: cable seated and link light on, or connected to the right Wi-Fi.

Address: ipconfig; an address starting 169.254 means it never got one from DHCP.

Reach and names: ping the gateway, then an outside IP, then test a name with nslookup to spot DNS.

Sample spoken answer:

"Since the neighbours are fine, the network as a whole is working, so it's something about this machine or its connection. I'd check the basics first: is the cable in and the link light on, or is it on the right Wi-Fi network and not a guest one. Then I'd run ipconfig with the all switch. If the address starts with 169.254, the PC didn't get an address from DHCP, so I'd release and renew, and if that fails I'd try another cable or wall port. If it has a proper address, I'd ping the default gateway, then an outside IP address. If IPs work but websites don't, that's DNS, so I'd check the DNS servers it's using, flush the DNS cache and test with nslookup. I'd also check for a static IP someone typed in, proxy settings, or a VPN client stuck half connected."

Code:
ipconfig /all
ipconfig /release
ipconfig /renew
ping <default-gateway-ip>
nslookup intranet.example.com
ipconfig /flushdns
Red flag to avoid:

Restarting the office router when everyone else is working, or not knowing what a 169.254 address means.

They may ask next:
  • The PC can ping the gateway but not anything outside. Where do you look?
  • What would make you suspect an IP address conflict?
Say it in 60 seconds
Medium Role knowledge round Fresher, Mid-level Practice question

8. Nobody on one floor can print to their shared printer this morning. Where do you start?

What the interviewer is really testing:
Whether you use the fact that many people are affected to rule out individual PCs, then check the printer, the network and the print queue in order.
Answer frame:

Scope: everyone on one printer means the printer, its connection or the print server, not the PCs.

Printer itself: display errors, paper, toner, jams, offline or sleep mode.

Path to it: ping the printer's IP, then check the queue for a stuck job and the print spooler.

Sample spoken answer:

"Because it's the whole floor, I can mostly rule out individual PCs, so I'd go to the printer or ask someone next to it what the screen says. A jam, an empty tray or a toner error explains a lot of these. If the printer looks healthy, I'd check it's on the network by pinging its IP address, and look at its network settings in case it picked up a new address. Then I'd check the print queue, either on the print server or on one user's PC if they print directly. A single stuck job at the top can block everything behind it, so I'd clear that job, and if the queue won't clear I'd restart the print spooler service. I'd also ask whether anything changed, like a driver update pushed overnight. Once it prints, I'd send a test page and let the floor know it's working again."

Red flag to avoid:

Going desk to desk reinstalling the printer on every PC before checking the printer and the queue.

They may ask next:
  • Only one person on that floor can't print, and everyone else can. What changes in your approach?
  • The printer keeps changing IP address. How would you stop that?
Say it in 60 seconds
Medium Situational round Fresher, Mid-level Practice question

9. A remote worker can't connect to the VPN and presents to a client in twenty minutes. You can't remote in because they're not on the network. How do you help?

What the interviewer is really testing:
Whether you can troubleshoot by voice alone, check the obvious causes fast, and find a workaround when time runs out.
Answer frame:

Internet first: can they open any public website; if not, it's their home connection, so try a phone hotspot.

VPN specifics: the exact error, an expired or locked password, restart the client and reconnect.

Workaround: if time runs short, get the presentation from cloud storage in a browser, then fix the VPN after.

Sample spoken answer:

"With twenty minutes, I'd go for the fastest checks and a backup plan at the same time. First, can they open any normal website? If not, the VPN isn't the problem, it's their internet, and a phone hotspot often gets them going. If the internet works, I'd ask them to read me the exact VPN error. A very common one for remote staff is a password that expired while they were off the network, so I'd check their account for an expired password or a lockout while we're talking. Then I'd have them quit and restart the VPN client and try again. If we're still stuck with ten minutes to go, I'd switch to getting the presentation: if it's in cloud storage they can open it from a browser without the VPN. After the meeting, I'd book a proper session to fix the real cause."

Red flag to avoid:

Spending the whole twenty minutes on the VPN with no backup plan for the presentation itself.

They may ask next:
  • How do you guide someone through steps on their screen when you can't see it?
  • The VPN connects but nothing internal opens. What would you suspect?
Say it in 60 seconds
Hard Behavioral round Mid-level, Senior Practice question

10. Tell me about the trickiest support ticket you've solved. How did you work out the cause?

What the interviewer is really testing:
Whether your method holds up on a hard problem: gathering evidence, forming guesses, testing them, and not giving up too early.
Answer frame:

Problem: the symptom and why it was hard, such as intermittent or affecting only some users.

Investigation: the clues you gathered and the ideas you ruled out.

Cause and fix: what it really was, and what you did so it didn't come back.

Sample spoken answer:

"At my last company, a handful of users kept getting dropped from video calls, but only in one part of the building and only some afternoons. It looked random at first. I started logging each drop with the time, the user and where they sat, and after a week there was a clear pattern: every one was on the same wireless access point, and the drops lined up with a meeting room next to it filling up. I passed that evidence to the network team, and they found the access point was overloaded and on a busy channel. They adjusted it and added a second one. The drops stopped. What I took from it is that when something looks random, writing down every occurrence usually shows the pattern."

Red flag to avoid:

A story where the fix was a lucky reboot and you can't explain what the cause actually was.

They may ask next:
  • What did you rule out along the way, and how?
  • If the network team had said the Wi-Fi was fine, what would you have done next?
Say it in 60 seconds
Medium Behavioral round Fresher, Mid-level Practice question

11. Tell me about a problem you fixed for someone over a remote support session. How did you run the session from start to finish?

What the interviewer is really testing:
Whether you run remote sessions with the user's consent and trust, explain what you're doing, respect their privacy, and confirm the fix before you disconnect.
Answer frame:

Before connecting: confirm who they are, get their permission, ask them to close anything private.

During: say what you're doing as you do it, and ask before restarting or closing their work.

Before leaving: have them test it themselves, disconnect, and note what you changed in the ticket.

Sample spoken answer:

"At my last job a user working from home couldn't get her second monitor to show anything after a docking station swap. Before I connected, I confirmed who she was from the ticket, told her I'd need to see her screen and asked her to close her email and anything personal. Once connected, I talked through each step so she wasn't just watching a mouse move on its own. I found the display settings set to show only the laptop screen and an old display driver, so I asked before restarting, since she had a spreadsheet open, and let her save it first. After the restart, I had her drag a window across to the new screen herself. Then I disconnected, told her I'd gone, and wrote the driver fix in the ticket."

Red flag to avoid:

Taking control without asking, clicking around silently, or disconnecting before the user has confirmed it works.

They may ask next:
  • How do you help someone who can't get the remote tool installed or started in the first place?
  • What would you do if you saw something private or worrying on a user's screen during a session?
Say it in 60 seconds

Accounts and Access 4 questions

Hard Role knowledge round Fresher, Mid-level Practice question

12. A user changed their password yesterday and has been locked out three times since, even though they're typing the new one. What do you check and fix?

What the interviewer is really testing:
Whether you connect lockouts right after a password change to a device still trying the old password, and walk the user through clearing it everywhere instead of just unlocking again.
Answer frame:

Link it to the change: lockouts that start right after a new password nearly always mean something still has the old one.

Go through their devices: phone email, the office Wi-Fi saved on a phone or tablet, a second laptop, saved Windows credentials, mapped drives.

Confirm the source: if nothing obvious turns up, check the lockout event for the computer the bad attempts came from.

Close properly: unlock, update each device with the new password, check the account next day.

Sample spoken answer:

"When lockouts start the day after a password change, I assume the user is right and something else still has the old password. So I'd unlock the account and go through their devices with them. The usual one is email on their phone, which keeps trying the old password in the background. Next is the office Wi-Fi saved on a phone or tablet, if our Wi-Fi uses their work login. Then a second laptop, saved entries in Windows Credential Manager, or a mapped drive set up with saved credentials. We'd update or remove the old password on each one. If none of that explains it, I'd check the lockout event on the domain controllers, event 4740, which names the computer the bad attempts came from, or ask the systems team to. Then I'd check the account the next morning before closing the ticket."

Red flag to avoid:

Unlocking the account again and again without looking for the device, or telling the user to type more carefully.

They may ask next:
  • The lockout event points to a computer the user says they've never used. What does that make you think?
  • How would you help a user change their password so this doesn't happen next time?
Say it in 60 seconds
Easy Role knowledge round Fresher, Mid-level Practice question

13. In plain words, what is Active Directory, and which jobs in it does a help desk analyst handle day to day?

What the interviewer is really testing:
Whether you understand the building blocks well enough to unlock, reset and check access safely, and know where the desk's rights end.
Answer frame:

What it is: the central list of users, computers and groups that handles sign-in on a Windows domain.

Desk jobs: find the user, check locked, disabled or expired, unlock, reset with a forced change, check group membership.

Groups and OUs: groups give access; OUs organise accounts and decide which ones the desk is allowed to manage.

Where you stop: deleting accounts, admin accounts and group policy belong to the admins.

Sample spoken answer:

"Active Directory is the company's central list of who and what is on the Windows network: user accounts, computers and groups. When someone signs in to a work PC, a domain controller checks their password against it. On the desk I'm in it all day. I search for the user, check whether the account is locked, disabled or expired, unlock it, and reset passwords with the option that makes them choose a new one at next sign-in. I also check group membership, because groups are how access is given, so if someone can't open a folder I compare their groups with a teammate's. OUs are like folders that organise accounts, and the desk usually only has rights over certain ones. Things like deleting accounts, admin accounts or group policy I leave to the system admins."

Red flag to avoid:

Saying OUs are what give people access, or treating every button you can click in the console as yours to use.

They may ask next:
  • What's the difference between disabling an account and deleting it, and when would you do each?
  • You reset a password and the user still can't get into email with it. What might be going on?
Say it in 60 seconds
Medium Role knowledge round Fresher, Mid-level Practice question

14. A user can't open a shared folder that the rest of their team can. How do you sort it out properly?

What the interviewer is really testing:
Whether you grant access through the right group with approval, and know why it may not work until the user signs in again.
Answer frame:

Check first: the exact path and error, and which group gives the team access.

Approval: confirm the folder owner or manager agrees before granting anything.

Grant and refresh: add them to the group, then have them sign out and back in so the change takes effect.

Sample spoken answer:

"I'd get the exact path and error first, because sometimes it's just a typo or a drive letter mapped to the wrong place. If it's a real access denied, I'd look at the folder's permissions to see which security group the team gets access through, and check whether the user is in it. Very often they're new or moved from another team and never got added. Before I add anyone, I'd check it's approved by the folder owner or their manager, depending on our process, and note that in the ticket, since access to data isn't something the desk should decide alone. Then I'd add them to the group, not to the folder directly. Group changes usually don't apply until the user signs out and back in, so I'd ask them to do that and test the folder with them."

Red flag to avoid:

Granting access because a user asked nicely, or adding them straight to the folder with no approval recorded.

They may ask next:
  • They're in the right group and have signed back in, but still get access denied. What might be different about their access?
  • Why not just add the user straight onto the folder's permissions?
Say it in 60 seconds
Medium Role knowledge round Fresher, Mid-level Practice question

15. Walk me through getting a new starter's account and laptop ready so they can work on their first morning.

What the interviewer is really testing:
Whether you can run a routine but important process end to end, with the right access and nothing extra.
Answer frame:

Request: an approved request from HR or the manager with role, team and start date.

Account: create it from a role template, add the right groups and licences, set a temporary password.

Device and day one: prepared laptop, record the asset, then sign-in, MFA setup and a quick walkthrough.

Sample spoken answer:

"It starts with an approved request from HR or the hiring manager that gives me the name, role, team and start date. I'd create the account from a template for that role, not by copying another person's account, because copying drags along whatever extra access they've built up over the years. Then I'd add the groups for their team, assign an email licence and set a temporary password that must be changed on first sign-in. For the laptop, I'd make sure it's enrolled in our device management, encrypted, updated and has the standard apps, and I'd record the asset against their name. On the first morning, I'd sit with them for sign-in, help them set up MFA on their phone, check email, the shared drives and printing, and show them how to raise a ticket."

Red flag to avoid:

Copying a colleague's account wholesale or setting up access before any approved request exists.

They may ask next:
  • The manager asks you to give the new person the same access as someone else on the team. How do you respond?
  • What would you check before handing the same laptop to a second new starter later on?
Say it in 60 seconds

Email and Office 1 questions

Hard Role knowledge round Fresher, Mid-level Practice question

16. A user says Outlook keeps popping up asking for their password and won't connect. How do you work it out?

What the interviewer is really testing:
Whether you separate account, service and local client problems quickly, starting with the web version as a test.
Answer frame:

Service or user: check the provider's service status and whether others are affected.

Account or client: if webmail works with the same password, the account is fine and the problem is on the PC.

Local fixes: stale saved credentials, sign-in or MFA state, add-ins in safe mode, updates, then a new profile.

Sample spoken answer:

"First I'd check whether it's just them. If several people have it, I'd look at the service health page for a wider outage. If it's one user, I'd ask them to sign in to the web version of their mailbox. If that fails, it's the account: maybe the password expired, the account is locked, or there's a problem with their MFA sign-in, and I'd fix that. If the web version works, the account is fine and the issue is on the PC. Then I'd ask whether they changed their password recently, because Windows may still hold the old one, and I'd clear the saved Office entries in Credential Manager and sign in again. If that doesn't do it, I'd start Outlook in safe mode to rule out an add-in, make sure Office is up to date, and as a last step create a new Outlook profile."

Red flag to avoid:

Rebuilding the profile or reinstalling Office first, without checking whether the account itself works.

They may ask next:
  • Webmail works, but Outlook still prompts after a new profile. What would you try next?
  • How would you handle this for someone who travels and is only reachable by phone?
Say it in 60 seconds

Security Awareness 4 questions

Easy Role knowledge round Fresher, Mid-level Practice question

17. A user forwards you a 'your mailbox is almost full, click here' email and asks if it's safe. What do you check, and what do you tell them?

What the interviewer is really testing:
Whether you can spot the usual signs quickly and reply in a way that makes the user glad they asked, so they report again next time.
Answer frame:

Sender: the real address and domain, not just the display name, and lookalike spellings.

Content: urgency, a sign-in request, links whose real address differs from the text, unexpected attachments.

Reply: thank them, tell them not to click, use the report button, and pass it to security.

Sample spoken answer:

"I'd look at the actual sender address, not just the name shown. These often come from a free mail account or a domain that's one letter off ours. Then the link. Hovering over it shows where it really goes, and it's usually some random site with a login page dressed up to look like ours. The message itself gives it away too: a vague greeting, a rush to act before your mailbox is closed, and a request to sign in, which our IT never asks for by email. I'd tell the user it's phishing, thank them for checking, and ask them to report it with the report button and then delete it. I'd also pass it to the security team so they can block the sender and pull it from anyone else who got it."

Red flag to avoid:

Answering 'just delete it' with no thanks, no report and no word to the security team.

They may ask next:
  • What would you do if the user had already clicked the link before asking you?
  • How would you encourage people to report emails like this more often?
Say it in 60 seconds
Hard Situational round Fresher, Mid-level, Senior Practice question

18. A caller says they're a senior director, locked out before a big meeting, and demands a password reset now. They can't answer the verification questions and get angry. What do you do?

What the interviewer is really testing:
Whether you hold the identity check under pressure, while still working hard to help the real person quickly.
Answer frame:

Hold the line: no reset without verification, however senior or urgent.

Offer fast routes: a callback to the number on file, confirmation from their manager or assistant, or self-service reset.

Stay calm and record: explain why politely, involve your lead if needed, log the call.

Sample spoken answer:

"I'd stay polite but I wouldn't reset it. Urgency plus seniority plus 'I can't verify' is exactly how a social engineering call sounds, and if I reset the wrong person's password I've handed over a senior account. So I'd explain that the check protects them, and then work hard to make verification fast. I could call them back on the number in the company directory, ask their assistant or manager to confirm, or walk them through self-service reset if they're enrolled. If they're genuinely who they say, one of those usually works in a couple of minutes. If they stay angry, I'd bring in my team lead rather than bend the rule myself. And I'd note the call in the ticket, because if it wasn't them, the security team will want to know someone tried."

Red flag to avoid:

Resetting the password because the caller sounded important, or refusing and offering no other way to verify.

They may ask next:
  • Your manager later says 'just do it next time, it's the director'. How do you respond?
  • What would make you report this call to the security team?
Say it in 60 seconds
Hard Situational round Mid-level, Senior Practice question

19. Five people call the desk within ten minutes about the same fake 'shared invoice' email. Some only received it, one clicked, and one typed their password. How do you handle the calls?

What the interviewer is really testing:
Whether you sort callers by how exposed they are, raise it as one security incident quickly, and keep the desk organised instead of treating five separate tickets.
Answer frame:

Sort the callers: received only, clicked, or entered a password, since each needs a different response.

Act by group: password reset and sign-out for the one who typed it, a device check for the clicker, report and delete for the rest.

One incident: raise it to security straight away with the email and every caller's name.

Run the desk: link calls to one parent ticket and help get a warning out to staff.

Sample spoken answer:

"With five calls about one email, I'd treat it as a campaign, not five tickets. First I'd sort people by how exposed they are. Most only received it, so I'd thank them, ask them to report it with the report button and delete it. The person who clicked but typed nothing, I'd ask what happened after the click, and if anything downloaded, get the laptop checked and scanned. The one who typed their password is the priority. I'd follow our runbook: reset it, sign them out everywhere and check nobody added a new MFA method. At the same time I'd raise one incident to the security team with the original email and every caller's name, so they can block the link and pull it from other inboxes. I'd link every call to that parent ticket and, if our process allows, help get a short warning out to staff."

Red flag to avoid:

Handling each call as a separate ticket and never telling the security team there's a wave.

They may ask next:
  • Ten more calls come in about the same email. How do you stop the desk being swamped?
  • The person who typed their password is worried they'll be in trouble. What do you say?
Say it in 60 seconds
Medium Situational round Fresher, Mid-level Practice question

20. A user asks you to install a free tool that isn't on the approved software list, and says their manager is fine with it. What do you do?

What the interviewer is really testing:
Whether you follow the software approval process without being unhelpful, and understand why it exists.
Answer frame:

Don't install on the spot: verbal approval isn't the process.

Explain simply: licence terms, security and support are why the list exists.

Offer a path: an approved alternative now, and raise a proper request with the manager's written approval.

Sample spoken answer:

"I wouldn't install it right there, even with the manager's name mentioned, but I'd try hard not to just say no. I'd ask what they're trying to do, because often something we already have does the job, and I can set that up on the spot. If not, I'd explain in one line why there's a list: free tools sometimes aren't free for business use, some bundle unwanted extras, and anything we install we have to keep patched and supported. Then I'd raise a software request for them, ask the manager to approve it in the ticket, and tell them what happens next and roughly how long it takes. That way the user gets the tool if it's safe, and there's a record if anyone asks later why it's on the machine."

Red flag to avoid:

Installing it to keep the user happy, or refusing with no explanation and no alternative.

They may ask next:
  • The user says a colleague already has the same tool installed. What do you do with that information?
  • What would make you escalate a software request to the security team?
Say it in 60 seconds

Tickets and Escalation 2 questions

Hard Situational round Mid-level, Senior Practice question

21. It's nine in the morning. A director can't get the meeting room screen working for a board meeting in fifteen minutes, and the whole sales team has just lost the shared drive. You're alone on the desk. What do you do?

What the interviewer is really testing:
Whether you weigh impact and urgency rather than seniority, and whether you can start two things moving instead of doing them one after the other.
Answer frame:

Impact and urgency: a whole team down is high impact; the board meeting is urgent with a hard deadline.

Start both: log the outage, quickly check whether it's server-side and escalate that right away.

Then go: head to the meeting room, and keep sales updated with a time for the next update.

Sample spoken answer:

"I'd look at impact and urgency, not who's calling. The shared drive affects a whole team and stops their work, so it's the bigger incident. But a drive outage for many people is very likely a server or network problem that the desk can't fix alone, so the best thing I can do is spend two minutes confirming it and escalate it straight away to the server team, logging it as a major ticket. Once that's in someone's hands, I'd go to the meeting room, because that problem has a hard deadline and is usually a cable, input or display setting I can fix in minutes. I'd send the sales team lead a short message saying we know, who's working on it and when they'll hear next. If I had a colleague, I'd split the two instead."

Red flag to avoid:

Choosing purely by seniority, or trying to fix the shared drive yourself while the escalation path goes unused.

They may ask next:
  • The director says their meeting matters more and wants you to stay until it starts. What do you say?
  • How would you normally define priority levels on a desk?
Say it in 60 seconds
Medium Situational round Fresher, Mid-level Practice question

22. You've spent forty minutes on a ticket and you're no closer. When do you escalate, and what do you hand over?

What the interviewer is really testing:
Whether you know when you're stuck, and whether your handover lets the next person start where you stopped instead of from the beginning.
Answer frame:

When: at the team's time limit, when it needs rights you don't have, or when it affects more people than you thought.

What you hand over: symptoms, exact errors, what you tried and what happened, screenshots or logs.

Stay with the user: tell them who has it and when they'll hear next, and learn from the fix.

Sample spoken answer:

"Forty minutes with no progress is usually past the point where I should have escalated. Most desks have a rough time limit, and I'd also escalate earlier if the fix needs access I don't have or if it turns out more users are affected. The important part is the handover. I'd write up the exact symptoms and error messages, what I've already tried and what happened each time, and attach screenshots or logs, so the second-line engineer doesn't repeat my first half hour. I'd tell the user plainly that I'm passing it to a specialist, who that is, and when they can expect to hear. Once it's solved, I'd read the resolution notes, because that's how I'd handle it myself next time."

Red flag to avoid:

Escalating with a one-line note like 'user has issue, please check', or never escalating out of pride.

They may ask next:
  • The second-line team sends it back saying you should handle it. What do you do?
  • How do you avoid escalating too early?
Say it in 60 seconds

User Communication 4 questions

Medium Situational round Fresher, Mid-level Practice question

23. A user walks up to the IT desk, clearly furious, saying their ticket has been ignored for three days. How do you handle it?

What the interviewer is really testing:
Whether you can calm someone down without getting defensive, own what went wrong, and leave them with a concrete next step.
Answer frame:

Listen: let them finish, don't argue about the timeline.

Own and look: apologise for the wait, open the ticket with them there, find what's really blocked.

Commit: give a real next step and time, then follow through and check why it stalled.

Sample spoken answer:

"I'd let them get it all out first without interrupting, because arguing about whether it's been three days or two only makes it worse. Then I'd say I'm sorry they've waited that long, and I'd pull up the ticket right there with them. Often I'll see what happened, like it's waiting on a part, or it was assigned to someone who's off sick, or honestly it just fell through the cracks. I'd tell them plainly what I see, and then either fix it on the spot if I can, or give them a clear next step and a time I'll update them by. Then I'd make sure I actually hit that time. Afterwards I'd look at why the ticket sat untouched and mention it to my lead, so the same gap doesn't catch someone else."

Red flag to avoid:

Blaming the queue, another team or the user for not following up, before you've even opened the ticket.

They may ask next:
  • The user starts being personally rude to you. Where is your line, and what do you do?
  • What if the delay was caused by another team, not yours?
Say it in 60 seconds
Easy Behavioral round Fresher, Mid-level Practice question

24. Tell me about a time you had to explain a technical problem or fix to someone with no technical background.

What the interviewer is really testing:
Whether you can drop the jargon, use a simple comparison, and check the person actually understood.
Answer frame:

Situation: who the person was and what they needed to understand.

How you explained it: plain words, a comparison from everyday life, one step at a time.

Check and result: how you confirmed they got it and what changed.

Sample spoken answer:

"At my last job, an office manager kept having her laptop fill up and grind to a halt. The cause was that she saved everything to the desktop and never used the synced cloud folder, so her files lived only on a small, full disk. Instead of talking about storage and sync, I said her desktop was like a small drawer, and the cloud folder was a big filing cabinet that also keeps a copy safe if the laptop dies. I showed her once how to save to it, then had her do the next file herself while I watched. I checked in a week later and her disk was fine, and the next month she reminded her own team to do the same."

Red flag to avoid:

A story where you explained it perfectly but never checked whether the person understood.

They may ask next:
  • How do you tell when someone has stopped following your explanation?
  • Which technical term do you avoid with users, and what do you say instead?
Say it in 60 seconds
Medium Behavioral round Fresher, Mid-level, Senior Practice question

25. Tell me about a mistake you made while supporting a user or their account. What happened, and what did you do?

What the interviewer is really testing:
Whether you own mistakes quickly and honestly, fix the impact, and change your habits afterwards.
Answer frame:

The mistake: say it plainly, without shrinking it.

Immediate fix: how you told people and limited the damage.

Change: the habit or check you added so it doesn't happen again.

Sample spoken answer:

"Early on, I was cleaning up an old laptop before reusing it for another person and wiped it, assuming the previous user had moved their files to the cloud like everyone else. She hadn't, and a folder of drafts she needed was only on that disk. As soon as she asked, I told her straight away what I'd done, and then told my lead. We got most of it back from an older backup, but she lost about a week of changes, and I apologised to her properly. After that I started using a checklist before wiping any device: confirm with the user in writing that their files are saved, and check the disk myself for anything outside the synced folders. The team ended up adopting that checklist."

Red flag to avoid:

Picking a fake mistake, or a story where you only admit it once someone else found out.

They may ask next:
  • How did the user react, and how did you handle that?
  • What's a check you now do on every ticket because of an earlier mistake?
Say it in 60 seconds
Medium Behavioral round Fresher, Mid-level Practice question

26. Tell me about a user who kept ignoring your advice, like never restarting or reusing an old password. How did you deal with it?

What the interviewer is really testing:
Whether you stay patient and find another angle, instead of lecturing or giving up.
Answer frame:

The pattern: what they kept doing and why it caused tickets.

New angle: what you changed in how you explained it or what you set up.

Outcome: what changed, and when you'd bring in a manager or policy.

Sample spoken answer:

"A sales rep at my last company never restarted his laptop, so updates piled up and he'd call every couple of weeks about it being slow or apps crashing. Telling him to restart more often didn't work, because to him it meant losing all his open tabs and files. So I stopped telling him and asked what bothered him about restarting. Then I showed him that his browser could reopen his tabs and that his files autosaved to the cloud, so a restart cost him two minutes, not his whole setup. We agreed he'd restart on Friday afternoons. His tickets dropped off after that. If it had been a security issue, like refusing MFA, I wouldn't have negotiated; I'd have explained the policy and involved his manager."

Red flag to avoid:

Describing the user as stupid or difficult, or a story where you just kept fixing the same thing without trying anything new.

They may ask next:
  • When would you escalate a user's behaviour to their manager?
  • How do you avoid sounding like you're lecturing?
Say it in 60 seconds

Documentation 2 questions

Medium Behavioral round Fresher, Mid-level Practice question

27. Tell me about a fix you wrote up as a knowledge article or guide. Did anyone actually use it?

What the interviewer is really testing:
Whether you document so others can repeat the fix, and whether you write for the reader, not for yourself.
Answer frame:

Why: the problem kept coming up, or took too long each time.

How you wrote it: symptom in the user's words, steps in order, screenshots, when to escalate.

Result: who used it and what changed.

Sample spoken answer:

"We kept getting calls about the new MFA app whenever someone changed phones, and each one took a while because people had to piece together the steps from memory. After the third one in a week, I wrote a short knowledge article. The title was what users actually said, 'I got a new phone and can't sign in', not the technical name. I wrote the steps in order with a screenshot for each, noted which parts only the desk could do, like clearing the old method, and added what to do if it still failed. The rest of the desk started linking it in tickets, and we also turned a cut-down version into a guide for users to read before they switched phones. Those calls got noticeably shorter."

Red flag to avoid:

Saying documentation is something you do if there's time, or articles only you can follow.

They may ask next:
  • How do you keep an article like that up to date when the process changes?
  • What makes a ticket note useful to the next person who reads it?
Say it in 60 seconds
Hard Behavioral round Mid-level, Senior Practice question

28. Tell me about a time you noticed the same problem coming into the desk again and again. What did you do about it?

What the interviewer is really testing:
Whether you look past single tickets to the cause behind them, and can push a fix through people who own it.
Answer frame:

Spot: how you noticed the pattern, ideally with ticket counts from the system.

Dig: the shared cause behind the repeats.

Push the fix: who owned it, how you made the case, and what happened to the volume.

Sample spoken answer:

"At my last job, I felt like I was reconnecting mapped drives for people every Monday. I searched our tickets and found it was dozens over a couple of months, nearly all from laptops that had been off the network over the weekend. I dug into one and found the login script that mapped the drives only ran at sign-in when the laptop could reach the domain, so anyone who signed in before their Wi-Fi came up got no drives. I wrote that up with the ticket list and took it to the systems team, who owned the script. They changed the setup so the drives reconnect once the laptop is back on the network. The Monday tickets for that almost disappeared, and I kept the ticket search as a way to spot the next pattern."

Red flag to avoid:

Just fixing each ticket as it arrives and never asking why the same one keeps coming back.

They may ask next:
  • What if the team that owned the cause didn't see it as a priority?
  • How do you tell a real pattern from a coincidence in the ticket data?
Say it in 60 seconds

Team and Work Style 2 questions

Easy Culture fit round Fresher, Mid-level Practice question

29. A lot of this job is repetitive, like the tenth password reset of the day. How do you stay careful and keep it from getting stale?

What the interviewer is really testing:
Whether you know routine work is where shortcuts and mistakes creep in, and whether you look for ways to reduce it.
Answer frame:

Same care every time: routine is where steps like verification get skipped.

Person first: each call is someone's whole morning, even if it's your tenth.

Reduce it: suggest self-service or automation for the most common requests.

Sample spoken answer:

"I treat the routine ones as the ones most likely to go wrong, because that's when people skip steps. A password reset is a good example. It's easy to rush the identity check on the tenth call of the day, and that's exactly what someone trying to trick the desk hopes for. So I follow the same short checklist every time. I also try to remember that for the person calling, it's not routine, they're locked out and stressed. And I keep a note of which requests come up most, because the best way to deal with repetition is to remove it, for example by pushing self-service password reset or writing a quick guide so people can fix the simple things themselves."

Red flag to avoid:

Admitting you go on autopilot for simple tickets, or describing users with routine problems as a nuisance.

They may ask next:
  • What would you automate first on a help desk, and why?
  • How do you keep learning when most of your day is routine tickets?
Say it in 60 seconds
Medium Culture fit round Fresher, Mid-level, Senior Practice question

30. On a busy help desk, what does being a good teammate look like to you?

What the interviewer is really testing:
Whether you think about the shared queue and the next shift, not just your own ticket count.
Answer frame:

Shared queue: take tickets in order, not just the quick easy ones.

Share what you learn: fixes, workarounds and outage news in the team channel and the knowledge base.

Clean handovers: notes a colleague can pick up, and asking for help early.

Sample spoken answer:

"To me it starts with how you treat the queue. It's tempting to grab the quick password resets to make your numbers look good and leave the messy ones for someone else, and a team notices that fast. So I take tickets in order and pick up the awkward ones too. Second, I share what I find. If I work out a fix for a new error, I post it in the team chat and add it to the knowledge base, so five people don't each spend an hour on it. Third, I leave clean notes and a proper handover at the end of my shift, so nobody has to call a user back to ask what I already asked. And I ask for help early, because a stuck ticket I'm hiding helps nobody."

Red flag to avoid:

Talking only about your own ticket count or speed, with nothing about the rest of the team.

They may ask next:
  • A teammate keeps cherry-picking easy tickets. What would you do?
  • What should a good end-of-shift handover on a help desk include?
Say it in 60 seconds
Were you asked something else? Share it A person checks every question before it goes on the site. No name is shown.
For the call itself

The questions above are the prep. The call has ten more.

ClapAssist is an AI interview assistant for Mac and Windows. It listens to the interview on your computer and shows you what to say, in short lines you can read while you talk. Your resume and notes are never stored on our servers. It stays out of screen share on every plan; only you can see it.

Download ClapAssist with 10 free minutes
Mac and Windows · Stays out of screen share · No card