Opens this plan in Hirezen, where one click makes it a position.
System Administrator interview questionsBackup review — what would actually come back round
A 60 min interview plan with a time-boxed script, what each question is for, and the signals to score against. Key skills: Backup and restore questions on a real backup report: green jobs that would not restore, a folder lost for longer than on-site retention, an attacker holding a domain admin account, and the restore page someone else follows — whether the candidate treats a backup as proven only by a restore..
Forty green rows
What this section is for
Purpose
Runs over a backup report and a half-page of setup notes, sent the day before so the hour is spent on judgment rather than on reading. Build the report to this content. One nightly job at 01:00 backs up 40 VMs, image-level, to the repository server `BKP01`, keeping 14 daily restore points; a copy job sends each night's backups to cloud object storage every morning and keeps 30 days. Every row is green for the last week. Show eight rows in full. `FS01`, the file server: disks of 80 GB and 1.2 TB, processed 1.21 TB on its last full, green, copied offsite; on the 12th it failed with "repository busy" and the retry at 01:47 succeeded, which is the only red mark in the month. `DOCS01`, the document management server: its job was created in 2024 and selects disk 0 only; the VM has had a second, 600 GB data disk since April; it processes 64 GB and is green every night. `SQL01`: "success with warning — could not bring applications in the guest to a consistent state: credentials rejected", every night since 3 March, and nothing else backs up its databases. `DC01`, `APP01`, `APP02`, `PRINT01` and `RDS01`: green, sizes matching their disks. Below the table, one line: "last restore test — one file from `FS01`, November 2025". The setup notes, used later in the round: `BKP01` is joined to the domain and its console is signed into with domain accounts; the service account `svc-backup` is a member of Domain Admins; the cloud bucket has versioning and object lock switched off; the access key stored in the backup software can delete objects. The red herring is `FS01`'s failed night; the deliberately correct rows are `FS01`'s current backups and `DC01`. Book 70 minutes; the close is outside the 60.
I'm [YOUR_NAME] and I look after backups, among other things, at [COMPANY_NAME]. Everything on this report is green, and I am not sure what we could get back. That is what this hour is about.
What this section is for
Purpose
States the round's premise — a green report is a claim, not evidence — so the candidate reads the report for what it does not prove.
You had the report yesterday. If each of these servers died tonight, tell me what we would get back tomorrow — server by server, where it differs from what the report suggests — and how you would find out for sure.
What this question is for, and what to listen for
Purpose
Reads backup and recovery on a report the candidate did not configure. The separator is whether they check what was backed up against what exists, instead of reading the status column.
Signals to score
- Compares processed sizes with disk sizes and finds that `DOCS01`'s 600 GB data disk has never been in the job
- Reads six months of "success with warning" on `SQL01` as backups that may not restore the databases cleanly
- Explains in plain terms the difference between a copy taken while the database was told to be consistent and one taken mid-write
- Spends little time on `FS01`'s failure on the 12th, because the retry succeeded
- Says a green job proves something was written, not that it restores, and asks when each server was last restored
- Notices that the only restore test on record is a single file from November 2025
- Asks what the report cannot show — servers in no job, and the backup system's own configuration
- Fixes the cause and not just `DOCS01`: jobs that pick up every disk a VM has, and an alert on warnings, not only on failures
- Proposes restore tests with a rota, a scope per server and a written result
Follow-up questions
- `DOCS01` processed 64 GB last night. How big is it?
- `SQL01` has said "success with warning" since March. What exactly would come back?
- The only red mark this month is `FS01` on the 12th. How worried are you?
- When was each of these servers last restored, and how would you find out?
- What is not on this report at all?
The folder that has been empty for a while
What this section is for
Purpose
A restore request, handed over on paper at the start of the section. Thursday 10:15, from finance: `\\FS01\Finance\Contracts\Suppliers` is empty; it held about 2,300 files, roughly 18 GB; the last person sure it had files in it opened it "about three weeks ago". What the service desk has already found: an administrator opening the folder directly on `FS01` also sees it empty; the previous versions kept by `FS01` itself go back nine days and show it empty; the oldest on-site restore point, fourteen nights old, shows it empty. From the report's notes: the offsite copy keeps 30 nights, and nobody has ever restored anything from it; file access auditing is not switched on for `FS01`. The red herring: the folder's permissions were changed on the 10th to add a new finance hire — tempting as an explanation, ruled out because an administrator sees the folder empty too. The deliberately correct thing: the service desk has not restored anything over the live folder.
Finance wants the supplier contracts back, and everything close at hand shows the folder empty. Take me through getting them back, and tell me what you tell finance, and when.
What this question is for, and what to listen for
Purpose
Reads backup and recovery at the moment a backup has to prove itself, including the copy nobody has used. The separator is whether the candidate establishes when the loss happened before choosing what to restore, and restores beside the live data rather than over it.
Signals to score
- Reads the three empty checks as dating the loss to more than fourteen nights ago, and goes to the offsite copy for anything older
- Finds the last point where the folder still had files by checking points, rather than restoring the oldest one available
- Says the offsite copy has never been restored from and plans for that: credentials, download time for 18 GB, and what to do if it fails
- Restores to a separate location with the original permissions, not over the live folder
- Asks how 2,300 files went, before restoring, in case whatever removed them is still running or still has access
- Tells finance early what is known, roughly how long it will take and what will not come back — anything created between the last good point and the loss
- Checks counts, sizes and a sample of opened files with finance before calling it done
- Notes that auditing would have answered who and when, and proposes switching it on for finance's shares
- Reads a loss noticed after three weeks against fourteen days on site and thirty offsite as a retention decision to revisit
Follow-up questions
- The oldest on-site point from fourteen nights ago shows the folder empty. What do you now know?
- Nobody has ever restored from the offsite copy. What could go wrong in the next hour?
- Why not restore straight back into the Suppliers folder?
- Does it matter how the files disappeared before you restore them?
- Finance noticed after three weeks. What does that tell you about fourteen days?
Friday night, with a domain admin account
What this section is for
Purpose
Uses the setup notes from the pack and nothing new: `BKP01` is domain-joined and administered with domain accounts; `svc-backup` is in Domain Admins; the cloud bucket keeps no versions and has no object lock; the access key held by the backup software can delete. Do not say the word ransomware first; let the candidate name the pattern.
Now assume the worst version of a normal Friday. Someone outside has a working domain admin account from about 20:00, and by Monday they want every file in the company unreadable and every way back gone.
What this section is for
Purpose
Sets an attacker who already holds the keys, which is the case the setup notes fail and the case a backup design is for.
Using only the setup notes, tell me which copies of our data still exist on Monday morning. Then tell me what you change, in what order, with the budget we have.
What this question is for, and what to listen for
Purpose
Reads backup and recovery against deliberate destruction rather than accidental loss. The separator is whether the candidate follows the attacker's credentials to each copy instead of listing backup best practices.
Signals to score
- Follows the domain admin account to `BKP01`: it can sign in to the console, delete restore points, or encrypt the repository's disks
- Follows it on to the offsite copy: the software holds a key that can delete, and a bucket with no versions keeps nothing once objects are gone
- Concludes that on Monday there may be no copy at all, and says so plainly
- Proposes a copy that cannot be deleted or shortened inside its retention period, even by the account that wrote it
- Takes `svc-backup` out of Domain Admins and asks what the backup system actually needs to read the VMs
- Moves administration of the backup system off domain accounts, with its own credentials and MFA, so one stolen identity does not reach both production and backups
- Orders the changes by protection bought per day of work, and puts the undeletable copy and the service account first
- Says restores after an attack need checking for what the attacker left behind, and that the restore order — directory first, then what people need — is written down beforehand
Follow-up questions
- The attacker has a domain admin account. What can it do to `BKP01`?
- And to the copy in the cloud?
- What exactly has to be true for the offsite copy to survive?
- `svc-backup` is in Domain Admins. Why do you think it was put there, and what does it need?
- It is Monday and you are restoring. What comes back first, and from which copy?
The page someone else follows
What this section is for
Purpose
A writing exercise on the restore they have just talked through. Give the candidate a blank page or a shared document and say they have about eight minutes to write and the rest to talk it through. Tell them the team is three people, the on-call rota covers nights and weekends, and whoever is on call may never have opened the backup console.
You are away next week, and finance's folder goes missing again on Saturday. Write the first page of the file restore procedure that whoever is on call will follow, then tell me what you left out and why.
What this question is for, and what to listen for
Purpose
Reads documentation directly, as a piece of work rather than a stated habit. In a team this small the procedure is the colleague who is not there, so the separator is whether the page can be followed by someone else under pressure.
Signals to score
- Opens with when to use the page and who may approve restoring another team's data
- Says where the credentials for the backup console and the offsite copy are kept, and what to do if the console itself is down
- Writes numbered actions, each with what the reader should see if it worked
- Explains how to choose the restore point, including when to go to the offsite copy
- Restores to a separate location by default and says how to hand the files back with their permissions
- Includes checks before telling the requester — file counts, sizes, a few files opened by the person who asked
- Marks how long each stage takes as measured on a real restore, or leaves a blank to fill in at the first test, rather than guessing, and says what to tell the requester while waiting
- Puts at the top when the procedure was last followed from start to finish, and by whom
- Keeps it to a page that works at 03:00, and links to detail rather than including it
- Says what to record in the ticket afterwards so the next person learns from it
Follow-up questions
- Who is this page written for, exactly?
- The backup console will not load on Saturday. What does your page say?
- How does the reader know which restore point to pick?
- How would you know in six months that this page still works?
- What did you leave out on purpose?
That's the hour. What would you want to ask about how backups work here — who checks the report, when we last restored something whole, what the offsite copy has really been tested for?
What this section is for
Purpose
Scores nothing and goes in the notes. Someone who has had to restore for real tends to ask when it was last done and by whom.
One true thing before you go: [name a real gap in your own backups — a job nobody has restored from, a copy that the domain can delete, a procedure that exists only in one person's head]. It would be among the first things on your list.
What this section is for
Purpose
Ends on a fact about the team's own backups rather than a pitch. It is what this candidate wants to hear and it only works if it is true today, so check it before the round.
System Administrator interviews — common questions
- Who is this System Administrator interview plan for?
- It is written for the interviewer, not the candidate: the hiring manager, engineer or panel member running the Backup review — what would actually come back round for a System Administrator role. It gives you a 60 min script to follow in the conversation — 4 questions with what each one is for and the signals to score against — so you are not writing the round from scratch the night before.
- What does the Backup review — what would actually come back round assess?
- This round is focused on: Backup and restore questions on a real backup report: green jobs that would not restore, a folder lost for longer than on-site retention, an attacker holding a domain admin account, and the restore page someone else follows — whether the candidate treats a backup as proven only by a restore.. It works through Forty green rows, The folder that has been empty for a while, Friday night, with a domain admin account and The page someone else follows, scoring against 36 observable signals, with follow-up prompts on all 4 questions for going deeper where an answer is thin.
- How is the 60 min split up?
- Forty green rows (16 min), The folder that has been empty for a while (16 min), Friday night, with a domain admin account (14 min), The page someone else follows (14 min). The timings are there so the round stays on schedule and every candidate gets the same shape of interview — which is what makes two candidates comparable afterwards.
- What other rounds should I run for a System Administrator?
A single round does not cover a whole role. The other rounds in this library for a System Administrator: