Systems Administrator interview questions and how to answer them

A sysadmin interview is mostly about one thing: can you be trusted with the keys. You'll get technical questions, but the people across the table care more about how you think when a server is down and a manager is standing behind you. Here's what they ask, why, and what a good answer sounds like.

The process

What happens in each round

  1. 1

    Recruiter screen

    What happens

    Whether your stack matches theirs. Expect quick questions on Windows versus Linux, which directory service you've run, whether you've touched cloud, and if you're fine with an on-call rotation. Be honest about gaps here. Bluffing gets caught in the next round.

  2. 2

    Technical interview with a senior admin

    What happens

    How deep your hands-on knowledge goes. They'll walk through DNS, Active Directory, permissions, backups and scripting, often by describing a broken system and asking what you'd check first. Talking through your order of operations matters more than landing the exact command.

  3. 3

    Hiring manager

    What happens

    Judgment and communication. They want to know how you handle change control, how you explain an outage to people who aren't technical, and whether you document your work or keep it all in your head.

  4. 4

    Practical or panel

    What happens

    Some teams give you a lab: a broken VM, a PowerShell or Bash task, or a whiteboard of a small network to troubleshoot. Others bring in a panel from the help desk and security teams to see if you'll work well with the people who escalate to you.

Questions you're likely to get

1.A user says they can't reach an internal site, but everyone else can. Walk me through how you'd troubleshoot it.

Why they ask

It's the classic opener because it shows whether you work in layers or just start rebooting things.

How to answer

  • Confirm the scope first: one machine, one user, or one location
  • Check the basics on that machine: IP config, can it ping the gateway, does nslookup return the right address
  • Flush the DNS cache and check the hosts file for a stale entry
  • Look at proxy settings, the local firewall and whether the user's account has access to that site
  • Say how you'd close it out: note the cause in the ticket so the help desk can fix the next one
2.Explain what happens when a domain-joined Windows machine logs a user in.

Why they ask

It tests whether you actually understand Active Directory or just click through the admin tools.

How to answer

  • The client uses DNS SRV records to find a domain controller
  • Kerberos handles authentication and the user gets a ticket
  • Group Policy objects apply for the computer and then the user
  • Mention what breaks it: clock drift, DNS pointing at a public resolver, a broken trust relationship
3.How do you handle patching across a fleet of servers without breaking production?

Why they ask

Patching is routine work that causes a lot of self-inflicted outages. They want to see a process, not luck.

How to answer

  • Patch a test or pilot group first and let it sit for a set period
  • Use a tool like WSUS, SCCM, Intune, or Ansible for Linux boxes so it's repeatable
  • Schedule production in a maintenance window that went through change control
  • Have a rollback plan: snapshots on VMs, known uninstall steps, a fresh backup
  • Check services came back after the reboot rather than assuming they did
4.Tell me about your backup strategy. How do you know your backups actually work?

Why they ask

Every team has backups. Far fewer have tested a restore. This question separates the two.

How to answer

  • Describe the tool you've used, such as Veeam, Windows Server Backup or rsync to a remote target
  • Talk about keeping at least one copy offsite or immutable so ransomware can't reach it
  • Explain how you schedule test restores of real files and full VMs
  • Mention monitoring backup job failures instead of trusting a green checkmark
5.A Linux server is running out of disk space and an app is about to fall over. What do you do?

Why they ask

It's a real page you'll get at night. They want to hear calm, ordered steps.

How to answer

  • Use df to confirm which filesystem is full and du to find what's growing
  • Check for runaway logs and whether logrotate is configured and working
  • Watch for deleted files still held open by a process, which lsof will show
  • Free enough space to stabilize, then fix the root cause so it doesn't come back
  • Set an alert threshold so you hear about it before it hits full next time
6.What do you automate, and can you show me a script you've written?

Why they ask

Admins who script get more done and make fewer typos. They want proof you write code, not just copy it.

How to answer

  • Pick one concrete script, like bulk user onboarding in PowerShell or a Bash health check
  • Explain the problem it solved and how often the task used to eat your time
  • Mention error handling, logging and running it safely with a dry-run first
  • Say where it lives, ideally in Git, so the team can find and change it
7.How do you manage permissions on file shares and servers?

Why they ask

Messy permissions are a security hole and a support headache. They want to see discipline.

How to answer

  • Grant access to groups, never to individual users directly
  • Follow least privilege and separate admin accounts from daily accounts
  • Tie access to a request and approval, with a regular review
  • Explain how you'd clean up an existing mess without locking everyone out
8.Tell me about the worst outage you've been part of. What happened and what did you change afterward?

Why they ask

Everyone has broken something. They want to see ownership and whether you learned anything.

How to answer

  • Pick a real incident and state your part in it plainly
  • Walk through how you found the cause and got service back
  • Describe how you kept people updated while it was down
  • End with the fix that stopped it happening again: a runbook, a monitor, a change process
9.A manager asks you to give their new hire domain admin rights so they can install software. What do you say?

Why they ask

It's a people question dressed as a technical one. They want to see you hold a line without being a jerk about it.

How to answer

  • Say no to domain admin, and explain the risk in plain words
  • Offer an alternative: a software request, a self-service portal or local admin through a tool like LAPS
  • Get the actual need met quickly so the manager isn't blocked
  • Loop in your own lead if the manager pushes past policy
10.How do you decide what to monitor, and what do you do about alert fatigue?

Why they ask

A pager that fires all night gets ignored. They want to know you tune it.

How to answer

  • Name a tool you've used, like Zabbix, PRTG, Nagios or Datadog
  • Monitor what users feel, such as service up and response time, not just CPU
  • Separate alerts that wake someone from ones that can wait for morning
  • Review noisy alerts and either fix the cause or kill the alert
11.What's your experience with cloud, and how is running a VM there different from on-prem?

Why they ask

Most shops are hybrid. They want to know you won't treat a cloud server like a box in the closet.

How to answer

  • Be specific about what you've done in Azure or AWS, even if it's small
  • Talk about identity and access being the main security boundary
  • Mention cost: resources left running cost money in a way a closet server doesn't
  • Cover networking differences like security groups instead of a physical firewall
12.How do you document your work?

Why they ask

The admin who keeps everything in their head becomes the outage when they go on vacation.

How to answer

  • Name where docs live: Confluence, a wiki, IT Glue or a Git repo
  • Describe writing runbooks for tasks others might need to do at night
  • Keep network diagrams and a server inventory current
  • Update the doc as part of the change, not as a someday task

Mistakes that sink good candidates

Bluffing through a command or concept you don't know

Say what you'd check instead, because a senior admin will spot the guess.

Talking about users as the problem

The help desk and the business are your customers, and the panel will notice the tone.

Describing heroics with no process behind them, like fixing production live with no change ticket and no rollback plan

Having no questions about on-call or backups

It suggests you haven't thought about what the job is really like.

Need more Systems Administrator interviews to prep for?

HeroApply applies to Systems Administrator jobs that match you, every day. 1,320 jobs are open today.

Find Systems Administrator jobs