For hiring managers

Interview guide for IT support roles: a short loop with a ticket queue and a social engineering call

On this page
  1. The loop at a glance
  2. Stage 1: the screen (25 minutes)
  3. Stage 2: the ticket queue exercise (60 minutes)
  4. Stage 3: user and security role-plays (30 minutes)
  5. Stage 4: hiring manager interview (40 minutes)
  6. Scorecard competencies and weights
  7. The decision rule
  8. Adjusting for related roles
  9. Common mistakes in IT support loops
  10. Questions people ask

An IT support hire is judged on three things users notice and one they do not. Users notice whether the problem got fixed, how long it took and whether they were treated like an adult. They do not notice whether the technician verified their identity before resetting a password, but that habit protects the whole company. This guide gives hiring managers a short loop for a help desk or desktop support technician: four stages, who owns which competency, core questions with what to listen for, a ticket queue exercise and a social engineering call, example weights and the decision rule. Adjustments for tier 2, desktop support and junior roles are at the end.

The first call, including a talk-through troubleshooting scenario and certification notes, is in help desk technician screening questions. If you are a recruiter or manager without an IT background, read how to interview for technical roles as a non-technical recruiter before the loop starts.

The loop at a glance

StageInterviewerOwnsLengthPass rule
1. ScreenRecruiterEnvironment supported, ticket volume, shifts, logistics, pay25 minHas supported end users in a comparable environment, or has a credible entry route
2. Ticket queue exerciseSenior technician or IT leadTroubleshooting method; technical knowledge; prioritization60 minAt least 3 on troubleshooting method
3. User and security role-playsTwo interviewers from IT or a business teamUser communication; security judgment30 minAt least 3 on user communication; no security failure
4. Hiring manager interviewIT managerDocumentation; ownership and follow-through; learning40 minAt least 3 on documentation

Stages 2 to 4 fit in one half-day visit or one block of video calls, which matters for candidates who are working shifts elsewhere. The stage design reasoning is in the interview process template.

Stage 1: the screen (25 minutes)

  • "How many users do you support, on what devices and systems, and how many tickets do you close on a normal day?" Listen for: a concrete environment (for example, 400 users on Windows laptops with Microsoft 365) and a realistic volume.
  • "Which tickets do you escalate, and to whom?" Listen for: a clear line between what they resolve and what goes to tier 2, network or security.

Stage 2: the ticket queue exercise (60 minutes)

The candidate sees a queue of five invented tickets with timestamps and user details. An IT lead plays the user, the system and any colleague the candidate wants to ask, answering only what is asked.

The queue

  • A user cannot print to the floor printer since this morning; others on the floor can.
  • A remote employee's VPN connects but they cannot reach the file share.
  • A sales team reports email is slow; it started 20 minutes ago and three people have called.
  • A new starter arrives tomorrow and their laptop and account are not ready.
  • A user's account is locked for the third time this week.

Running it

  1. Prioritize (10 minutes): "Put these in the order you would work them and tell me why."
  2. Work two tickets in depth (35 minutes): the interviewer picks the VPN ticket and the repeated lockout. The candidate asks questions and says what they would check; the interviewer reports results.
  3. Close one ticket in writing (10 minutes): "Write the resolution note for the VPN ticket."
  4. Wrap-up (5 minutes): "Which of these might be connected?"

What to listen for

  • Prioritization: the multi-user email issue first because it affects several people and may be growing, with a quick acknowledgment to the others.
  • Troubleshooting method: gathering facts, isolating the layer (account, device, network, service), changing one thing at a time and confirming the fix with the user.
  • The repeated lockout: looking for a cause such as a saved old password on a phone, and raising the possibility of an attack if the pattern is odd, rather than unlocking it a fourth time.
  • The resolution note: symptoms, cause, fix and anything the next technician should know, readable without a conversation.

If you can run a reliable test environment, swap the talk-through for a hands-on lab, but keep the same tickets and scoring. More questions on method are in how to interview for problem-solving.

Stage 3: user and security role-plays (30 minutes)

Role-play 1: the frustrated user (15 minutes)

An interviewer from outside IT plays a user whose laptop died before a client presentation in an hour. They are short-tempered and not technical. Listen for: acknowledging the deadline, offering a workaround first (a loaner, web access to the files), plain language, a clear next step and no blame.

Role-play 2: the social engineering call (15 minutes)

A second interviewer calls as the chief financial officer, traveling, locked out, and needing a password reset and multifactor authentication removed "right now" before a wire approval. They cannot answer the verification questions and become impatient.

Listen for: following the verification process anyway, staying polite, offering the approved alternative route (for example a call-back to the number on file or a manager's verification), and reporting the call afterward. A candidate who resets the account to be helpful fails the gate, however good the rest of the loop.

Stage 4: hiring manager interview (40 minutes)

  1. "Tell me about a problem you could not solve. What did you do with it?" Listen for: what they tried, how they escalated with notes so the next person did not start over, and whether they followed up to learn the answer.
  2. "Tell me about a fix you got wrong." Listen for: telling the user and the team, putting it right and checking more carefully afterward.
  3. "What is something technical you learned in the last six months, and how?" Listen for: a specific skill and a specific method, such as a home lab, documentation or shadowing a colleague.
  4. "Tell me about a knowledge base article or process you wrote or improved." Listen for: a recurring problem turned into documentation others used.

Scorecard competencies and weights

Example weights for a tier 1 help desk technician. Set yours at intake and lock them before the first candidate.

CompetencyOwned byExample weight
Troubleshooting methodTicket queue exercise25%
User communicationFrustrated user role-play20%
Technical knowledgeTicket queue exercise15%
PrioritizationTicket queue exercise10%
DocumentationResolution note; hiring manager interview15%
Ownership and learningHiring manager interview15%
Security judgmentSocial engineering callPass/fail gate

The scorecard builder checks that the weights add up to 100 and prints a sheet per interviewer. Anchors on a 1–4 scale: 1 guessing or no method, 2 a method with gaps, 3 a clear method that reaches a fix, 4 the same plus prevention.

The decision rule

  1. Scorecards first, including the resolution note, before the short debrief.
  2. Gate: no failure on the social engineering call.
  3. Floor: troubleshooting method at 3 or above for experienced candidates; 2 or above for entry-level candidates who scored 3 or above on learning.
  4. Weighted total: in this example, 2.7 or higher on the 1–4 scale is an offer.
  5. Decide within two working days. Good support candidates often have several offers; slow loops lose them.

The debrief record is in the interview debrief template.

RoleWhat changes
Entry-level or career changerSimpler tickets with more prompts; accept home labs and coursework as evidence; raise learning to 25% and lower technical knowledge.
Desktop supportAdd a hands-on hardware or imaging task; weight device setup and asset handling.
Tier 2 or service desk leadHarder tickets involving directory, group policy or email routing; add a stage on coaching tier 1 from ticket notes.
Systems administratorA different loop; see systems administrator screening questions for the first call.

Common mistakes in IT support loops

  • Trivia quizzes. Port numbers and acronyms are easy to look up. Score method, not recall.
  • Ignoring the user side. A technician who fixes everything and alienates users generates complaints and repeat tickets.
  • No security test. CISA's Scattered Spider advisory (updated July 2025) describes attackers posing as employees to get help desk staff to reset passwords and move multifactor authentication to the attacker's device. Test the verification habit directly.
  • Overweighting certifications. They open the door; the exercise decides.

Questions people ask

How do you test troubleshooting skills in an IT support interview?

Give the candidate realistic tickets and have them talk through their steps while an interviewer answers as the user or the system would. Score the method: whether they gather information, check the simple causes first, test one hypothesis at a time and confirm the fix. A candidate who jumps to reimaging a laptop for a printer problem shows you the gap quickly.

Should IT support candidates do a hands-on lab?

A short lab is useful if you can run it reliably, for example a test virtual machine with a broken network setting or a locked account in a test directory. If you cannot, a talk-through of tickets with an interviewer playing the system gives most of the same evidence. Either way, keep it under an hour.

How important are certifications like CompTIA A+ for IT support hires?

They show that a candidate studied a broad syllabus, which is useful for someone without work history. They do not show troubleshooting method, security judgment or patience with users, which is what the loop should test. Treat a certification as a reason to interview, not as a substitute for the work sample.

What is a social engineering test in an IT support interview?

A short role-play where an interviewer calls as a senior executive or a panicked colleague and asks for a password reset or access without passing identity checks. It tests whether the candidate follows verification steps under pressure, which is one of the most important habits in a support role.