Back to Blog

Systems Administrator Interview Questions 2026

HiringInformation TechnologyIT Hiring

Last updated: September 19, 2026

By Jennifer Burdick, Recruiting Manager, KORE1

The systems administrator interview questions that predict a good hire ask about restores the candidate actually ran, where the BitLocker recovery keys live, how certificates get renewed, and the last outage they owned. Definitions of RAID levels and FSMO roles belong on a phone screen at most, because every certification study guide prints the answers. A mid-level sysadmin costs about $85,000 to $110,000 base in 2026, which is a lot to spend on a guess.

I have been filling infrastructure seats at KORE1 since before most of our clients moved their email to the cloud. Systems administrators are still one of the searches our systems administrator staffing desk hears about most often, and the question I hear second, right after “what should we pay,” is “what should we ask.” Both are fair questions.

Here is the answer I give now. It changed on a Friday in July 2024.

That morning a faulty CrowdStrike update left Windows machines around the world stuck on a blue screen, 8.5 million of them by Microsoft’s count. One of them belonged to a client of ours, a cold-storage and produce shipper in Salinas, California, about 450 people, with packing sheds that run around the clock in lettuce season. Actually 214 of them did. Every laptop in the front office went down, and so did both domain controllers.

The fix was simple. Boot into safe mode, delete one bad driver file, restart. On an encrypted laptop, though, safe mode asks for the BitLocker recovery key first. The shipper stored its recovery keys in Active Directory, and Active Directory lived on the two domain controllers that were sitting at the same blue screen as everything else.

Their sysadmin had been hired that February after three interviews built almost entirely from definitions. He knew all of them. The five FSMO roles, the RAID levels, the seven layers of the OSI model, the difference between a forest and a tree. Nobody had asked him where the recovery keys were, or how he would reach them with the directory down. It had not occurred to him. It had not occurred to the three people who interviewed him either.

A contractor from our bench got one domain controller back that afternoon by attaching its virtual disk to a healthy VM and removing the file by hand. The keys came back with it. It was slow work. The packing sheds ran on paper until Saturday.

He was not a bad administrator. He had been interviewed for a job that was mostly about remembering things, and the job turned out to be mostly about being ready. When the shipper opened a second admin seat that September, we helped them rebuild the loop around questions like the ones below, and the person they hired, at $118,000, answered the recovery key question before anyone finished asking it.

One disclosure. KORE1 is paid when a client hires a sysadmin we sent. The questions work the same way whether you run the search yourself or we do, and plenty of the teams that use them never call us. Good for them.

Most interview question lists for this role are written for the candidate. They make decent study guides. As interviews they have one flaw, which is that the answers sit right under the questions, and a candidate who read the same page the night before will hand them back to you almost word for word.

Worker walking down a cold-storage produce warehouse aisle, the kind of round-the-clock operation a systems administrator keeps running

Trivia Is What the Certification Already Tested

A good systems administrator interview question has an answer only a working admin could give. It asks about something that happened in the candidate’s own environment, a restore, a patch that went badly, a certificate that expired, an outage at 2 a.m., and the person who was there answers in more detail than anyone who only read about it.

I have nothing against the FSMO question. It sits on every CompTIA Server+ and Microsoft practice test for a reason, and we use it ourselves when we screen juniors. The trouble starts when it is still being asked in round three. Last year I sat in on a panel at a regional hospital system where a candidate named all five roles in about eleven seconds, then could not say which of his own company’s domain controllers held them. He had studied. He had never had to move one.

So keep each topic and change what you ask about it. Textbook version on the left, what a correct answer actually shows you in the middle, and on the right, the version I would use instead.

The question most loops askWhat a right answer provesAsk this instead
What are the five FSMO roles?They read the study guideWhich domain controller holds the PDC emulator role in your environment, and what would you do if that server died tonight?
What is RAID 5?Recall of a tableWhen did a disk last fail on your watch, and what did you check before you swapped it?
Explain the OSI model.A memorized list of seven layersUsers in one office can reach the file server and users in the other office cannot. Where do you start?
What is Group Policy?A definitionIf you inherited our domain tomorrow, which Group Policy objects would you want to read first, and why those?
What is the difference between a snapshot and a backup?The correct sentenceTell me about a time a snapshot was the only thing you had. How old was it?

For a junior seat the left column is still a decent five-minute screen, and I would leave it there. For anyone you plan to pay more than about $85,000, drop it.

One more note on the OSI row. If your team keeps coming back to it, the job may be closer to network administration than you think, and that is a different loop with different questions about switches and firewalls. Our network engineer interview questions cover that one.

Your Domain, Your Hypervisor, Your Leftovers

Nobody interviews for systems administration in general. They interview for your domain, your hypervisor, your backup product, and whatever the last admin left half finished. Our systems administrator job description template splits the title into four versions of the job, and the interview should follow whichever version you posted. An opening question for each, the one I would ask in the first ten minutes.

  • A Microsoft shop running Active Directory, Entra ID, Intune, and Microsoft 365. “Which of your conditional access policies would you be most nervous to edit, and what would you do before you touched it?”
  • For a Linux fleet, I ask what happened to their CentOS 7 servers. More on that one below. It sorts people fast.
  • Hybrid, VMware or Hyper-V on premises and Azure or AWS beside it. “What still runs in your own building, and who decided it should stay there?”
  • The only admin in the company gets different questions altogether, and they have their own section further down.

CentOS Linux 7 reached end of life on June 30, 2024. Every Linux admin working today had to decide something about it, or watch somebody else decide.

An office furniture manufacturer in Grand Rapids, Michigan, still had 38 CentOS 7 servers running in the spring of 2025 when it asked us for a senior Linux admin. The engineering manager started every interview with the same question. The answers came in three kinds. One candidate had migrated a similar fleet to Rocky Linux 9 and could describe which two servers refused to move and why. Another said his current employer was “still on it, but it is behind the firewall.” The third asked what was wrong with CentOS 7. He meant it. The manager hired the first one at $121,000 and told me later that he could have skipped half the loop after hearing that one answer.

If the job you are describing is really infrastructure as code and deployment pipelines, with very few servers anybody logs into, you are hiring a different role. Our DevOps engineer interview questions cover that loop, and the pay band sits well above this one.

Eight Questions Built From Things That Broke

Each of these comes from an outage, an advisory, or a deadline that landed on real admins in the last two years. None of them has a textbook answer. Good candidates tell you a story with a date in it. Weak ones tell you a policy.

Your domain controllers are down and 300 laptops are asking for BitLocker recovery keys. Where are the keys?

This is the Salinas question, and it is the first one I would add to any loop. Microsoft’s own recovery article for the CrowdStrike outage, KB5042421, told people to look their keys up online if the screen asked for one, which works when your keys are escrowed in Entra ID and does nothing at all when they live only in an on-premises directory that is also down.

A strong answer names where the keys are escrowed today, Active Directory, Entra ID through Intune, or both, and then describes the second path. An export in the password vault. A cloud copy. A documented way to bring one domain controller back first. A weak answer says “in AD” and stops talking.

When did you last restore something nobody asked you to restore?

Backup jobs report success every night. Green lights prove little. Restores are where people find out. The #StopRansomware Guide from CISA, the FBI, the NSA, and MS-ISAC tells organizations to keep offline, encrypted backups and to regularly test their availability and integrity in a disaster recovery scenario. Most shops do the first half. Ask about the second.

Listen for a date, a system, and a number of minutes. “Last quarter I restored our accounting server to an isolated network, and it took 52 minutes, most of it waiting on the database to come up” is an admin who tests. “Our Veeam jobs are all green” is an admin who hopes.

How does a certificate get renewed where you work now, and who hears about it when renewal fails?

A credit union in Spokane, Washington, lost remote access for a whole Monday morning in 2025 because the certificate on its VPN gateway expired over a weekend. The renewal lived in one person’s calendar. She had left in April.

It matters more every year. Under the CA/Browser Forum’s Ballot SC-081, adopted in April 2025, publicly trusted TLS certificates issued since March 15, 2026, can be valid for no more than 200 days. The limit drops to 100 days in March 2027 and to 47 days in March 2029. A calendar reminder stops working at that pace. Software has to do it. A good candidate talks about an inventory of every certificate, automated renewal through ACME where the device supports it, alerts that fire well before expiry, and the difference between public certificates and the internal ones your own certificate authority issues, which follow their own rules.

What did you do about the Secure Boot certificates this year?

Of the eight, this one draws the widest spread of answers. Plenty of working admins missed it.

The Microsoft certificates that Secure Boot has trusted since 2011 are expiring in 2026. Per Microsoft’s support article, the Microsoft Corporation KEK CA 2011 expired on June 24, the Microsoft UEFI CA 2011 on June 27, and the Microsoft Windows Production PCA 2011, which signs the Windows boot loader, expires October 19. Machines that never get the 2023 replacements keep booting. What they lose is future security updates to the early boot process.

A mid-level admin who has not heard of it yet is not disqualified. It happens. A senior admin who has never heard of it has stopped reading advisories. The best answers I have heard mention firmware updates from the hardware vendor, the VM templates on the hypervisor, and the Linux servers whose boot loader was signed under the old third-party certificate.

Tell me about your break-glass accounts.

Microsoft recommends two or more emergency access accounts in Entra ID. Cloud-only, not tied to any one person’s phone, excluded from conditional access policies that block sign-in, protected with a passkey or certificate, and tested at least every 90 days. It also suggests keeping the credentials in fireproof safes in separate locations.

Hand placing a sealed envelope into a small fireproof safe, the way break-glass emergency access credentials should be stored

Ask how many they have, where the credentials sit, and when someone last signed in with one on purpose. “Never” comes up more than you would guess. Then ask about the on-premises side. An admin who has thought this through keeps the cloud emergency path and the local one independent, so an outage in one cannot lock them out of the other.

Which server in your environment runs the oldest operating system, and what is the plan for it?

Every environment has one. Microsoft ends extended support for Windows Server 2016 in January 2027, per its lifecycle page. A lot of payroll, lab, and manufacturing software still sits on it, usually because the vendor never certified anything newer. A strong candidate names the box, names the vendor application that keeps it there, and tells you what they did to fence it off in the meantime. “We are fully patched” is not an answer. Nobody is. It usually means they have not looked.

A user in the branch office cannot sign in, and the error mentions Kerberos. What do you check first?

There are several reasonable first moves. Check the clock early. Active Directory’s default Kerberos policy tolerates five minutes of difference between a client and a domain controller, and a branch machine that has drifted past that fails in ways that look like a password problem. DNS and the secure channel come next. Candidates who reach for the clock first have usually been burned by it once. You want that scar.

Show me something you automated that another person still runs.

The emphasis is on “another person.” Ask to see it. A PowerShell script that only its author can run is not automation. It is a second job. If they cannot share the file, have them walk you through it on a shared screen with the client names blurred. Where does it log? What happens when it fails halfway? Who changed it last? Senior admins in 2026 write code, even if the code is Bash, PowerShell, or an Ansible playbook, and the ones worth hiring write it for the person who comes after them.

A Sandbox With Three Faults in It

Talking gets you most of the way. Watching gets you the rest.

The best version of this I have seen came from an IT director at a freight logistics company in Stockton, California. He spent a Saturday afternoon, about two hours, building a small Windows member server that matched his own domain, and then he broke three things in it. The clock ran eight minutes off the domain controller. A Group Policy object was filtered to the wrong security group. A service account’s password had expired. Each candidate got a shared session, 45 minutes, and permission to use a search engine, since his own admins look things up all day and he saw no point in testing whether a candidate could get by without doing the same.

A Linux team at another client built the same thing with different faults, a /var partition filled by a runaway log, a typo in a systemd unit file, and a resolver still pointing at a DNS server they had retired. Hybrid teams tend to trade one of those for a cloud problem. A VM that lost its managed identity permissions after somebody tidied up a resource group is a favorite.

What the Stockton director watched was order, more than whether anyone finished. The strong candidates talked while they worked, opened Event Viewer before touching a setting, and asked before rebooting. Two of the five he saw fixed the first fault, said they were done, and never noticed the other symptoms were still there.

The one he hired, a candidate we sent him in 2025, ran out of time with the third fault still open. In her last three minutes she typed a note into the VM saying what she suspected, which log line pointed there, and what she would try next. He told me it was better written than half of his runbooks. She is still there.

Between candidates he just reverted the snapshot. I would keep an exercise like this live and inside the interview, the way he did. A take-home version slides toward free work faster than anyone plans for, and candidates notice.

IT technician on a stepladder tracing an orange network cable through an open ceiling tile, practical work a sysadmin interview should probe

When There Is Only One Admin

Plenty of the sysadmin searches we run are for the only IT person in the building, or the only one who is not on the help desk. Those candidates need a different set of questions, because nobody will be standing behind them.

An architecture firm in Tucson, Arizona, about 70 people, hired its first real sysadmin this spring after years of leaning on an outside provider and a partner who “knew computers.” The firm’s managing partner ran the interviews herself. Her best question was also her plainest. “What would you hand to an outside company, and what would you keep?” The candidate she hired, at $96,000, said he would keep identity, backups, and anything touching client drawings, and hand off after-hours monitoring and the phone system. He had a reason for each one. She made the offer that week. The two candidates who said they would do everything themselves did not get a second call. Nobody can.

Four more that work for a one-person seat.

  • “Show me documentation you left behind at your last job.” Ask for a sanitized page. Someone who has only ever written notes for themselves will struggle to produce one.
  • Vacations are a real test for a one-person shop. The honest plan for two weeks away involves a written runbook, a second person holding the emergency credentials, and an outside provider on call. The other plan is “I just check my phone.”
  • Ask what they bought last year and how they got it approved. Solo admins who have never written a budget request will be writing one by spring.
  • “Which of our vendors would you call first in your first week?” A good candidate asks to see the contracts before answering.

Some companies at this size are better served by a managed provider plus a part-time admin than by one full-time person carrying everything, and it is worth deciding that before the interviews start. Our managed IT staffing team can help you size both options side by side.

What $85,000 Buys and What $140,000 Buys

The O*NET profile for network and computer systems administrators, built on Bureau of Labor Statistics data, puts the 2025 national median at $99,130 a year. It also projects total employment edging down through 2034. Openings do not follow the same line. O*NET still expects roughly 14,300 of them every year, nearly all created by admins who retire or move into other work. Fewer seats, steady turnover. Good admins still get more than one offer.

These bands come from our systems administrator salary guide. The third column is the question I would use to tell a candidate at that level from one at the level below.

Level2026 U.S. baseThe question that separates this level
Entry (0 to 2 years)$59,000 to $73,000What do you check before you reset the password of someone who called the help desk?
Early career (2 to 4 years)$66,000 to $85,000Walk me through the last patch cycle you ran without anyone checking your work.
Mid-level (5 to 7 years)$85,000 to $110,000When did you last restore something nobody asked you to restore?
Senior (7 to 10+ years)$110,000 to $140,000Which key, certificate, or account would hurt most to lose, and where is its second copy?
Principal or lead (10+ years)$130,000 to $152,000 and upWhat did you talk the company out of buying, and were you right?

On-call changes the math. In our placements a week of coverage typically carries a stipend of $150 to $400 on top of base, and the rotation size matters as much as the money. Ask the candidate what rotation they are on now. Then tell them yours. Do it before the final round. For a specific metro and level, our free salary benchmark assistant will give you a range before finance picks one, and the longer guide to hiring a systems administrator covers sourcing and offer structure.

Arguments Inside the Hiring Team

Is a hands-on lab fair to the candidate, or is it free work?

A lab is fair when it is a sandbox you broke on purpose, it runs 45 minutes or less, and it happens inside the interview, because nothing the candidate fixes has any value to you afterward.

It turns into free work the moment you hand over a real ticket from your own queue, or a take-home that asks for a migration plan for your actual environment. Candidates can tell the difference. The good ones will say so, politely, and then take the other offer.

How many rounds does a systems administrator loop really need?

Three rounds cover most seats, a 30-minute screen, a 90-minute technical session with the lab inside it, and a final conversation with the hiring manager and one person from outside IT.

The person from outside IT is there to see whether the candidate can explain an outage to someone who only cares when it will be over. Add a fourth round only for a lead seat with direct reports. Four is the ceiling. Every round past that costs you candidates who had other offers by the second week.

The candidate already holds an RHCSA or AZ-104. Can we skip the technical round?

Shorten it, but do not skip it, because a certification proves the person passed an exam on a published syllabus, and your environment was never on that syllabus.

Drop the recall questions entirely for certified candidates, since the exam covered them. Keep the lab and the questions about their own environment. An RHCSA is a practical exam and a good signal for Linux work. It still tells you nothing about how someone handles your CentOS 7 leftovers or a vendor who will not certify a newer operating system.

Our help desk lead knows the environment best. Should they run the technical round?

Probably not as the lead interviewer, though they should be in the room, because a help desk lead sees the symptoms of every problem and often has not yet had to trace the causes.

Pair them with a senior infrastructure person, or with an outside admin if you do not have one, and let the help desk lead ask the questions about users and tickets. Their read there is sharp. If you are staffing both levels at once, our help desk staffing team runs the tier 2 and tier 3 side of the search.

What should we ask someone whose whole career has been at an MSP?

MSP admins have usually seen more environments than anyone else in the candidate pool, so ask which client environment they knew best and what they changed there on their own initiative.

Managed service work builds breadth quickly and ownership only sometimes. Some MSP admins spent years closing tickets across forty clients without ever deciding anything, and others ran two or three accounts as if they worked there. The question tells you which one you are talking to. Then ask how they would feel about one environment, every day, for years. Some people love that. Some find out in month four that they do not.

Does a contract admin brought in for a migration need the same loop?

Two conversations are usually enough, because a contract admin brought in for a server migration or a tenant move is judged on the plan and the rollback, not on how they will handle the next five years of tickets.

Ask for the cutover plan from their last migration. Then ask what went wrong on the night, and how they rolled back if they had to. Once the environment is defined, our contract sysadmins usually start within 10 to 14 days, which is most of the reason clients use contract staffing for this work. Might you keep the person afterward? Say so in the first conversation, and look at how contract-to-hire staffing converts a seat before you promise anything.

Ask Where the Keys Are

The Salinas shipper still opens every sysadmin interview with the recovery key question. The admin they hired in 2024 now asks it himself, and he told me recently that about half the candidates he sees start answering with where the keys are stored and never get to what happens when that place is down. The other half get a second interview.

That is the pattern with every question on this page. The first half of the answer is knowledge, and anyone can study for it. The second half is the plan for when the first half fails, and people only have that part if they have lived through something. Ask for the second half every time. It works. The loop gets shorter, the candidates you keep are the ones you wanted, and your 3 a.m. problems land on somebody who has already thought about them.

If you would like help running the loop, reach out to our sysadmin recruiters. We fill these seats as contract work, as contract-to-hire, and through direct hire in more than thirty metro areas around the country. A year after the start date, 92 percent of those hires are still in the seat. Ask about the keys first.