Half of our recent candidates can't even get past the most basic phone screening.
"What is the difference between HTTP and HTTPS?"
"Well , I know HTTPS is the secure version."
"Well, what makes it secure?"
There is so much opportunity is this fucking basic technology question to show off what you know. You can talk about CAs, (browser and system), how websites identify themselves, how people use to pay a lot of certs but now we have LetsEncrypt, how even some of the paid cert providers now use ACME challenges LetsEncrypted pioneered, man-in-the-middle, certification revocation ... or hell, just fucking say it initiates a public/private key exchange! I'd even take "Secure Socket Layer," (even though it's TLS now) as a fucking bare minimum for our mid-level opening.
Zero clue what-so-ever. Some people can explain SQL-injection, but barely. If you're not out west, the talent pool is pretty bad out there.