FirstHR

Web Administrator Interview Questions and Scorecard

Free web administrator interview questions for employers: 6 sets on hosting, uptime, security, backups, and vendors, plus a scorecard. Download as DOCX.

Nick Anisimov

Nick Anisimov

FirstHR Founder

Hiring
16 min

Web Administrator Interview Questions and Scorecard

Six question sets for the employer deciding what to ask: hosting and DNS, uptime and incidents, security and certificates, backups and change control, CMS and vendors, plus a weighted scorecard. Every question comes with why it is worth asking and what a strong answer sounds like. Download as DOCX.

The first web administrator interview I sat in on went badly, and it was my fault. I asked a list of definitions, the candidate answered them all correctly, and six weeks later we found out he had never restored a site from a backup in his life. The questions were fine. They were just the wrong ones, because I was testing vocabulary instead of method.

A web administrator keeps the site you sell from running. Hosting, DNS, certificates, updates, backups, uptime, and the agency that never quite answers on time. When it works, nobody notices. When it does not, your public front door is closed and you are the one refreshing the page.

At FirstHR we write hiring material for the owner or office manager who is making this call alone, without an HR department and usually without a technical background. These six sets give you the questions, the reason each one is worth asking, and what a strong answer sounds like, plus a weighted scorecard so the decision rests on evidence.

TL;DR
Interview a web administrator on five things: hosting and DNS fluency, uptime and incident method, security and certificates, backups and change control, and CMS administration with vendor coordination. The three highest-value questions are what they do in the first fifteen minutes of an outage, when they last restored from a backup, and who controls the domain on a site they run today. Score seven areas on a weighted 1-to-5 rubric. Download six sets and the scorecard as DOCX.

What a Web Administrator Actually Owns

A web administrator keeps an existing website running, while a web developer builds new functionality on it. The administrator owns hosting, DNS, TLS certificates, content management system and plugin updates, backups, monitoring, user access, and the relationship with the hosting provider or agency. Those duties are the entire interview.

The distinction matters because the two roles interview completely differently. A web developer is tested on building things. An administrator is tested on maintenance, recovery, and judgment under pressure, which are quieter skills and much easier to fake in a conversation about tools.

Duty areaWhat the administrator ownsWhat to ask about it
Hosting and DNSRegistrar, DNS records, host, CDN, certificatesWho controls the domain on a site they run today
AvailabilityMonitoring, outage response, performanceTheir first fifteen minutes of an unexplained outage
SecurityPatching, access control, certificate renewalThe least secure thing about a setup they run now
DataBackups, restores, retention, recovery timeThe last time they actually restored from a backup
Content platformCMS roles, plugins, publishing workflowHow a landing page gets live by Friday
VendorsAgency, host, and freelancer coordinationA time a vendor said a problem was not their fault

Read that table as an interview plan rather than a job description. Each row is one question set below, and a candidate who is strong in four rows and blank in one is a normal, hireable person. A candidate blank in three is a different job.

Scope the Role Before You Write the Questions

Decide first whether this person owns content only, content plus the platform, or content plus the platform plus the server. Each scope is a different candidate pool, a different pay band, and a different set of questions, and most bad web hires start as a posting that quietly assumed all three.

ResponsibilityContent and CMS scopeFull web administrator scope
Publishes and edits pages
Manages CMS users and roles
Applies plugin and platform updates
Owns certificates, DNS, and hosting
Owns backups and restore testing
Carries outage response expectations

If the right column is your reality, say so in the posting and weight the security and backup questions heavily. If only the left column is, you are hiring a content role and should not pay or interview for server work you will never ask for. The webmaster job description templates include a server-focused web administrator variant if you still need to write the posting.

Answer One Question Before You Interview Anyone
Does this person own content only, content plus the platform, or content plus the platform plus the server? Write the answer down. It decides which of the six sets below you use, which two areas you double-weight on the scorecard, and what you can honestly promise about on-call expectations. Interviewing before you have answered it is how a company ends up with a publisher managing its certificates, or a server engineer bored into quitting within a year.

The Six Question Sets

The questions are grouped into five competency sets plus a scorecard. Each set targets a different failure mode, and candidates rehearse them unevenly, so a strong performance on hosting fluency tells you very little about how they handle a live outage.

Core Administration and Hosting
Every candidate
Registrar, DNS, host, and CDN in plain language, plus what they actually touch every week on a site they own today. Start here.
Uptime and Incident Response
Method under pressure
The first fifteen minutes of an outage, how they learn the site is down, and what they changed after the worst one they handled.
Security, Certificates, Access
You have no security team
Certificate renewal, patching a CMS without breaking it, named accounts with least privilege, and multi-factor authentication.
Backups and Change Control
The restore is the test
What is backed up and where, the last time they actually restored, recovery time, staging, and how a change gets rolled back.
CMS, Content, and Vendors
The other half of the job
Publishing workflow, role separation inside the CMS, and holding an agency or hosting provider to a commitment in writing.
Scorecard and Red Flags
Score, do not guess
A weighted 1-to-5 rubric across seven areas plus a ten-item red-flag checklist, so the decision rests on written evidence.
Do Not Skip the Uncomfortable Sets
Candidates prepare for hosting and CMS questions. The sets that separate a real administrator from someone who has used a control panel are uptime, where you are watching method rather than knowledge, and backups, where a single question about their last actual restore does more work than an hour of discussion. Ask at least two questions from every set, and use the scorecard so a confident answer in one area does not quietly cover a blank in another.

6 Free Question Sets to Download

Download all six as one Word document, or copy the sets you need. Every set follows the same structure: who it is for, the questions with a stated reason for each, what a strong answer looks like next to a weak one, and space for notes. The last file is the scorecard.

Download All 6 Web Administrator Question Sets
Hosting, uptime and incidents, security, backups, CMS and vendors, plus a weighted scorecard with a red-flag checklist. All in one DOCX.

Set 1: Core Administration and Hosting

The opening set for every candidate: what they run today, who controls the domain and DNS, the registrar and host and CDN in plain language, and what routine maintenance actually looks like for them.

Core Web Administration and Hosting Questions
WEB ADMINISTRATOR INTERVIEW: CORE ADMINISTRATION AND HOSTING
Candidate: __
Interviewer: __
Date: __
USE THIS SET FOR: every web administrator candidate, as the opening block.

QUESTIONS TO ASK

1. Walk me through a website you are responsible for today. Where is it hosted,
what runs it, and what do you personally touch every week?
Why ask it: it separates people who own a site from people who once edited
one. The answer also tells you which layer they actually live in.
2. Who controls the domain registration and the DNS records for that site,
and what would you change about that setup?
Why ask it: domain and DNS control is the single most common gap at a small
business. A candidate who has an opinion here has been burned before.
3. Describe the difference between the registrar, the DNS provider, the host,
and the CDN, using a site you have run.
Why ask it: it is a fast, fair competence check that does not require a
whiteboard, and it is the vocabulary you will use with them every month.
4. What does routine weekly and monthly maintenance look like on a site
you own?
Why ask it: the job is mostly maintenance. Vague answers here predict a
site that quietly rots.
5. How do you decide whether to fix something yourself or hand it to a
developer or the hosting vendor?
Why ask it: at a small business this judgment call happens weekly and it
controls your spend.
6. Tell me about a migration you ran, hosting, platform, or domain. What
broke, and what did you do about it?
Why ask it: migrations expose planning, rollback thinking, and honesty.
7. What is the current state of documentation on the sites you run?
Why ask it: an administrator who documents is an administrator you can
replace or supplement later without pain.

WHAT A STRONG ANSWER LOOKS LIKE

A strong candidate names specific systems and specific weekly tasks, and can
draw the line between registrar, DNS, host, and CDN without hedging. They talk
about the site as a system they are accountable for, including the parts they
inherited and dislike. On the fix-versus-escalate question they give you a rule
of thumb tied to risk and cost, not a shrug.
A weak candidate describes only content edits, cannot say who controls the
domain, or answers every question with the name of a tool instead of a task.
Watch for someone who has only ever worked inside a CMS admin panel if the
role you are filling includes the server.

NOTES

[Record the systems named, the weekly tasks described, and any gaps.]

Set 2: Uptime, Performance, and Incident Response

The most revealing set on the page. The first fifteen minutes of an unexplained outage, how they learn the site is down, who they tell while it is happening, and what they changed after the worst one.

Uptime, Performance, and Incident Response Questions
WEB ADMINISTRATOR INTERVIEW: UPTIME, PERFORMANCE, AND INCIDENTS
Candidate: __
Interviewer: __
Date: __
USE THIS SET FOR: any role where the site going down costs you orders,
leads, or reputation. That is almost every role.

QUESTIONS TO ASK

1. The site is down and you have no idea why. Walk me through your first
fifteen minutes.
Why ask it: this is the single most revealing question on the page. You
are testing method under pressure, not knowledge.
2. How do you find out the site is down before a customer tells you?
Why ask it: monitoring is cheap and most small business sites have none.
A candidate who sets it up unprompted saves you real money.
3. A customer says the site is slow. It looks fine to you. What do you do?
Why ask it: it tests whether they measure or guess, and whether they take
a vague complaint seriously.
4. Name the usual suspects when a business site loads slowly, and how you
would confirm each one.
Why ask it: a good administrator has a short ranked list and a way to
verify, rather than a generic answer about images.
5. Who do you tell, and when, while an outage is still going on?
Why ask it: communication during an incident is a business skill, and
silence during downtime is what actually damages trust.
6. Tell me about the worst outage you have handled. What was the root cause,
and what did you change afterward?
Why ask it: the follow-up change is the whole answer. No change means no
learning.
7. What would you put in place in your first month so the next outage is
shorter?
Why ask it: it turns the interview into a preview of their plan for you.

WHAT A STRONG ANSWER LOOKS LIKE

Strong candidates narrow before they act: confirm the outage is real and not
local, check whether it is DNS, the host, the certificate, or the application,
look at what changed most recently, and only then start fixing. They mention
telling someone early. They name a monitoring tool and an expected alert path.
On the worst-outage question they give a specific root cause and a specific
change that followed, such as adding monitoring, a staging step, or a backup
restore test.
Weak answers start with restarting things at random, blame the previous
provider without evidence, or describe an outage with no aftermath.

NOTES

[Record the diagnostic order they used and whether they communicated.]
Still Using Spreadsheets for Onboarding?
Automate documents, training assignments, task management, and track onboarding progress in real time.
See How It Works

Set 3: Security, Certificates, and Access Control

Certificate renewal, patching a content management system without breaking the site, named accounts instead of shared logins, and one honest question about the weakest part of a setup they run right now.

Security, Certificates, and Access Control Questions
WEB ADMINISTRATOR INTERVIEW: SECURITY, CERTIFICATES, AND ACCESS
Candidate: __
Interviewer: __
Date: __
USE THIS SET FOR: every candidate. A small business web administrator is
usually the closest thing you have to a security owner for the public site.

QUESTIONS TO ASK

1. How do you manage TLS certificates across the sites you run, including
renewal?
Why ask it: an expired certificate is the most common self-inflicted
outage in small business web work, and it is fully preventable.
2. Walk me through how you keep a content management system and its plugins
patched without breaking the site.
Why ask it: patching is the core security duty and the core risk. You want
a process, not enthusiasm.
3. How do you handle admin accounts and passwords for the site, the host,
and the registrar?
Why ask it: shared logins are the default at small companies. Listen for
whether they will fix that or quietly continue it.
4. What is your position on multi-factor authentication for site and hosting
accounts?
Why ask it: a candidate who treats it as optional is telling you something
about every other control they will set up.
5. A form on the site is being flooded with spam submissions. How do you
diagnose and stop it?
Why ask it: a realistic, low-drama scenario that tests practical judgment
rather than theory.
6. How would you know if the site had been defaced or had malicious code
injected, and what is your first move?
Why ask it: detection and response, not prevention theater.
7. What is the least secure thing about a site you currently run, and why
is it still that way?
Why ask it: honest candidates answer this well. It also reveals how they
handle constraints they do not control.

WHAT A STRONG ANSWER LOOKS LIKE

A strong candidate automates certificate renewal and monitors expiry rather
than relying on memory. They patch on a schedule, test on staging or a copy
first where the risk warrants it, and can say what they would do if an update
broke the site. They want individual named accounts with least privilege and
multi-factor authentication, and they are direct about the weak spot in their
current setup.
Weak answers treat security as the hosting company problem, describe shared
admin logins as normal, or claim nothing on their current site is insecure.
The last one is not confidence. It usually means they have not looked.

NOTES

[Record their certificate process, patch cadence, and access hygiene.]

Set 4: Backups, Recovery, and Change Control

What is backed up and where, when they last performed a real restore, how long recovery would take, and whether they can change a live site without taking it down or losing the ability to roll back.

Backups, Recovery, and Change Control Questions
WEB ADMINISTRATOR INTERVIEW: BACKUPS, RECOVERY, AND CHANGE CONTROL
Candidate: __
Interviewer: __
Date: __
USE THIS SET FOR: any role where the site holds content, customer data, or
orders you cannot recreate by hand.

QUESTIONS TO ASK

1. Describe the backup setup on a site you run: what is backed up, how often,
where it is stored, and how long it is kept.
Why ask it: four specifics. A candidate who can give all four has actually
built one.
2. When did you last restore from a backup, and how did it go?
Why ask it: the most important question in this set. A backup that has
never been restored is a hope, not a backup.
3. How long would it take you to bring the site back if the host lost
everything tonight?
Why ask it: it forces a real number and exposes whether they know where
the pieces live.
4. How do you make a change to a live site without taking it down?
Why ask it: staging, off-hours windows, and rollback plans separate
professionals from improvisers.
5. Walk me through a change you had to roll back. What made that possible?
Why ask it: rollback capability is a design decision made before the
change, not after.
6. Who approves a change that could affect the public site, and how do you
record what changed?
Why ask it: at a small business the answer is often nobody. You want a
candidate who proposes a light process rather than none.
7. What would you back up that most people forget?
Why ask it: strong candidates mention the database, uploaded files,
configuration, and the certificate or DNS records, not just the files.

WHAT A STRONG ANSWER LOOKS LIKE

Strong candidates describe backups that are automatic, offsite or at least
separate from the live host, retained long enough to survive a problem nobody
noticed for a week, and tested by an actual restore. They can estimate recovery
time and explain what makes it long. On changes they describe a staging copy or
a low-traffic window, and a way back.
Weak answers say the host handles backups without knowing what that includes,
have never performed a restore, or describe editing production live because it
is faster. The second one is the disqualifier.

NOTES

[Record the last real restore, the recovery estimate, and rollback method.]
Companies Using FirstHR Onboard 3x Faster
Join hundreds of small businesses who transformed their new hire experience.
See It in Action

Set 5: CMS, Content Workflow, and Vendor Coordination

The other half of the job: publishing workflow, role separation inside the CMS, accessibility, and holding an agency or hosting provider to a commitment when they say the problem is not theirs.

CMS, Content Workflow, and Vendor Coordination Questions
WEB ADMINISTRATOR INTERVIEW: CMS, CONTENT, AND VENDORS
Candidate: __
Interviewer: __
Date: __
USE THIS SET FOR: roles where the administrator also publishes content and
manages the agency, freelancers, or the hosting provider.

QUESTIONS TO ASK

1. Which content management systems have you administered, and what did you
actually do in them beyond publishing?
Why ask it: the gap between publishing and administering is the whole
difference between the two candidate types you will see.
2. Marketing wants a new landing page live by Friday. Walk me through how
that happens.
Why ask it: it tests real workflow, permissions, review, and the handoff
between content and code.
3. How do you set up access for people who publish content but should not
touch settings or plugins?
Why ask it: role separation inside the CMS is a control most small
businesses never configure.
4. Tell me about working with an outside developer or agency. What did you
own, and what did they own?
Why ask it: most small business sites are shared with a vendor. You need
someone who can hold a vendor to a deadline.
5. A vendor says a problem is not their fault. How do you resolve it?
Why ask it: this is a large share of the job and it is mostly evidence
gathering and persistence, not technical skill.
6. How do you keep a site accessible and usable for people with
disabilities, and whose job do you think that is?
Why ask it: accessibility is increasingly part of the role, and the answer
tells you whether they think in terms of users or tickets.
7. What would you refuse to do yourself and insist on bringing in help for?
Why ask it: knowing the edge of your competence is a senior trait at any
level.

WHAT A STRONG ANSWER LOOKS LIKE

Strong candidates name the systems and describe administration tasks: user
roles, plugin and theme management, staging, updates, integrations, and forms.
They describe a publishing workflow with a review step and a rollback. On
vendors they gather evidence, put it in writing, and follow up, and they can
describe a time they held a vendor to account without a blowup.
Weak answers describe only content entry, give every person full administrator
access because it is easier, or resolve vendor disputes by escalating to you
immediately.

NOTES

[Record the systems administered and the vendor handling example.]

Set 6: Scorecard and Red Flags

A weighted 1-to-5 rubric across seven areas with space for written evidence, plus a ten-item red-flag checklist you can tick during the conversation. Use it with any set above.

Web Administrator Scorecard and Red Flags
WEB ADMINISTRATOR INTERVIEW SCORECARD
Candidate: __
Interviewer: __
Date: __
Score each area from 1 (poor) to 5 (excellent). Write one line of evidence
from the interview under each score. Score before you discuss with anyone else.

SCORING AREAS

Hosting, DNS, and platform fluency Score: [ 1 2 3 4 5 ]
Evidence: __
Uptime, monitoring, and incident method Score: [ 1 2 3 4 5 ]
Evidence: __
Security, certificates, and access Score: [ 1 2 3 4 5 ]
Evidence: __
Backups, restore, and change control Score: [ 1 2 3 4 5 ]
Evidence: __
CMS administration and content workflow Score: [ 1 2 3 4 5 ]
Evidence: __
Vendor coordination and communication Score: [ 1 2 3 4 5 ]
Evidence: __
Judgment and working without supervision Score: [ 1 2 3 4 5 ]
Evidence: __

WEIGHTING (set this before you interview anyone)

Mark the two areas that matter most for your site and double their score.
A self-hosted store weights security and backups. A marketing site on a
managed platform weights CMS workflow and vendor coordination.

RED FLAGS

[ ] Cannot say who controls the domain or DNS on a site they run today
[ ] Has never performed a restore from backup
[ ] Edits the live site directly because it is faster
[ ] Treats shared admin logins as normal and has no plan to change it
[ ] Says security is entirely the hosting provider responsibility
[ ] Describes an outage with no root cause and no follow-up change
[ ] Answers every question with a tool name instead of a task
[ ] Cannot name one weak spot in a setup they currently run
[ ] Will not put anything in writing with a vendor
[ ] Vague about what they personally did versus what the team did

SUMMARY

Total score: ______ / 35 (before weighting)
Overall recommendation: [ ] Strong yes [ ] Yes [ ] No [ ] Strong no
Key strengths: __
Key concerns: __
Reference check completed: [ ] Yes [ ] No
Interviewer signature: __

How to Judge Answers If You Are Not Technical

You do not have to grade the technology, only the method. Ask about real work rather than definitions, then listen for four patterns: did they narrow before acting, did they measure before concluding, did they change something afterward, and can they separate what they did from what the team did.

That is a skill you already have from every other hire you have made. The three exchanges below are the ones where the difference is loudest, and they work as a quick calibration before you sit down with the full sets.

The site is down and you do not know why. What do you do first?
Strong answer: Confirms the outage is real and not local, then narrows by layer: is it DNS, the host, an expired certificate, or the application. Checks what changed most recently. Tells someone early that the site is down and that a fix is in progress, before disappearing into the problem.
Weak answer: Starts restarting or reinstalling things at random, or fixes silently for an hour while sales fields customer calls with no information.
When did you last restore a site from backup?
Strong answer: Gives a specific occasion and what it taught them, or says they run a scheduled test restore. Knows what the backup contains: database, uploaded files, and configuration, not only the page files. Can estimate how long a full recovery takes and what makes it long.
Weak answer: Says the hosting company handles backups, without knowing what is included, how far back it goes, or whether a restore has ever been attempted.
Who controls the domain and DNS for the site you run today?
Strong answer: Answers immediately and with detail, and usually has an opinion about it: the registrar account should belong to the business, not to an agency or a former employee, with the owner holding access. A candidate who has been locked out once will be emphatic about this.
Weak answer: Does not know, or says an agency has it and has never questioned that. This is the most common way a small business loses control of its own website.

One more thing carries surprising weight: ask a candidate to explain the difference between the registrar, DNS, the host, and the CDN in plain language. It is a fair check because you will use exactly that vocabulary with them every month, and it rewards clarity rather than depth.

Follow-Ups, Signals, and Red Flags

The written questions start the conversation and the follow-ups decide it. Push for the specific system, the specific outcome, the specific change that came after. The patterns below are what you are listening for underneath whatever answer you get.

Diagnostic method
Narrows by layer before touching anything
Checks what changed most recently
Says what they would do if the first theory is wrong
Ownership instincts
Knows who holds the domain and DNS
Wants named accounts, not shared logins
Documents so someone else could take over
Honest self-assessment
Names the weakest part of a setup they run
Says what they would escalate rather than attempt
Separates what they did from what the team did
Red flags
Never restored from a backup
Edits the live site directly to save time
Blames the host for every past problem

The most useful follow-up is a flat what happened next. Strong candidates have an ending: the root cause, the fix, the thing they changed so it would not recur. Weaker ones stop at the drama and never get to the aftermath, which is where the actual skill lives.

Structure Beats a Good Conversation
A structured interview, where every candidate answers the same questions scored against the same rubric, predicts on-the-job performance more reliably than an unstructured conversation. It is also the practical safeguard against basing a decision on protected characteristics, which the EEOC prohibits. For a technical role the risk is specific: a candidate who shares your taste in hosting can feel like a great fit while never having tested a restore.

The Access Questions Most Interviews Skip

A web administrator ends up holding the registrar login, the hosting account, the CMS administrator role, and often the certificate and DNS. Ask about that in the interview, because the answers tell you as much about the person as any technical question does.

Ask who should own the registrar account
The right answer is the business, in an account tied to a company email nobody personally owns. A candidate who volunteers this has seen a company locked out of its own domain and will protect you from it.
Ask what access they need on day one
A strong candidate asks for the minimum to start and expects to earn more, and is comfortable with you keeping owner-level access to the registrar and the host. Demanding everything immediately is worth a second look.
Ask what they would hand over if they left
The answer should be a documented list: accounts, credentials location, vendor contacts, the backup location, and the runbook. If they cannot describe a handover, you are hiring a future single point of failure.
Ask how they would document the setup
One page listing where the domain, DNS, host, certificate, backups, and CMS admin live is enough. An administrator who writes it in the first month is worth more than one who is faster at everything else.

The pattern to listen for is comfort with oversight. A candidate who expects the business to keep owner-level access to the registrar and the host, and who volunteers a handover plan before you ask, is describing how they will behave for the entire engagement. Resistance here is worth a second interview.

Federal cybersecurity guidance for small organizations pushes the same basics you are testing for: unique accounts, multi-factor authentication, patching on a schedule, and backups that have been restored at least once. The CISA Cyber Essentials material is a useful yardstick if you want to check a candidate answer against something official.

How to Run the Interview

Run it the same way for every candidate: same core questions, same order, scored immediately afterward. Consistency is what makes two very different interviews comparable, and it is the part that falls apart first when the owner is squeezing interviews between everything else.

StepWhat to doTime
1. ScopeWrite down whether the role includes the server, before you post it15 min, once
2. Choose setsPick the sets that match the scope and fix the question order20 min, once
3. Weight the rubricDouble-weight the two areas that matter most for your site10 min, once
4. InterviewSame questions, same order, notes captured as you go45 to 60 min each
5. Work sampleOptional paid two-hour diagnosis on a copied site, same brief for all2 hours, finalists
6. Score and decideRate seven areas with evidence, independently, then compare15 min each

Score right after each conversation while the answers are still exact. If more than one person interviews, everyone scores before anyone talks, which keeps the most senior opinion in the room from becoming the group opinion by default.

Then close the loop properly. Write the interview feedback down, check references with someone who saw the candidate day to day rather than a manager two levels up, and treat a reference check for this role as a real step rather than a formality, because the person will hold your credentials.

Web Administrator Pay

There is no separate federal wage line for this title, so every single number you see quoted is a proxy. Federal data classifies the role inside a residual category full of specialized enterprise jobs, which means the headline median overstates a small business web administrator badly.

Median $116,580 in a Residual Category (BLS OEWS, May 2025)
O*NET classifies Web Administrators under the Bureau of Labor Statistics residual category Computer Occupations, All Other, whose national median annual wage was $116,580 in the Occupational Employment and Wage Statistics survey (May 2025). The same category's 10th and 25th percentiles, $55,940 and $79,370, are far closer to a small business generalist. Published comparators: Web Developers $92,650, Network and Computer Systems Administrators $99,130, Computer Network Support Specialists $76,220 (U.S. Bureau of Labor Statistics, OEWS national estimates).

For a generalist maintaining one small business site, benchmark toward the support end of that range and adjust upward for every extra layer you are asking one person to cover. A part-time or retained arrangement is also common, and if you go that route classify the relationship carefully rather than by convenience.

Scope also drives classification. A contractor or employee decision and the overtime question both turn on actual duties, not on the title you put in the posting. The Department of Labor computer employee exemption fact sheet is the document to read before you decide, and a maintenance-focused web administrator generally fails its duties test.

Fair, Legal, and Structured Interviewing

Fair, legal, and structured are the same practice seen from three angles. Asking every candidate the same job-related questions in the same order keeps you compliant, reduces bias, and produces better hires, and technical interviews have specific traps worth naming.

Ask about the job, not the person
Federal anti-discrimination law, enforced by the EEOC, prohibits basing hiring decisions on protected characteristics, and questions that probe them create risk even when they are asked as small talk. Avoid age, race, religion, national origin, sex, pregnancy or family plans, disability, and genetic information. Technical interviews have their own version of this trap: asking when someone learned to code, which university they attended and in what year, or where they are originally from because of an accent. None of that predicts whether the site stays up. Keep every question tied to running a website. The sets on this page are written to stay on the job. This is general information, not legal advice.
Use the same core questions for every candidate
Ask each candidate the same core questions in the same order and score them on the same rubric. Structured interviews predict on-the-job performance far better than a free-flowing technical chat, and they are the main defense against a decision that rests on rapport. For a web administrator this matters more than usual, because a candidate who shares your taste in hosting providers can feel like a great fit while never having restored a backup. Write the questions before you meet anyone, keep the order fixed, and let the scorecard settle disagreements between two candidates you liked for different reasons.
Prefer a small paid work sample to a quiz
For a web administrator, a two-hour paid exercise tells you more than any trivia question: hand over a copy of a site with a broken form or an expired certificate and ask for a written diagnosis and fix plan. Keep it short, pay for the time, give the same brief to every finalist, and state the criteria in advance. Never ask a candidate to do real work on your production site as an unpaid test. If you do use a work sample, apply it consistently to everyone at that stage, and keep the brief job-related, because selection procedures that screen candidates should be tied to the job.
Classify the role correctly before you post it
The FLSA computer employee exemption covers systems analysts, programmers, software engineers, and similarly skilled workers whose primary duty is systems analysis or program design and development, paid on a salary basis at the standard level or hourly at no less than $27.63. The Department of Labor states that job titles do not determine exemption status, and that employees whose work merely depends on computers, without being primarily engaged in systems analysis and programming, are not exempt. A web administrator doing patching, publishing, and vendor coordination is doing skilled maintenance, which generally fails the duties test. Run a real duty analysis before you decide. This is general information, not legal advice.

Keep every question tied to running a website, and watch the technical small talk about when someone learned to code or which year they graduated. Those drift toward age and national origin without telling you anything about whether the site stays up. This is general information, not legal advice, and a list of questions to avoid is worth reading before you sit down.

Interviewing a Web Administrator Without HR

At a large company this hire goes through a technical panel, a security review of the access request, and a recruiter holding the scorecards. At a small business it is one conversation, run by the person who also has to decide what the role even is. That difference shapes everything.

You are hiring for a job you cannot personally evaluate
Most owners hiring a web administrator are not web administrators. The instinct is to ask trivia, and trivia is exactly what a mediocre candidate prepares for. The alternative is to ask about work they have done and listen for structure: did they narrow before acting, did they measure before concluding, did they change something after the incident. Every question in these sets carries a note on why it is worth asking and what a strong answer sounds like, so you can grade method rather than vocabulary. You will hear the difference between someone describing a system they own and someone describing a tool they have used.
This one hire will hold the keys to your public front door
A web administrator ends up with the registrar login, the hosting account, the CMS administrator role, and often the certificate and DNS. At a company with an IT department that access is granted, logged, and revoked by process. At a small business it is handed over in a chat message and never reviewed again. Interview for that reality: ask who should own the registrar account, ask what they would need on day one, and ask what they would hand over if they left. A candidate who welcomes you keeping owner-level access is showing you how they will behave for the whole engagement.
The interview is the easy part; the handover is where it goes wrong
Once you choose someone, the work shifts to getting them productive without losing control of your own systems: a written offer, a confidentiality and acceptable-use acknowledgment, provisioned accounts with least privilege, and a documented list of what they now hold. FirstHR fits that side of it for a small business: send the offer for e-signature, run the new hire paperwork and onboarding workflow, assign the access and documentation tasks, and store every signed document on the employee profile. To be clear on scope, FirstHR is an onboarding and HR platform, not hosting, monitoring, or website software, so pair it with those. Applicant tracking is coming soon to FirstHR.

None of that requires an HR department. It requires the questions written before the first conversation, the same set for everyone, and a scorecard filled in while the answers are still fresh. That is the whole method, and it is what turns one owner running one interview into something as rigorous as a panel.

If your role sits closer to internal systems than to the public site, the system administrator questions fit better, and the network administrator set covers connectivity and firewalls. Applicant tracking is coming soon to FirstHR.

From Interview to Onboarding

The interview is the short part. Once you choose someone, the job is getting them productive without handing over more control than you meant to: a written offer, a signed acceptable use policy, named accounts with least privilege, and a record of what they now hold.

Offer and acceptable use
A written offer plus a confidentiality and acceptable-use acknowledgment signed before day one, since this hire will hold credentials to your public site.
Provision with least privilege
Named accounts only, no shared logins, multi-factor authentication everywhere, and owner-level access to the registrar and host retained by the business.
Write the setup down together
In the first month, produce one page recording where the domain, DNS, host, certificate, backups, and CMS admin live, and who holds each account.
Name the first ninety days
Pick the first real improvement, usually monitoring or a tested restore, and define what good looks like at thirty, sixty, and ninety days.

Do the documentation step in the first month, while the new administrator is still discovering your setup and writing things down feels natural. One page covering the domain, DNS, host, certificate, backups, and CMS admin is enough, and it is what makes the eventual offboarding a checklist rather than an archaeology project.

FirstHR connects the offer, the paperwork, the e-signatures, and the access and setup tasks in one workflow, and stores every signed document on the employee profile so a small business can run hiring through to onboarding from one system. FirstHR is an onboarding and HR platform, not hosting, monitoring, or website software, so pair it with those. Applicant tracking is coming soon to FirstHR.

Key Takeaways
Scope the role first: content only, content plus platform, or content plus platform plus server changes the questions and the pay band.
The three highest-value questions are the first fifteen minutes of an outage, the last real restore from backup, and who controls the domain today.
Judge method rather than vocabulary: did they narrow before acting, measure before concluding, and change something afterward.
Ask the access questions most interviews skip, including what they would hand over if they left, since this hire holds your public front door.
Score seven areas on a weighted 1-to-5 rubric with written evidence, independently, before anyone discusses the candidate.
Classify the role by actual duties, because the FLSA computer employee exemption turns on the work, not on the job title.

Frequently Asked Questions

What questions should I ask a web administrator candidate?

Ask questions that cover five areas: hosting and DNS fluency, uptime and incident response, security and certificates, backups and change control, and CMS administration with vendor coordination. The highest-value single question is what they would do in the first fifteen minutes of an unexplained outage, because it tests method rather than trivia. Close behind it are when they last restored a site from backup, and who controls the domain and DNS on a site they run today. Ask them to describe a site they are responsible for now, including what they personally touch every week, and ask what the least secure thing about it is. Every question should have a stated reason and an expected shape of answer, so a non-technical interviewer can grade it. This page provides six ready-to-use sets with exactly that guidance plus a weighted scorecard.

What is the difference between a web administrator and a web developer?

A web administrator keeps an existing website running; a web developer builds new functionality. The administrator owns hosting, DNS, TLS certificates, content management system and plugin updates, backups, uptime monitoring, user access, and coordination with the hosting provider or agency. The developer writes the code that creates features and pages. The two overlap at small companies, where one person often does both, but they are different interviews: the administrator is tested on maintenance, recovery, and judgment under pressure, while the developer is tested on building things. If your site is stable and the pain is downtime, expired certificates, stale plugins, and nobody knowing who holds the domain, you need an administrator. If the pain is that the site cannot do what the business needs, you need a developer. Write the job description for the one you actually need before you interview.

How do I interview a web administrator if I am not technical?

You do not need to grade the technology, only the method. Ask about real work rather than definitions, and listen for four things: does the candidate narrow a problem before acting, do they measure rather than guess, did they change something after an incident, and can they separate what they personally did from what a team did. A strong candidate can explain the difference between the registrar, DNS, the host, and the CDN in plain language, which is itself a fair competence check because you will use that vocabulary with them every month. Each question set on this page includes a note on what a strong answer sounds like and what a weak one sounds like, so the comparison is concrete. If you want extra confidence, add a short paid work sample and check references with someone who saw their day-to-day work.

What are the biggest red flags in a web administrator interview?

The three that matter most are: never having performed a restore from backup, not knowing who controls the domain and DNS on a site they run today, and editing the live site directly because it is faster. Each one predicts a specific future incident. Other warning signs include treating security as entirely the hosting provider responsibility, describing shared administrator logins as normal with no plan to change that, answering every question with a tool name instead of a task, and describing a past outage with no root cause and no follow-up change. Being unable to name a single weak spot in a setup they currently run is also a flag, because it usually means they have not looked rather than that nothing is wrong. The downloadable scorecard on this page includes a ten-item red-flag checklist you can tick during the interview.

Is a web administrator exempt or non-exempt from overtime?

Often non-exempt, and the job title never decides it. The FLSA computer employee exemption covers systems analysts, programmers, software engineers, and similarly skilled workers whose primary duty is systems analysis, program design, development, or testing, paid either on a salary basis at the standard salary level or hourly at no less than $27.63. The Department of Labor states that job titles do not determine exemption status, and that employees whose work is merely dependent on computers, without being primarily engaged in systems analysis and programming, are not exempt. A web administrator whose week is plugin updates, certificate renewals, content publishing, and vendor coordination is doing skilled maintenance rather than systems design, so the duties test generally fails. A deeply server-focused variant is the most likely to qualify, and it still needs a genuine duty analysis. This is general information, not legal advice.

How much does a web administrator cost?

There is no separate federal wage line for the title, so treat any single figure as a proxy. O*NET classifies Web Administrators under the Bureau of Labor Statistics residual category Computer Occupations, All Other, which had a national median annual wage of $116,580 in the Occupational Employment and Wage Statistics survey for May 2025. That bucket is full of specialized enterprise roles and overstates a small business web administrator considerably. The 10th and 25th percentiles of the same category, $55,940 and $79,370, sit far closer to reality for a generalist maintaining one site. Adjacent published occupations give better anchors: Web Developers at a $92,650 median, Network and Computer Systems Administrators at $99,130, and Computer Network Support Specialists at $76,220. Benchmark to the support end of that range for a maintenance-focused role, then adjust for how many layers you are asking one person to cover and for your local market.

Should I hire a web administrator or use a freelancer or agency?

It depends on how much the site changes and how expensive downtime is. A freelancer or agency on a monthly retainer usually makes sense when the site is stable, changes a few times a month, and an hour of downtime is an annoyance rather than lost revenue. An in-house web administrator earns their cost when the site is central to how you sell, when changes are frequent, or when you already depend on a vendor who is slow to respond. A common middle path is a part-time administrator who owns the relationship and the access while an agency handles specialist work. Whichever you choose, the business should hold the registrar and hosting accounts, because the most expensive version of this decision is discovering that an outside party controls your domain. Interview a retained vendor with the same question sets you would use for an employee.

What questions are illegal to ask in a web administrator interview?

Avoid any question that probes characteristics protected under federal law, which the EEOC enforces: age, race, color, religion, national origin, sex, pregnancy or family plans, disability, and genetic information. Technical interviews have their own versions of these traps. Asking when someone first learned to build websites, which year they graduated, or where they are originally from because of an accent all edge toward age or national origin, and none of them predicts whether your site stays up. You may ask whether a candidate can perform the essential functions of the job, whether they are legally authorized to work, and anything about their actual experience running websites. The simplest safeguard is to ask every candidate the same job-related questions in the same order and score them on the same rubric. This is general information, not legal advice.

Ready to transform your onboarding?

7-day free trial No credit card required
Start Your Free Trial