3.2 Given a scenario, use network monitoring technologies. Flashcards
What is a SNMP Trap?
- Most SNMP operations expect a poll, devices then respond to the SNMP request, requiring constant polling.
- Communicates over UDP 162
- It allows you to configure a switch or router to look for a certain number of CRC errors to occur.
What is an MIB?
- Management Information Base
- This is what SNMP provides to the network administrator.
- Database contains Object Identifiers (OIDs).
Occurs over UDP 161
What is SNMP v2c?
- Data type enhancements, bulk transfers, but still “in the clear” (unencrypted).
What is SNMP v3?
- This is the most current version that has message integrity, authentication, and encryption.
What role do community string play in SNMP?
- A simple password that allows you access to the SNMP data on that device.
- You can usually set-up multiple on a single device.
- SNMPv3 uses username and password.
What role does authentication play in SNMP?
What is flow data?
- It gathers traffic statistics from all traffic flows
- It is shared communication between devices.
- Netflow is standard collection method; Probe and collector watches network communication and summary records are sent to the collector.
What is the benefit of packet capture?
What are the benefits of log aggregation?
What is a SIEM?
- Security Information and Event Management (console)
- It is logging of security events and information that may contain a dashboard with real-time information.
What is API integration?
- Application Programming Interface
- It allows you to automate the process of logging into devices one by one, utilizing a batch/script process at the command line to make changes to a switch or router.
What are the benefits of port monitoring?
- Allows you to view an identical copy of the traffic traversing that port via port mirroring.
What is “ad hoc” network discovery?
- When you need to scan as needed or when required.
What is “scheduled” network discovery?
- Scans that occur at regular intervals that would report on moves, adds, and changes.
How is traffic analysis beneficial?
- Detailed frame by frame description of the traffic that flows across your network.
- View traffic summaries to generate detailed forensics reports.
What is performance monitoring?
- Amount of network use over time and can gather the information from SNMP, Netflow, protocol analysis, software agent.
What is availability monitoring?
- Is a device up or is it down?
- The most important statistic
- Can set it for alarms or alerts so that notification can be generated should an interface fail to report.
What is configuration monitoring?
- You have ten identical web servers, should you have ten identical configs? How do you confirm this?
What is an SNMP OID?
- Object Identifier
- It can be referenced by name or number
- Every variable in the MIB has a corresponding OID
- Some of these are common across devices and some manufacturers define their own.
What is a protocol analyzer?
It is able to gather frames on the network to solve complex application issues; it can sometimes be built into the device.