3.2 Given a scenario, use network monitoring technologies. Flashcards

1
Q

What is a SNMP Trap?

A
  • Most SNMP operations expect a poll, devices then respond to the SNMP request, requiring constant polling.
  • Communicates over UDP 162
  • It allows you to configure a switch or router to look for a certain number of CRC errors to occur.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is an MIB?

A
  • Management Information Base
  • This is what SNMP provides to the network administrator.
  • Database contains Object Identifiers (OIDs).
    Occurs over UDP 161
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is SNMP v2c?

A
  • Data type enhancements, bulk transfers, but still “in the clear” (unencrypted).
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is SNMP v3?

A
  • This is the most current version that has message integrity, authentication, and encryption.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What role do community string play in SNMP?

A
  • A simple password that allows you access to the SNMP data on that device.
  • You can usually set-up multiple on a single device.
  • SNMPv3 uses username and password.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What role does authentication play in SNMP?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is flow data?

A
  • It gathers traffic statistics from all traffic flows
  • It is shared communication between devices.
  • Netflow is standard collection method; Probe and collector watches network communication and summary records are sent to the collector.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the benefit of packet capture?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the benefits of log aggregation?

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a SIEM?

A
  • Security Information and Event Management (console)
  • It is logging of security events and information that may contain a dashboard with real-time information.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is API integration?

A
  • Application Programming Interface
  • It allows you to automate the process of logging into devices one by one, utilizing a batch/script process at the command line to make changes to a switch or router.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the benefits of port monitoring?

A
  • Allows you to view an identical copy of the traffic traversing that port via port mirroring.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is “ad hoc” network discovery?

A
  • When you need to scan as needed or when required.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is “scheduled” network discovery?

A
  • Scans that occur at regular intervals that would report on moves, adds, and changes.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How is traffic analysis beneficial?

A
  • Detailed frame by frame description of the traffic that flows across your network.
  • View traffic summaries to generate detailed forensics reports.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is performance monitoring?

A
  • Amount of network use over time and can gather the information from SNMP, Netflow, protocol analysis, software agent.
17
Q

What is availability monitoring?

A
  • Is a device up or is it down?
  • The most important statistic
  • Can set it for alarms or alerts so that notification can be generated should an interface fail to report.
18
Q

What is configuration monitoring?

A
  • You have ten identical web servers, should you have ten identical configs? How do you confirm this?
19
Q

What is an SNMP OID?

A
  • Object Identifier
  • It can be referenced by name or number
  • Every variable in the MIB has a corresponding OID
  • Some of these are common across devices and some manufacturers define their own.
20
Q

What is a protocol analyzer?

A

It is able to gather frames on the network to solve complex application issues; it can sometimes be built into the device.