3.3 Flashcards

1
Q

Whats log management?

A

It’s a very diverse log sources which usually are sent via syslog and it requires a massive storage which also makes data rollup important.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Whats port scanning?

A

It’s finding devices and identify ports(Nmap).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Whats vulnerability scanning?

A

By using a vulnerability scanner, we can poke around and see whats open, identify systems and security devices. This is done from the inside and the outside.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does a vulnerability scan result help with?

A
  1. Shows the lack of security control(no firewall, no anti-virus, no anti-spyware)
  2. Shows misconfigurations (open shares and guest access)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Whats patch management?

A

It helps with system stability and security fixes which are incredibly important and if its more than one patch at a time, we get them in service packs all at once like windows monthly updates(incremental).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Whats rollback option?

A

The reverse of patch management (helps with going back to normal if one of the patches cause problems.)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Whats baseline review?

A

Reviewing baseline helps you to understand what the normal operation of your network might be over time.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is protocol analyzer used for?

A

It helps to solve complex application issues since it can get into the details by gathering packets on the network and they view traffic patterns.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Whats interface monitoring?

A

It’s used to see if a device is up or down.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Whats alerting in interface monitoring?

A

It’s a basic automated function we create to warn the user about the malfunction and sent to them via email or sms.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Whats SIEM?

A

(Security Information and Event Management)

  1. It helps with real-time info and security alerts.
  2. It also helps with log aggregation and lon-term storage.
  3. We can create data correlation.
  4. It helps with Forensic analysis by gathering details after an event.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Whats syslog?

A

It’s the standards for message logging that works on different systems and they use syslog protocols to send data to the SIEM and that means a lot of disk space.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Whats the difference between SIEM dashboard and SIEM logs?

A

SIEM logs show a lot of details while SIEM dashboard gives you a broader view.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Whats SNMP?

A

(Simple Network Management Protocol) Another way to monitor the network and all of the devices is to proactively query those devices for more information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Whats MIB?

A

(Management Information Base) It’s a collection database of data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Whats error rate?

A

We can monitor interfaces for errors. We can look at those error rates over time, and we can see exactly the specific error that may be occurring.

17
Q

Whats utilization?

A

another good monitoring statistic is to evaluate how much traffic is going through a particular interface and gather utilization details on every single interface on our network.

18
Q

What are packet drops?

A

These errors occur when the problem isn’t associated with the packet, but instead is associated with the system’s ability to process that packet.

19
Q

Whats the difference between bandwidth and throughput?

A

Throughput is an actual measure of how much data is successfully transferred from source to destination, and bandwidth is a theoretical measure of how much data could be transferred from source to destination.