Alerting and Monitoring Flashcards
(62 cards)
What is the importance of alerting and monitoring?
Crucial for maintaining integrity, confidentiality, and availability of information systems
What are the two main components of alerting and monitoring?
- Alerting
- Monitoring
What is a True Positive in alerting?
Correctly identifies a legitimate issue
What is a False Positive in alerting?
Incorrectly indicates an issue when there isn’t one
What is a True Negative in alerting?
Correctly recognizes the absence of an issue
What is a False Negative in alerting?
Fails to alert about a real issue
What are the goals of an alerting system?
- Maximize true positives
- Minimize false positives to avoid alert fatigue
What are the types of monitoring?
- Automated Monitoring
- Manual Monitoring
What is log aggregation?
Collecting and centralizing log data
What is the purpose of alerting?
Notification of potential security incidents
What does scanning involve in monitoring?
Continuous examination for anomalies
What is the purpose of reporting in monitoring?
Generating reports on system and network status
What is archiving in the context of monitoring?
Storing historical data
What is SNMP and its primary use?
Widely used in network management systems to monitor and manage network devices
What is the function of a Security Information and Event Management (SIEM) system?
Integrated management technologies for holistic security views
What does SIEM collect and aggregate?
Log data
What is the Security Content Automation Protocol (SCAP)?
Enables automated vulnerability management, measurement, and policy compliance evaluation
What are network traffic flows?
A sequence of packets from source to destination identifiable by a unique set of identifiers
What does a ‘Single Pane of Glass’ refer to?
Consolidates data from different sources into a unified display
What is a baseline in monitoring?
A reference point representing normal system behavior under typical operating conditions
What does application monitoring focus on?
Managing and monitoring software application performance and availability
What tools are used for application monitoring?
- New Relic
- AppDynamics
What does infrastructure monitoring observe?
Physical and virtual infrastructure, including servers and networks
What types of scanning are included in alerting and monitoring activities?
- Vulnerability scanning
- Configuration scanning
- Code scanning