Discovery Fundamentals Overview Flashcards
(31 cards)
How many steps are there to each phase in Discovery?
Five
What is a lightweight Java process running under a Linux or Windows platform that resides within enterprise networks?
MID Server
What interrogates the enterprise network for recognizable devices and applications they host?
Discovery
What protocol does the MID server use to communicate with ServiceNow?
HTTPS
What port does the MID server use to communicate with ServiceNow?
443
Which step in the Discovery process is this?
Discovery work is initiated by placing instructions in the form of output probes on the External Communications Channel (ECC)
Step 1
Which step in the Discovery process is this?
A worker job on the MID Server regularly polls the ServiceNow platform for work placed on the ECC queue
Step 2
Which step in the Discovery process is this?
Depending upon the type of probe (Port Scan/Classification/Identification/Exploration) the MID Server then interrogates the enterprise infrastructure (single devices, entire networks, a range of subnets or cloud services) to gather information about the discovery target
Step 3
Which step in the Discovery process is this?
Responses from the discovery targets are returned to the ECC Queue in the form of input probes, an XML payload containing information
Step 4
Which step in the Discovery process is this?
Sensors (or discovery patterns) decipher the XML payload and determine what course to take.
Step 5
The monitor checks for entries in the ECC queue with a value of ___________ and a state of _____________.
output, Ready
What are the different Discovery phases?
Scanning
Classification
Identification
Exploration
In what Discovery phase is a single Shazzam probe launched, scanning for open TCP on network-connectable nodes?
Scanning Phase
In what Discovery phase do classify sensors process data returned from classify probes (one per device), comparing against criteria for each class of device, attempting to classify the device specifically?
Classification
In what phase of Discovery would it be distinguished is a Windows platform is Windows 2003, Windows 2008, Windows 2012, etc.?
Classification
In what Discovery phase are patterns launched via the Horizontal Discovery Probe and, using CI Identifiers, an attempt is made to match information against CMDB records?
Identification
In what Discovery phase do patterns gather more information to populate CI attributes accordingly, both hardware and software characteristics?
Exploration
During what Discovery phase can Discovery also update the CMDB with details of installed software?
Exploration
During what Discovery phase can Discovery determine running processes?
Exploration
What determine and track running processes by launching additional process probes to create child configuration items with “Runs on::Runs” relationship with their host?
Process Classifiers
What does Service Mapping require?
- Entry Point (e.g. URL used to access service)
- Credentials for the supporting hosts of the applications
What dashboard displays port scanning data, IP address usage, and Discovery schedules. Key indicators include Total, Alive, Active, Non-reachable IP addresses, and open ports?
Shazzam Insights dashboard
Where can a user find a summary of discoveries that were triggered from Configuration Item schedules during the last 30 days, including errors that might have occurred?
Discovery Home page
What determine the probes that Shazzam launches, and from which MID Servers these probes are launched?
Behaviors