Network Logging and Monitoring Flashcards

1
Q

Only routers can stop broadcast traffic. TRUE of FALSE?

A

False. Switches can too but not by default

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What’s the name of Microsoft’s graphical utility used to capture network traffic called? In order to use it what capability does your NIC need to have?

A

Network Monitor

NIC needs to operate in promiscuous mode

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What OSI layer does SNMP work at?

A

Layer 7

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

SNMP agents send what kind of messages about them to the what?

A

SNMP Trap messages to the Network Management Station (NMS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

The NMS solicits for what on an SNMP agent using what type of message?

A

Solicits for an Object ID (OID) using SNMP GET

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

In SNMP, what are SET messages used for?

A

configuring agents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What SNMP message gathers many types of info at once to cut down on multiple GET messages?

A

GET BULK

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which version of SNMP uses plain-text authentication with MD5/SHA, no encryption and uses UDP by default?

A

SNMPv2c

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what utility allows you to log events based on 8 (0-7) severity levels?

A

syslog

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

By default, what two places do all system messages and debug output generated by the IOS go out of?

A

Console Port and RAM buffer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

List the top 4 (by urgency) severity states by number and description

A

0 - Emergency (lowest level)
1 - Alert
2 - Critical
3 - Error

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

List the lower 4 severity states by number and description

A

4 - Warning
5 - Notification
6 - Information
7 - Debugging

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

If you configure severity level 03, what levels of severity will you be notified on?

A

0 through 3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

SIEM provides what?

A

real-time analysis of security alerts generated by network hardware applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Regarding security event management:
What term is used to describe the long-term storage, analysis and reporting on log data?
What term is used to describe the management of real-time monitoring and correlation of events?

A

Security Information Management (SIM)
Security Event Management
(SIM, SEM and SIEM are often used interchangeably)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What software monitoring products are used exclusively by security network admins?

A

SIEM (security information and event management) software products

17
Q

When I a SIEM alert is triggered and notification generated, who typically addresses the problem?

A

The Security Operations Centre

18
Q

List the 3 types of system event logs?

A

1) Application
2) Security
3) System

19
Q

Windows Server 2008 offered what optional monitoring and optimization tool?

A

System Centre Operations Manager 2010

20
Q

Utilization cover what 3 things?

A

1) Wired/Wireless Bandwidth utilisation
2) Server/Host activity utilisation
3) wireless channel utilisation

21
Q

what standard, originally developed for the sendmail project and used by Unix facilitates the transmission of log entries generated by a device across an IP network to a message collector?

22
Q

Which Microsoft tool checks the baseline configuration for it’s operating systems?

A

MS Baseline Security Analyzer (MBSA). But now replaced by Microsoft Security Compliance Toolkit (SCT)

23
Q

Which Microsoft application is used for all kinds of Microsoft OS and product updates and which is used for application patches?

A

WSUS (Windows Server Update Services) for OS updates

SCCM (Systems Centre Configuration Manager)

24
Q

log entry, sending an email, or sending a text message in response to an alert are forms of what?

A

Notifications

25
What is being described below? the database of the Object IDs published by the vendor of a network device that SNMP uses to collect data about the device.
Management Information Base of SNMP
26
When capturing error rate measurements, what is actually measured?
How many frames are received where the CRC check fails
27
What can bad connections on the receive pair or dirty optical connection cause?
High Error rate/CRC failures
28
It's common to see error rates on the transport layer when what mechanism is being used?
TCP offload. (e.g. used by iSCSI)
29
Packet drops is a measurement at what layers?
Transport or Network! At Network layer Collected as a percentage of total ICMP packets sent/lost Transport layer uses an incremental counter. High packet loss is a sign of network congestion or connectivity issue at sending host.
30
Erroneous frames SENT can't be measured because hosts don't report it, what can be used as a proxy metric for it?
Error Rate