Section 4 Flashcards

1
Q

What do system logs track?

A

System shut down and driver failure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What do security logs track?

A

Successful and unsuccessful log on attempts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What do application logs track?

A

OS and third party app events

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Where do you look for the logs?

A

/var/logs and event viewer and SYSLOG

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the BEST way to look at logs?

A

SYSLOG server

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the 3 versions of SYSLOG in order from oldest to newest?

A

SYSLOG, RSYSLOG (Linux), SYSLOG-NG (Linux)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is netflow for?

A

Created by Cisco. Collects IP network traffic. It gives a summary of how traffic is flowing in or out of the network. It is not a packet capture tool.

It gives information such as who is using the most bandwidth and why is traffic spiking at certain times.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is sflow short for and what is its purpose?

A

Sampled Flow; its an open source version of netflow. It exports a samples of network flows.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is Internet Protocol Flow Information Export (IPFix)?

A

It’s essentially a standardized system that tracks information for billing/accounting systems. Phone companies use this to track your minutes and data usage in order to bill you based on your usage.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is Metadata?

A

It’s analytical data about data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is journalctl used for?

A

Linux command line to query and display logs from journald which is the systemd logging service on linux.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is nxlog?

A

Cross-platform, open source. Very similar to RSYSLOG, and SYSLOG-NG, except that it can work on Windows.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly