Securing your Network Week 2 Flashcards

(10 cards)

1
Q

Which Wireshark feature allows you to selectively capture network traffic based on predefined criteria before it is captured?

A

Capture Filters

Capture filters in Wireshark enable the selective capturing of network traffic based on predefined criteria.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

The NOC team primarily interacts with end clients, while the help desk manages enterprise-level IT communications.

A

False

The NOC is responsible for managing enterprise-level IT communications, while the help desk typically interacts with end clients, providing user support and assistance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What key statistical categories does Wireshark Statistics encompass?

A

Conversations
Protocol Hierarchy
Capture File Properties
Endpoints

Wireshark Statistics includes categories like conversations, capture file properties, protocol hierarchy, and Endpoints, providing insights into captured packets.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Shallow Packet Inspection (SPI) primarily examines the content within data packets rather than their headers.

A

False

Shallow Packet Inspection (SPI) primarily examines the packet headers for routing information, not the content within the data packets.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

SNMPv3 added View, Groups, and Users to enhance its security features.

A

True

SNMPv3 introduced security enhancements like encryption and authentication, along with features like View, Groups, and Users.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Zeek generates logs categorized based on network activity or protocols such as HTTP, DNS, and SSL.

A

True

Zeek creates structured logs categorized by network activity and protocol types, which helps with organized analysis and effective monitoring of network traffic, aiding in identifying anomalies or suspicious activities within the network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the primary purpose of SNMP sniffing?

A

Unauthorized interception and analysis of SNMP traffic.

SNMP sniffing involves intercepting and analyzing SNMP traffic, which can pose security risks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the primary purpose of NetFlow?

A

To monitor network performance and optimize resource allocation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the primary function of tcpdump in network analysis?

A

Capturing network traffic.

The primary function of tcpdump is to capture and analyze network traffic in real-time or offline by utilizing command-line interfaces.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

NetworkMiner is primarily designed for deeper packet analysis than Wireshark.

A

False

NetworkMiner is not primarily designed for in-depth packet analysis. Its primary function is to simplify the extraction of files from captured traffic.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly