Syslog, SNMP, and Netflow Flashcards

(50 cards)

1
Q

What is the default port used by Syslog?
a) TCP 514
b) UDP 514
c) TCP 162
d) UDP 162

A

Answer: b) UDP 514

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which Syslog severity level indicates a critical condition that requires immediate attention?
a) 0 (Emergency)
b) 2 (Critical)
c) 3 (Error)
d) 5 (Notice)

A

Answer: b) 2 (Critical)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the highest severity level in Syslog?
a) 0 (Emergency)
b) 1 (Alert)
c) 7 (Debug)
d) 6 (Informational)

A

Answer: a) 0 (Emergency)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which command enables Syslog logging on a Cisco router?
a) logging on
b) logging host <IP>
c) logging trap <level>
d) All of the above
Answer: d) All of the above</level></IP>

A

Answer: d) All of the above

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does Syslog facility level 16 (local0) typically represent?
a) Kernel messages
b) User-level messages
c) Locally defined logs
d) Mail system logs

A

Answer: c) Locally defined logs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which Syslog severity level is used for normal but significant events?
a) 5 (Notice)
b) 6 (Informational)
c) 4 (Warning)
d) 7 (Debug)

A

Answer: a) 5 (Notice)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the purpose of the logging synchronous command?
a) Synchronizes logs across multiple devices
b) Prevents console messages from interrupting commands
c) Enables secure Syslog with TLS
d) Sets Syslog timestamps

A

Answer: b) Prevents console messages from interrupting commands

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which command configures a router to send Syslog messages to a server at 192.168.1.100?
a) logging 192.168.1.100
b) logging host 192.168.1.100
c) syslog server 192.168.1.100
d) log-server 192.168.1.100

A

Answer: b) logging host 192.168.1.100

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which Syslog severity level is used for debug-level messages?
a) 7
b) 6
c) 5
d) 4

A

Answer: a) 7

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the purpose of the service timestamps log datetime command?
a) Adds timestamps to Syslog messages
b) Synchronizes time with an NTP server
c) Enables logging of date and time for debug messages
d) Both a and c

A

Answer: d) Both a and c

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which of the following is NOT a valid Syslog facility?
a) auth
b) cron
c) ospf
d) syslog

A

Answer: c) ospf

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What happens if a Syslog server is unreachable?
a) Logs are stored locally in a buffer
b) Logs are discarded
c) The router stops functioning
d) Logs are sent via email

A

Answer: b) Logs are discarded (unless buffered)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which command limits Syslog messages to only level 4 (Warnings) and higher?
a) logging trap 4
b) logging level 4
c) logging severity 4
d) logging filter 4

A

Answer: a) logging trap 4

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which protocol does Syslog typically use for transport?
a) TCP
b) UDP
c) Both TCP and UDP
d) ICMP

A

Answer: b) UDP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the purpose of the logging buffered command?
a) Stores logs in NVRAM
b) Sends logs to a buffer in RAM
c) Forwards logs to a Syslog server
d) Encrypts log messages

A

Answer: b) Sends logs to a buffer in RAM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the default port for SNMP traps?
a) UDP 161
b) UDP 162
c) TCP 161
d) TCP 162

A

Answer: b) UDP 162

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Which SNMP version provides encryption and authentication?
a) SNMPv1
b) SNMPv2c
c) SNMPv3
d) All of the above

A

Answer: c) SNMPv3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is an SNMP OID?
a) A unique identifier for managed devices
b) A numeric identifier for a specific variable in the MIB
c) A password for SNMP access
d) A type of SNMP trap

A

Answer: b) A numeric identifier for a specific variable in the MIB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Which SNMP operation allows an agent to send unsolicited alerts?
a) GET
b) SET
c) TRAP
d) WALK

A

Answer: c) TRAP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is the community string in SNMPv2c used for?
a) Encryption
b) Authentication
c) Compression
d) Error checking

A

Answer: b) Authentication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Which command enables SNMPv2c with a read-only community string “public”?
a) snmp-server community public ro
b) snmp-server public ro
c) snmp enable community public
d) snmp ro community public

A

Answer: a) snmp-server community public ro

22
Q

Which MIB contains system information such as device uptime?
a) IF-MIB
b) IP-MIB
c) SNMPv2-MIB
d) CISCO-SMI

A

Answer: c) SNMPv2-MIB

23
Q

What is the purpose of the snmp-server host command?
a) Configures an SNMP manager IP
b) Defines where traps/informs are sent
c) Enables SNMP on an interface
d) Sets the SNMP read-write community

A

Answer: b) Defines where traps/informs are sent

24
Q

Which SNMP version uses a community string for authentication?
a) SNMPv1
b) SNMPv2c
c) SNMPv3
d) Both a and b

A

Answer: d) Both a and b

25
What is the difference between SNMP traps and informs? a) Traps are unacknowledged, informs are acknowledged b) Informs use TCP, traps use UDP c) Traps are secure, informs are not d) Informs are only in SNMPv1
Answer: a) Traps are unacknowledged, informs are acknowledged
26
Which SNMP operation modifies MIB variables? a) GET b) GETNEXT c) SET d) TRAP
Answer: c) SET
27
What is the purpose of the snmp-server enable traps command? a) Enables all SNMP traps b) Disables all SNMP traps c) Enables specific SNMP traps d) Configures SNMP polling
Answer: c) Enables specific SNMP traps
28
Which SNMP security model provides message integrity and encryption? a) NoAuthNoPriv b) AuthNoPriv c) AuthPriv d) Community-based
Answer: c) AuthPriv
29
What is the default SNMP port for polling? a) UDP 161 b) UDP 162 c) TCP 161 d) TCP 162
Answer: a) UDP 161
30
Which command configures an SNMPv3 user with authentication and encryption? a) snmp-server user admin auth sha password priv aes 256 key b) snmp-server user admin auth md5 password priv des key c) snmpv3 user admin auth sha password priv aes 128 key d) snmp enable user admin auth sha password priv aes key
Answer: b) snmp-server user admin auth md5 password priv des key
31
What is the purpose of the snmp-server location command? a) Sets the device’s physical location in the MIB b) Configures SNMP server IP c) Enables SNMP on a specific interface d) Defines SNMP trap destinations
Answer: a) Sets the device’s physical location in the MIB
32
Which SNMP PDU type is used for a response to a GET request? a) GET-RESPONSE b) RESPONSE c) REPLY d) GET-REPLY
Answer: a) GET-RESPONSE
33
What does the snmp-server contact command do? a) Sets the administrator contact information in the MIB b) Configures SNMP trap contacts c) Enables SNMP notifications d) Disables SNMP polling
Answer: a) Sets the administrator contact information in the MIB
34
Which SNMP version is the most secure? a) SNMPv1 b) SNMPv2c c) SNMPv3 d) All are equally secure
Answer: c) SNMPv3
35
What is the purpose of the snmp-server engineID command? a) Configures a unique identifier for the SNMP engine b) Sets the SNMP server IP c) Enables SNMP traps d) Disables SNMP polling
Answer: a) Configures a unique identifier for the SNMP engine
36
What is the primary purpose of NetFlow? a) Network monitoring and traffic analysis b) Encrypting network traffic c) Configuring VLANs d) Managing SNMP traps
Answer: a) Network monitoring and traffic analysis
37
Which protocol does NetFlow typically use for exporting data? a) TCP b) UDP c) SCTP d) ICMP
Answer: b) UDP
38
What is a NetFlow "flow"? a) A unidirectional sequence of packets with common attributes b) A bidirectional communication session c) A routing table update d) An SNMP trap message
Answer: a) A unidirectional sequence of packets with common attributes
39
Which command enables NetFlow on a Cisco router interface? a) ip flow ingress b) ip flow-export destination c) ip flow monitor d) netflow enable
Answer: a) ip flow ingress
40
What is the default NetFlow export version on Cisco devices? a) Version 1 b) Version 5 c) Version 9 d) Version 10 (IPFIX)
Answer: b) Version 5
41
Which NetFlow version supports flexible, template-based data export? a) Version 5 b) Version 7 c) Version 9 d) Version 3
Answer: c) Version 9
42
What is the purpose of the ip flow-export destination command? a) Configures where NetFlow data is sent b) Enables NetFlow on an interface c) Defines flow timeout values d) Sets the NetFlow version
Answer: a) Configures where NetFlow data is sent
43
Which of the following is NOT a key field in a NetFlow record? a) Source IP b) Destination IP c) TCP Window Size d) Next-hop router
Answer: c) TCP Window Size
44
What is the purpose of the ip flow-cache timeout command? a) Defines how long flows are stored before export b) Sets the NetFlow export interval c) Configures SNMP polling for NetFlow d) Disables NetFlow on an interface
Answer: a) Defines how long flows are stored before export
45
Which command displays active NetFlow flows on a router? a) show ip flow b) show flow cache c) show ip cache flow d) show netflow stats
Answer: c) show ip cache flow
46
What is IPFIX? a) A proprietary Cisco version of NetFlow b) An IETF standard based on NetFlow v9 c) An SNMP-based flow monitoring protocol d) A Syslog extension for flow data
Answer: b) An IETF standard based on NetFlow v9
47
Which transport layer protocol is monitored by NetFlow? a) Only TCP b) Only UDP c) TCP, UDP, and others d) Only ICMP
Answer: c) TCP, UDP, and others
48
What is the purpose of the ip flow-export source command? a) Sets the source interface for NetFlow exports b) Configures the NetFlow collector IP c) Enables flow monitoring on an interface d) Disables NetFlow sampling
Answer: a) Sets the source interface for NetFlow exports
49
Which NetFlow component collects and analyzes flow data? a) NetFlow exporter b) NetFlow collector c) NetFlow monitor d) NetFlow aggregator
Answer: b) NetFlow collector
50
What is the purpose of NetFlow sampling? a) To reduce CPU usage by analyzing only a subset of packets b) To encrypt NetFlow data c) To increase the number of exported flows d) To disable NetFlow on low-speed interfaces
Answer: a) To reduce CPU usage by analyzing only a subset of packets