(3) Analyzing Network Events Flashcards

1
Q

What is router based monitoring?

A

Router based monitoring is where a network team uses data provided by routers to give insight into what traffic is flowing through the network.

This type of traffic is useful because it can help catch bad traffic.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What type of technologies are Netflow, sFlow, and J-Flow

A

Netflow, sFlow, and J-Flow are router based network monitoring technologies.

They record traffic that flows through network device interfaces and then send the data to flow collectors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How does Simple Network Monitoring Protocol (SNMP) help with network related events?

A

SNMP is often used to get information from routers and network devices overall to provide more information about devices and what they are up to.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Explain how flows can be used proactively and reactively?

A

Network flows can be used proactively in that they can be used to keep an eye on network health and traffic, and reactively to look for unexpected traffic or for changes that aren’t expected in bandwidth usage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What other powerful network tool can be used to help make sense of network flows?

A

A Security Information and Event Management (SIEM) device can be used with network flow data to analyze what is going on on a network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is active monitoring?

A

Active monitoring reaches out and collects data from remote systems. They often are the data gathering apparatus themselves (although they can also still send data to collectors)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What types of data do active monitoring systems look for?

A

Active monitoring systems often look for data about availability, packet delay or loss, bandwidth and others

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are two examples of active monitoring in action?

A

Two examples of active monitoring include:

Pings: Internet Control Message Protocol (ICMP) can be used to reach out to remote systems. It only provides basic info though

iPerf: A tool that is very useful for baselining and bandwidth testing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

In terms of network capacity, what do we need to be aware of when using active monitoring technologies?

A

When using active monitoring technologies, we need to be aware that the monitoring checks can also competing with legitimate traffic, so we need to be careful with how much monitoring happens, especially during peak times.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is passive monitoring?

A

Passive monitoring is monitoring that does not add any additional traffic to the network.

Oftentimes a device such as a network tap is placed in the line of the network flow so that traffic can be captured after it passes through.

Traffic is pushed to a collector where it is analyzed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly