3.3 Explain common scanning, monitoring and patching processes and summarize their expected outputs. Flashcards

1
Q

Log management

A

Very diverse log sources
Usually sent via syslog
Massive storage requirement
Data rollup becomes important

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Data graphing

A

Many different data sources
Usually managed through a SIEM
Graphing can require extensive resource utilization
Can use built-in graphs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Port scanning

A
Nmap
Port scan
Operating system scan
Service scan
Additional scripts
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Nmap - Network mapper

A

Find and learn more about network devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Port scan

A

Find devices and identify open ports

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Operating system scan

A

Discover the OS without logging in to a device

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Service scan

A

What service is available on a device? Name, version, details

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Additional scripts

A

Nmap Scripting Engine (NSE) - extend capabilities, vulnerability scans

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Vulnerability scanning

A
Usually minimally invasive
Run a vulnerability scanner
Identify systems and security devices
Test from the outside and inside
Gather as much information as possible
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Vulnerability scan results

A

Lack of security controls
Misconfigurations
Real vulnerabilities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Patch management

A

Incredibly important
Service packs - All at once
Monthly updates
Emergency out-of-band updates

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Protocol analyzers

A

Solve complex application issues
Gathers packets on the network
View traffic patterns
Large scale storage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Interface monitoring

A

Up or down
Alarming and alerting
Short-term and long-term reporting
Not focused on additional details

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

SIEM

A
Security Information and Event Management
Security alerts
Log aggregation and long-term storage
Data correlation
Forensic analysis
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

SNMP

A

Simple Network Management Protocol

Access should be very limited

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

SNMP v1 - The original

A

Structured tables, in-the-clear

17
Q

SNMP v2 – A good step ahead

A

Data type enhancements, bulk transfers, still in-the-clear

18
Q

SNMP v3 - The new standard

A

Message integrity, authentication, encryption

19
Q

Syslog

A

Standard for message logging
Usually a central logging receiver
You’re going to need a lot of disk space

20
Q

Monitoring the interface

A

Often your first sign of trouble
Can sometimes indicate a bigger issue
View in the operating system
Monitor with SNMP

21
Q

Interface monitoring

A

Link status - link up, or link down?
Error rate - Problems with the signal - CRC error, runt, giant
Utilization
Discards, packet drops
Interface resets
Speed and duplex - These should match on both sides