4A. Configure Log Review and SIEM tools obj 3.1 Flashcards

1
Q

SIEM use cases should capture the five Ws…

A

1) When the event started (and ended)
2) who was involved
3) what happened
4) where it happened (e.g., which hosts, network, file systems, etc)
5) where it originated (e.g., outside IP addresses over VPN connection)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Agent-based data (SIEM)

A

agent service installed on each host. As events occur on the host, logging data is filtered, aggregated, and normalised at the host and then sent to the SIEM for analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Listener/collector data (SIEM)

A

Hosts configured to push updates to the SIEM server using protocol (e.g., syslog, SNMP). Management server parses and normalises each log/monitoring source

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Sensor (SIEM)

A

SIEM collects traffic flow data from sniffers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

TAP vs SPAN

A

SPAN copies traffic passing through one or more ports and sends it to another port for analysis. It is useful for monitoring traffic on individual switches or specific VLANs or ports. A TAP is a physical device that sits between two network devices and monitors all traffic that passes through, regardless of the type of traffic or network devices involved.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

syslog

A

A protocol enabling different appliances and software applications to transmit logs or event records to a central server.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly