Chapter_12_Forwarding Flashcards

1
Q

What can be forwarded via email?

A

Only Alerts can be forwarded via email

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How can other information be forwarded?

A

Other information (as well as alerts) may be forwarded via Syslog

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Why might you configure forwarding conditions?

A

So Alerts get sent not only to the SEIM and SOC, but also to the Operations center managing the OT device

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What format are Syslog messages sent using? Can the message be edited? If so, how?

A

CEF, LEEF and JSON(Splunk) are the standard formats, but they can be edited by adding any available tag from the SilentDefense properties database.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly