Chapter_2_SilentDefense Initial Configuration and Concepts Flashcards
1
Q
What are the 3 types of sensors?
A
Monitoring Sensor: Connects to the network and listens to live traffic ICS Patrol Sensor: Makes active requests using NMAP scans for information PCAP Replay Sensor: Prerecorded traffic vs live traffic analysis (Bundled Config)
2
Q
Describe a Bundled Configuration:
A
An installation of SilentDefense in which the Command Center and a Monitoring Sensor are installed together in one server.
3
Q
What port is used by default for communication between the command centerand monitoring sensors?
A
9999
4
Q
What port is used by default for communication between a Command Centerand an ICS Patrol Sensor:
A
9001
5
Q
List the “Built-In Modules”:
A
MitM Malformed Packet Detection Port scan Frequent Event Aggregation Visual Analytics Event Logging