Dip Configuration Flashcards

1
Q

The ____ consists of multiple servers configured as a Collector to store data and Sensors to supply data to the Collector.

A

DIP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Operators at the Mission Partner site could directly access the DIP while conducting mission operations on-site.

A

On-Site DIP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

The DIP collector resides on the remote site with the Mission Partner.

A

Remote Operations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

The DIP ______ main purpose is to capture MPNET traffic.

A

Sensor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

This program saves raw pcaps to disks.

A

Arkime (Moloch)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

This program analyzes network traffic against specific signature sets.

A

Suricata

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

This program can be a signature-based NIDS as well, but gains its power through the use of its scripting language.

A

Bro (Zeek)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

A _____ _______ takes everything it sees on a port or ports you specify, then mirrors it out of another port.

A

Mirrored Port

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q
  1. No disconnection needed for implementation
  2. Requires no hardware
  3. Can capture all traffic from a switch w/many links
A

Mirrored Port Pros

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q
  1. Requires an open port on MPNET switch
  2. Requires MPNET support and configuration changes to equipment
  3. May drop packets on a saturated link
A

Mirrored Port Cons

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

A _____ is typically a dedicated hardware device providing access data flowing across a network and, ideally, will not affect the speed of the data traversing it.

A

TAP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q
  1. Virtually undetectable
  2. Does not require Mission Partner Device configuration to install
  3. Does not require processing power of device to mirror traffic
A

TAP Pros

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q
  1. Disconnects the network when hardware is installed
  2. Only captures traffic sent through one link
  3. Requires purchase of equipment
A

TAP Cons

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Is a passive, open-source network traffic analyzer.

A

Bro (Zeek)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

A real-time Network Intrusion Detection System (NIDS).

A

Suricata

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are Suricata’s three operating modes?

A
  1. Sniffer mode
  2. Packet logger mode
  3. Intrusion Detection Mode
17
Q

Automatically deletes oldest data to make room for new pcap when 95% of disk space capacity is reached.

A

Rolling packet capture

18
Q

The sensor uses ________ to ship Bro logs and Suricata alerts to the Collector.

A

FileBeat

19
Q

The ____________ is a server that provides a virtual, boundary protected, environment in which to deploy capabilities.

A

Collector

20
Q

________ is an open source, server-side data processing pipeline ingesting data from a multitude of sources simultaneously, transforming it and then sending it to ElasticSearch. (Parses and normalizes data for ES)

A

Logstash

21
Q

___________ _________ - Provides indexing for logs (Bro and Suricata)

A

Elastic Search

22
Q

Lets you visualize your ElasticSearch data and navigate the ELK stack.

A

Kibana

23
Q

________ aggregates data from the host, providing significant visibility into the behavior of a host. (installed at kernel level)

A

Endgame

24
Q

Will serve as a DNS server for the DIP, allowing operators to query hostnames instead of IP addresses.

A

pfSense