Event Management (3.3) Flashcards

1
Q

Interface Monitoring

A
  • Is the interface up or down which is one of the most important things to know. No special rights or perms and green is good red is bad.
  • Alarming or Alerting should an interface fail to report can send emails or smss
  • Short term and long term reporting

Not focused on traditional details

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

SIEM

A

Security information and Event management including security events and information

Performs security alerts on real time information

Uses Log aggregation and long term storage which usually includes advanced reporting features

Data correlation to link diverse data types

Allows for forensic analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Syslog

A

Standard for message logging for diverse systems, consolidated log.

Usually a central logging receiver integrated into the siem

You need a lot of disk space

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

SIEM Dashboard

A

Takes all info gathered in logs and shows in graphical form using graphs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

SNMP

A

Simple Network Management Protocol. Allows for a database of data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

MIB

A

Management Information Base

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

SNMP Versions

A

V1 - The original structured tabled in the clear
V2 - Data type enhancements, bulk transfers, still int he clear
V3 - The New Standard Message integrity, auth, encryption

How well did you know this?
1
Not at all
2
3
4
5
Perfectly