Event Management Flashcards

1
Q

Interface monitoring

A
  • Up or down
    • The most important statistic
    • No special rights or permissions required
    • Green is good, red is bad
  • Alarming and alerting
    • Notification should an interface fail to report
    • Email, SMS
  • Short-term and long-term reporting
    • View availability over time
  • Not focused on additional details
    • Additional monitoring may require SNMP
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

SIEM

A
  • Security Information and Event Management
    • Security events and information
  • Security alerts
    • Real-time information
  • Log aggregation and long-term storage
    • Usually includes advanced reporting features
  • Data correlation
    • Link diverse data types
  • Forensic analysis
    • Gather details after an event
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

SNMP

A

• Simple Network Management Protocol
• A database of data (MIB) - Management Information
Base

  • SNMP v1 - The original
    • Structured tables, in-the-clear

• SNMP v2 – A good step ahead
• Data type enhancements, bulk transfers, still in-the-
clear

  • SNMP v3 - The new standard
    • Message integrity, authentication, encryption
  • SNMP information can be very detailed
    • Access should be very limited
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Syslog

A
  • Standard for message logging
    • Diverse systems, consolidated log
  • Usually a central logging receiver
    • Integrated into the SIEM

• You’re going to need a lot of disk space

How well did you know this?
1
Not at all
2
3
4
5
Perfectly