Module 27 Working with Network Security Data Flashcards

1
Q

What are the core elements for ELK

A

Elasticsearch, Logstash, Kibana and Beats

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is Kibana

A

Provides a graphical interface to data that is compiled by Elasticsearch

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is beats

A

Series of software plugins that send diff types of data to the elasticsearch data stores

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is logstash

A

Enables collection of network data into data indexes that can be searched by elasticsearch

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is Elasticsearch

A

An open-core platform for searching and analyzing an org data in near real time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is ELK

A

To reduce Data, ELK identifies the volume of network data, shrinks it down, only the relevant stuff

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is data normalizaiton?

A

Process of combining data from a number of sources into a common format.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Why is data archiving important?

A

Retaining NSM data is not feasbile, Sguil alert data can be retained for 30 days.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly