Network Analysis Flashcards

1
Q

What is a protocol?

A

A set of rules that defines the messages sent, and the actions taken on those messages.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What do protocols define?

A

Format
Order
Actions taken

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Networking Layers

A

Application
Transport
Network
Link
Physical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What level of networks do switches operate on?

A

Operate at the physical and link layers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Routers

A

Operate at the physical, link, and network layers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Firewalls

A

Deny bad and allow ok traffic.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

IDS/IPS

A

Alerting and prevention of malicious network activity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Gateway

A

The IP that will forward your datagram

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Routing table

A

Where do I send the next hop?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

ARP Table

A

Address Resolution Protocol
Maps IP addresses to MAC addresses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

CAM Table

A

Maps MAC addresses to physical ports
Used on switches

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

NAT

A

Network -> Address translation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What tool allows us to do packet captures forom the CLI?

A

tcpdump

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the common ports?

A

0-1023

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the registered ports?

A

1024-49151W

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the dynamic ports?

A

49152-65535

17
Q

FTP port

A

21

18
Q

SSH port

A

22

19
Q

Telnet port

A

23

20
Q

HTTP port

A

80

21
Q

HTTPS port

A

443

22
Q

SMB port

A

445

23
Q

DNS port

A

53

24
Q

DHCP port

A

67/68

25
Q

Display Filter

A

Changes whenever you display already captured packets

26
Q

Capture filter

A

Only captures a given subset of packets.

27
Q

What network devices strip link layer headers and forward network layer headers?

A

Routers

28
Q

Which of the 5 layers in networking facilitates process to process data transfer?

A

Transport

29
Q

What is an endpoint in wireshark?

A

A unique IP Adrress/port combo.