Network Logging and Monitoring Flashcards

1
Q

Only routers can stop broadcast traffic. TRUE of FALSE?

A

False. Switches can too but not by default

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What’s the name of Microsoft’s graphical utility used to capture network traffic called? In order to use it what capability does your NIC need to have?

A

Network Monitor

NIC needs to operate in promiscuous mode

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What OSI layer does SNMP work at?

A

Layer 7

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

SNMP agents send what kind of messages about them to the what?

A

SNMP Trap messages to the Network Management Station (NMS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

The NMS solicits for what on an SNMP agent using what type of message?

A

Solicits for an Object ID (OID) using SNMP GET

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

In SNMP, what are SET messages used for?

A

configuring agents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What SNMP message gathers many types of info at once to cut down on multiple GET messages?

A

GET BULK

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which version of SNMP uses plain-text authentication with MD5/SHA, no encryption and uses UDP by default?

A

SNMPv2c

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what utility allows you to log events based on 8 (0-7) severity levels?

A

syslog

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

By default, what two places do all system messages and debug output generated by the IOS go out of?

A

Console Port and RAM buffer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

List the top 4 (by urgency) severity states by number and description

A

0 - Emergency (lowest level)
1 - Alert
2 - Critical
3 - Error

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

List the lower 4 severity states by number and description

A

4 - Warning
5 - Notification
6 - Information
7 - Debugging

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

If you configure severity level 03, what levels of severity will you be notified on?

A

0 through 3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

SIEM provides what?

A

real-time analysis of security alerts generated by network hardware applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Regarding security event management:
What term is used to describe the long-term storage, analysis and reporting on log data?
What term is used to describe the management of real-time monitoring and correlation of events?

A

Security Information Management (SIM)
Security Event Management
(SIM, SEM and SIEM are often used interchangeably)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What software monitoring products are used exclusively by security network admins?

A

SIEM (security information and event management) software products

17
Q

When I a SIEM alert is triggered and notification generated, who typically addresses the problem?

A

The Security Operations Centre

18
Q

List the 3 types of system event logs?

A

1) Application
2) Security
3) System

19
Q

Windows Server 2008 offered what optional monitoring and optimization tool?

A

System Centre Operations Manager 2010

20
Q

Utilization cover what 3 things?

A

1) Wired/Wireless Bandwidth utilisation
2) Server/Host activity utilisation
3) wireless channel utilisation

21
Q

what standard, originally developed for the sendmail project and used by Unix facilitates the transmission of log entries generated by a device across an IP network to a message collector?

A

Syslog

22
Q

Which Microsoft tool checks the baseline configuration for it’s operating systems?

A

MS Baseline Security Analyzer (MBSA). But now replaced by Microsoft Security Compliance Toolkit (SCT)

23
Q

Which Microsoft application is used for all kinds of Microsoft OS and product updates and which is used for application patches?

A

WSUS (Windows Server Update Services) for OS updates

SCCM (Systems Centre Configuration Manager)

24
Q

log entry, sending an email, or sending a text message in response to an alert are forms of what?

A

Notifications

25
Q

What is being described below?
the database of the Object IDs published by the vendor of a network device that SNMP uses to collect data about the device.

A

Management Information Base of SNMP

26
Q

When capturing error rate measurements, what is actually measured?

A

How many frames are received where the CRC check fails

27
Q

What can bad connections on the receive pair or dirty optical connection cause?

A

High Error rate/CRC failures

28
Q

It’s common to see error rates on the transport layer when what mechanism is being used?

A

TCP offload. (e.g. used by iSCSI)

29
Q

Packet drops is a measurement at what layers?

A

Transport or Network!
At Network layer Collected as a percentage of total ICMP packets sent/lost
Transport layer uses an incremental counter.
High packet loss is a sign of network congestion or connectivity issue at sending host.

30
Q

Erroneous frames SENT can’t be measured because hosts don’t report it, what can be used as a proxy metric for it?

A

Error Rate