Network Logging and Monitoring Flashcards
Only routers can stop broadcast traffic. TRUE of FALSE?
False. Switches can too but not by default
What’s the name of Microsoft’s graphical utility used to capture network traffic called? In order to use it what capability does your NIC need to have?
Network Monitor
NIC needs to operate in promiscuous mode
What OSI layer does SNMP work at?
Layer 7
SNMP agents send what kind of messages about them to the what?
SNMP Trap messages to the Network Management Station (NMS)
The NMS solicits for what on an SNMP agent using what type of message?
Solicits for an Object ID (OID) using SNMP GET
In SNMP, what are SET messages used for?
configuring agents
What SNMP message gathers many types of info at once to cut down on multiple GET messages?
GET BULK
Which version of SNMP uses plain-text authentication with MD5/SHA, no encryption and uses UDP by default?
SNMPv2c
what utility allows you to log events based on 8 (0-7) severity levels?
syslog
By default, what two places do all system messages and debug output generated by the IOS go out of?
Console Port and RAM buffer
List the top 4 (by urgency) severity states by number and description
0 - Emergency (lowest level)
1 - Alert
2 - Critical
3 - Error
List the lower 4 severity states by number and description
4 - Warning
5 - Notification
6 - Information
7 - Debugging
If you configure severity level 03, what levels of severity will you be notified on?
0 through 3
SIEM provides what?
real-time analysis of security alerts generated by network hardware applications
Regarding security event management:
What term is used to describe the long-term storage, analysis and reporting on log data?
What term is used to describe the management of real-time monitoring and correlation of events?
Security Information Management (SIM)
Security Event Management
(SIM, SEM and SIEM are often used interchangeably)