Network Monitoring Flashcards

1
Q

the de facto protocol for network management on TCP/IP networks

A

Simple Network Management Protocol (SNMP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

part of an SNMP system that requests and process information from managed devices; uses UDP port 162 or, with TLS, TCP port 10162.

A

SNMP manager

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

the specialized software run by the SNMP manager

A

network management station

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

the specialized software run by managed devices in an SNMP system; uses UDP port 161 or, with TLS, TCP port 10161

A

agent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

a protocol that can be adapted to accomodate various needs, like SNMP

A

extensible protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

used by SNMP to categorize the information that can be queried; inform SNMP monitors what can be monitored on a specific device

A

management information base (MIB)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

the eight core functions of an SNMP system

A

protocol data unit (PDU)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

function sent by an SNMP manager when it wants to query an agent

A

Get

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

function sent by an SNMP manager to make changes to variables

A

Set

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

function sent by an agent containing the requested information from a Get request

A

Response

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

function used by an agent to solicit information from an NMS or send information to the NMS without first being queried

A

Trap

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

SNMP utility that tells the SNMP manager to perform a series of Get commands

A

snmpwalk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

SNMP capability that sends alert notifications to techs, such as through text messages or email

A

event management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

program that queries a network interface and stores packets in a capture file on a computer, router, or dedicated piece of hardware; used where there is a suspicion of malicious network access/probing; need to collect as much data as possible, usually set in promiscuous mode or via a mirrored port on a switch

A

packet sniffer/sniffer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Cisco tool found in their routers and switches that tracks traffic flowing between specific source and destination devices

A

Netflow

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

tool that tracks the bandwidth and utilization of one or more interfaces, such as a physical port or ports, on one or more devices

A

interface monitor

17
Q

a tool that keeps track of the performance of a certain aspect of a system over time; requires detailed understanding of the low-level aspects of the system, so it’s usually tied to an operating system or application

A

performance monitor

18
Q

the particular aspect that is tracked by a performance monitor

A

counter (Perf Mon); facility (syslog)

19
Q

computers in a network that are receiving the most data

A

top listener

20
Q

network monitoring approach that is a mashup of SEM and SIM; typically only used by large enterprises; can be self-implemented or administered by a vendor

A

security information and event management (SIEM)

21
Q

process of monitor security event in real-time, often through edge devices, and saving the events to a location to be analyzed; also collects and centralizes disparately located event logs

A

security event management (SEM)

22
Q

process of SIEM where the saved log files are analyzed, either through automated or human interpreters

A

security information management (SIM)

23
Q

the process of checking for changes in various aspects of a file

A

file integrity monitoring

24
Q

vendor who is under contract to administer an SIEM system

A

managed security service provider (MSSP)