SIEM Flashcards

1
Q

Elastic Search Components

A

Logstash
Kibana
Beats

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is logstash?

A

Ingest pipeline that enriches the data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Kibana

A

Visualization tool

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are beats?

A

Lightweight single purpose data shippers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is Splunk?

A

Used for collecting, normalizing, aggregating, and analyzing a lot of data.
Maybe in real time.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the types of forwarders in Splunk?

A

Universal forwarder
Heavy forwarder
Light forwarder

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a universal forwarder?

A

Does not even parse data, just literally forwards it to the next thing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a heavy forwarder?

A

Combination of a universal forwarder and an indexer. FOrwards, indexes, and searches.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a light forwarder?

A

Old

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is an Indexer in Splunk?

A

Index incoming data and searches it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a splunk dashboard

A

Collections of search queries. Can be updated in real time.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a splunk app?

A

Prepackaged frontend solutions. lots of dashboards.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is netflow?

A

A feature that allows network administrators to monitor traffic.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

what is a netflow exporter?

A

Sends data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is a netflow collector?

A

Receives netflow data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a netflow analyzer?

A

Processes records collected by a flow collector.

17
Q

When is a flow complete?

A

The flow is inactive
The flow is active but timed out
The flow is terminated by TCP

18
Q

What is nprobe?

A

A flow exporter

19
Q

Which Splunk component distributes searches, but rarely has indexes of its own

A

Search head