SECFND 13: Security Data Collection Flashcards

1
Q

Transaction Data

A

Operations that occur during network sessions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Epoch time

A

of seconds since 1/1/70

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

TCP_Hit (Proxy)

A

Cached in proxy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

HTTP 200 Series

A

Successful

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

HTTP 300 Series

A

Redirected

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

HTTP 400 Series

A

Client side errors (403 forbidden, 401 Unauthorized)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

HTTP 400 Series

A

Server side errors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

HTTP Get

A

Retrieval and simple searches

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

HTTP Post

A

Submit Data-query

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

HTTP Put

A

Upload files

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

HTTP Head

A

Retrieve Metadata

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

HTTP Delete

A

Remove resource

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

HTTP Trace

A

Application layer trace of route

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

HTTP Option

A

Request available methods

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

HTTP Connect

A

Tunnel SSL Connection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

HTTP Propfind

A

Retrieve properties of an object

17
Q

IPFIX

A

Latest version of netflow

18
Q

A flow

A

unidirectional series of packets between a source and a destination. 5 tuple is constant in a flow

19
Q

Flow stitching

A

Combines unidirectional flow records into once record

20
Q

NAT Stitching

A

Combine internal and external NAT info into one record

21
Q

Netflow provides…

A

An audit trail