Chapter 2: Monitoring and Diagnosing Networks Flashcards

1
Q

Sniffer

A

A passive network monitor that listens to the signaling and traffic on the network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Promiscuous Mode

A

A NIC in promiscuous mode looks at any packet it sees on the network even if it isn’t addressed to that NIC.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Application Log

A

Where applications log various events such as errors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Security Log

A

Records events related to resource use, logon attempts, file use, etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

var/log/faillog

A

Linux log file containing failed user logins

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

/var/log/apport.log

A

Linux log file that records application crashes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Windows tool for viewing log files

A

Event Viewer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Services

A

Programs that run when the operating system boots, often running in the background.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

File and Print Servers are primarily vulnerable to _______.

A

DoS attacks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which service should you disable on a network with PC-based systems?

A

NetBIOS, ports 135, 137, 138, 139

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which port should you make sure is closed on Unix systems?

A

Remote Procedure Call (RPC), port 111

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Performance Monitor

A

Can be used to examine activity on any counter.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Service Pack Patch

A

A periodic update that corrects problems in one version of a product

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Update Patch

A

Code fixes for products that are provided to individual customers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

File Allocation Table (FAT)

A

-Microsoft’s first file system, very unsecure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Two types of FAT privileges

A

1) Share-level

2) User-level

17
Q

New Technology Filesystem (NTFS)

A

-Introduced with Windows NT to address security problems

18
Q

Command to see version of NTFS

A

fsutil fsinfo ntfsinfo C:

19
Q

802.1X

A

Defines port-based security for wireless network access control

20
Q

EAPOL

A
  • EAP over LAN

- Another name for 802.1X

21
Q

How to disable a port?

A

Disable the service and block the port with a firewall

22
Q

Security Audit

A

A scheduled, in-depth check of security

23
Q

Alarms

A
  • Indications of ongoing current problems

- Address them now

24
Q

Alerts

A

-Issues you should pay attention to, but will not bring the system down now

25
Q

Trends

A

Trends in threats

26
Q

OS Hardening

A

Making the OS as secure as possible before adding antivirus, firewall, etc.

27
Q

Entrapment

A

Law enforcement encourages a person to commit a crime when the criminal expresses desire not to.

28
Q

Enticement

A

Luring someone in to commit a crime