Soru

Zorluk: KolayNetwork Logging and Auditing

Match each network logging and auditing component on the left with its corresponding primary function on the right.

  • SyslogStandardized message protocol used by network devices to forward event log messages to a central server
  • NetFlowCollects IP traffic statistics and flow data to monitor network bandwidth usage
  • SNMPv3Monitors network device status using authenticated and encrypted communications
  • SIEMCentralized platform that aggregates, correlates, and analyzes security log data across the enterprise

Cevap

Syslog matches standard system event log forwarding; NetFlow matches IP traffic flow statistics collection; SNMPv3 matches secure device status monitoring with authentication and encryption; SIEM matches centralized log aggregation and security event correlation.
Each logging and monitoring technology addresses a distinct auditing requirement: Syslog forwards system event notifications; NetFlow gathers traffic flow metadata; SNMPv3 provides secure device polling and alerting; and SIEM centralizes log aggregation, correlation, and compliance auditing.

Adım Adım Çözüm

1
Identify the function of Syslog.
Syslog handles sending text-based log messages generated by system events to a central log collector.
Syslog is the standard protocol for event messaging on network equipment.
2
Identify the function of NetFlow.
NetFlow records traffic volume, IP source/destination pairs, and port metrics.
NetFlow focuses on traffic flow metadata rather than system status event logs.
3
Identify the features of SNMPv3.
SNMPv3 provides device monitoring with built-in encryption and authentication capabilities.
Version 3 addresses security weaknesses found in SNMPv1 and SNMPv2c.
4
Identify the role of a SIEM platform.
SIEM aggregates and correlates event data from across the enterprise for auditing and detection.
SIEM systems combine log management with automated correlation.

Anahtar Kavram

Network Logging and Auditing Technologies
Bu soruyu puanla