Soru

Zorluk: OrtaCommon Ports and Protocols

A network operations team is configuring intermediate Access Control Lists (ACLs) to allow perimeter routers to send standardized event logs to a central SIEM server located in the management VLAN. If the infrastructure relies on standard unencrypted log forwarding, which transport protocol and destination port combination must be allowed through the ACLs?

  1. UDP port 514Cevap
  2. B
    TCP port 514
  3. C
    UDP port 161
  4. D
    TCP port 6514

Cevap

UDP port 514 is the correct transport protocol and destination port for standard unencrypted Syslog forwarding.
Standard unencrypted Syslog log forwarding uses User Datagram Protocol (UDP) on port 514 to send event notifications to a log collector or SIEM server without incurring TCP connection setup overhead.

Adım Adım Çözüm

1
Identify the standard protocol utilized by routers and switches to send system notifications and logs to a central collector.
The network protocol used for system log aggregation is Syslog.
Syslog is the defined RFC standard for transmitting event messages across IP networks.
2
Determine the transport layer protocol and destination port number for traditional unencrypted Syslog.
Unencrypted Syslog operates over User Datagram Protocol (UDP) on destination port 514.
UDP is selected for standard logging to ensure lightweight transmission without requiring connection handshakes or acknowledgement overhead.

Anahtar Kavram

Syslog transport protocol and port assignments
Tahmini Süre:1m 0s
Bu soruyu puanla