Soru

Zorluk: ZorNetwork Logging and Auditing

A network security administrator is configuring centralized event collection and device monitoring across enterprise infrastructure. Match each network logging, monitoring, or auditing mechanism on the left with its defining operational characteristic or security control capability on the right.

  • Syslog Severity Level 2Indicates critical device conditions requiring immediate action, such as a primary link failure or hardware component loss.
  • SNMPv3 authNoPriv ModeProvides message integrity and identity verification using HMAC-SHA/MD5 hashes, but leaves packet payloads unencrypted.
  • NetFlow / IPFIX TelemetryExports traffic flow metadata (IP addresses, ports, and byte counts) for bandwidth and security auditing without full payload capture.
  • SIEM Correlation EngineIngests time-synchronized event logs across heterogeneous network hosts to detect complex multi-system attack patterns.

Cevap

Syslog Severity Level 2 matches Critical condition alerts; SNMPv3 authNoPriv Mode matches authenticated but unencrypted SNMP traffic; NetFlow / IPFIX Telemetry matches flow metadata export without full payload capture; SIEM Correlation Engine matches centralized time-correlated event log analysis across multiple network systems.
Each concept is matched to its exact operational role in enterprise network operations: Syslog Level 2 identifies critical emergency alerts; SNMPv3 authNoPriv secures log/management requests via authentication hashes without packet encryption; NetFlow/IPFIX provides high-level session flow statistics for audit analysis; and a SIEM engine correlates centralized log streams across disparate infrastructure devices.

Adım Adım Çözüm

1
Analyze standard Syslog severity numerical levels.
Identify that Syslog severity levels range from 0 (Emergency) to 7 (Debug). Severity Level 2 represents Critical conditions requiring immediate attention (e.g., loss of primary network link).
Correctly categorizing Syslog severity levels ensures proper event notification filtering in enterprise log management.
2
Evaluate SNMPv3 security levels (noAuthNoPriv, authNoPriv, authPriv).
Determine that authNoPriv incorporates authentication algorithms (HMAC-SHA or MD5) for integrity and user authentication, but omits payload encryption (DES/AES).
Understanding SNMPv3 security modes prevents misconfigurations where confidential management data is transmitted unencrypted despite enabling authentication.
3
Differentiate traffic flow telemetry from full packet capture.
Recognize that NetFlow/IPFIX records flow metadata (5-tuple: source IP, destination IP, source port, destination port, protocol, plus packet/byte counters) for bandwidth auditing and anomaly detection.
NetFlow provides scalable network visibility without requiring heavy storage infrastructure needed for packet capture files.
4
Define the primary function of a SIEM correlation engine in network auditing.
Connect SIEM functionality with cross-device event aggregation, parsing, and rule-based correlation of time-stamped logs from switches, firewalls, and servers.
SIEM systems correlate isolated log entries to identify multi-stage attacks or broader operational issues across the enterprise network.

Anahtar Kavram

Network Logging, Telemetry, and Auditing Architecture
Bu soruyu puanla