Soru

Zorluk: ZorNetwork Logging and Auditing

An enterprise network engineer is auditing centralized management protocols and event notification mechanisms across core infrastructure switches. Match each network logging or management protocol configuration on the left with its correct operational or security characteristic on the right.

  • Syslog Severity Level 2 (Critical)Indicates severe device conditions, such as primary system component failures, that require immediate attention.
  • SNMPv3 authNoPrivProvides HMAC-based message integrity and user authentication, but transmits payload data unencrypted.
  • NetFlow v9 / IPFIXProvides statistical traffic flow metadata and IP header information rather than individual event log messages.
  • Syslog over TLS (TCP 6514)Establishes a connection-oriented, cryptographically secured transport channel to prevent log eavesdropping and tampering.

Cevap

Syslog Severity Level 2 (Critical) matches with indicating severe device conditions requiring immediate attention. SNMPv3 authNoPriv matches with providing HMAC-based authentication without payload encryption. NetFlow v9 / IPFIX matches with providing statistical traffic flow metadata. Syslog over TLS (TCP 6514) matches with establishing a connection-oriented, cryptographically secured transport channel.
Each protocol or standard is correctly matched based on its core technical functionality: Syslog Level 2 represents Critical alerts; SNMPv3 authNoPriv authenticates users without encrypting traffic; NetFlow/IPFIX exports flow statistics rather than log strings; and Syslog over TLS utilizes TCP port 6514 for secure, reliable event transport.

Adım Adım Çözüm

1
Analyze Syslog severity levels and transport security protocols.
Identify that Syslog severity level 2 represents 'Critical' error states. Syslog over TLS (RFC 5425) operates on TCP port 6514 to provide encryption and reliable delivery.
Standard Syslog ranges from 0 (Emergency) to 7 (Debug), where Level 2 is Critical. TCP 6514 is the standard secure port for TLS-encrypted log shipping.
2
Evaluate SNMPv3 security levels.
Map authNoPriv to authentication via hashing (HMAC-SHA/MD5) without encryption (privacy/DES/AES).
SNMPv3 supports noAuthNoPriv (no security), authNoPriv (authentication only), and authPriv (authentication and encryption).
3
Distinguish flow collection technologies from system log mechanisms.
Associate NetFlow v9 / IPFIX with IP flow export data rather than event log strings.
NetFlow tracks traffic statistics across interfaces (5-tuple metadata) whereas Syslog records system status, auditing, and error events.

Anahtar Kavram

Network Logging and Auditing Mechanisms (Syslog, SNMPv3, NetFlow)
Bu soruyu puanla