Network Defense Module 10.4.2 Network Security Data Quiz Questions Exam Answers
1. What is a feature of the tcpdump tool?
- It records metadata about packet flows.
- It provides real-time reporting and long-term analysis of security events.
- It uses agents to submit host logs to centralized management servers.
- It can display packet captures in real time or write them to a file.
2. A NIDS/NIPS has identified a threat. Which type of security data will be generated and sent to a logging device?
- alert
- transaction
- statistical
- session
3. Which statement describes the tcpdump tool?
- It is used to control multiple TCP-based applications.
- It is a command-line packet analyzer.
- It accepts and analyzes data captured by Wireshark.
- It can be used to analyze network log data in order to describe and predict network behavior.
4. What are two of the 5-tuples? (Choose two.)
- protocol
- ACL
- IPS
- IDS
- source port
5. Which type of security data can be used to describe or predict network behavior?
- statistical
- alert
- transaction
- session
6. Which Windows log records events related to login attempts and operations related to file or object access?
- setup logs
- system logs
- application logs
- security logs
7. Which type of data is used by Cisco Cognitive Intelligence to find malicious activity that has bypassed security controls, or entered through unmonitored channels, and is operating inside an enterprise network?
- session
- statistical
- alert
- transaction
8. Which Windows host log event type describes the successful operation of an application, driver, or service?
- warning
- error
- success audit
- information
9. What are two popular SIEM platforms? (Choose two.)
- NetFlow
- tcpdump
- Splunk
- Security Onion with ELK
- Cisco Umbrella
10. Which Windows tool can be used to review host logs?
- Event Viewer
- Services
- Task Manager
- Device Manager
11. Which statement describes an operational characteristic of NetFlow?
- NetFlow captures the entire contents of a packet.
- NetFlow flow records can be viewed by the tcpdump tool.
- NetFlow collects basic information about the packet flow, not the flow data itself.
- NetFlow can provide services for user access control.
12. In a Cisco AVC system, in which module is NBAR2 deployed?
- Application Recognition
- Metrics Collection
- Control
- Management and Reporting