SNMP Versions
Baseline
Quality of Service
6 Steps of Incident Response
100

What are the three versions of SNMP?

SNMPv1, SNMPv2, SNMPv3

100

Why create a baseline?


To provide a reference of network use to enable data traffic anomalies to be detected and then investigated.

100

Why is QoS used?

Ensures reliable and efficient transmission of critical traffic.  

100

What is the purpose of the identification step in incident response? 

To detect and report potential security incidents. 

200

A security difference between SNMPv1-2 and SNMPv3?

SNMP version 3 supports authentication and encryption.

200

Which metrics is typically included in a network baseline

Network Utilization

200

Which of QoS technique is used to prioritize traffic based on importance?

Traffic Prioritization 

200

What does the two 1's stand for in the 3-2-1-1 rule?

Store at least one backup copy offsite.
Ensure that at least one backup copy is stored offline.

300

Which Protocol does SNMP use to manage network devices?

UDP(User Datagram Protocol).

300

What are the benefits to regularly checking and updating a network baseline?

To ensure accurate anomaly detection and troubleshooting. 


300

What is one of the difference between IntServ and DiffServ QoS models?

IntServ reserves resoruces per flow, DiffServ classifies and prioritize traffic. 

300

What is the purpose of eradication? 

To remove root cause of the incident and prevent reoccurrence. 

400

What are the security concerns with SNMP?

Lack support for strong encryption. 

400

What is the main reason to establish an initial network performance baseline?

To enable you to quantify between changes in performance and changes in your load or application.

400

How does MPLS architecture benefit QoS in IP network? 

MLPS support by enabling traffic architecture and traffic prioritization. 

400

Which step in incident response involves isolating affected systems to prevent future damage

Containment