Chapter 14 – Ongoing Security Management
TRUE/FALSE
1. Network protection is something you should implement initially and then only make changes if there is
a serious security breach.
2. One of the events you should continually monitor is logins.
3. In centralized data collection, data from sensors go to security managers at each corporate office.
4. Most IDPSs use random ports to transfer security data, thereby making it difficult for attackers to
exploit.
5. Change management should be used before making changes to firewall or IDPS rules that affect users.
6. Security auditing is the process of documenting countermeasures put in place due to attacks on the
network.
7. An operational audit looks for accounts that have weak or blank passwords.
8. Nonrepudiation is the use of encryption methods to ensure the confidentiality of data.
9. An IDPS must have enough memory to maintain connection state information.
10. Since system intrusions take place over a very short period of time, there is no need to maintain IDPS
log data for more than a few hours.
MULTIPLE CHOICE
1. Which of the following is NOT typically an aspect of a security event management program?
a.
monitoring events
c.
managing data from sensors
b.
managing IDPS firmware
d.
managing change
2. Which of the following is NOT a type of event that you would normally monitor?
a.
user account creation
c.
antivirus scanning
b.
e-mail attachment handling
d.
access to shared folders
3. Which of the following is a benefit of using centralized data collection to manage sensor data?
a.
less network traffic
c.
data stays on the local network
b.
less administrative time
d.
must use a VPN to transport data
4. Which of the following is a security-related reason for monitoring and evaluating network traffic?
a.
to determine if your IDPS signatures are
working well
c.
to optimize your router and switch
protocols
b.
to create substantial data to analyze
d.
to see how many files employees
download form the Internet
5. Which type of change does NOT typically require the use of change management procedures?
a.
new VPN gateways
c.
changing a manager’s permissions to a file
b.
changes to ACLs
d.
new password systems or procedures
6. The process of testing a network defense system is referred to as which of the following?
a.
security auditing
c.
IDPS evaluation
b.
change management
d.
distributed data collection
7. What should an outside auditing firm be asked to sign before conducting a security audit?
a.
subpoena
c.
search and seizure contract
b.
nondisclosure agreement
d.
social engineering covenant
8. What approach to security calls for security through a variety of defensive techniques that work
together?
a.
DOA
c.
DiD
b.
WoL
d.
PoE
9. Which aspect of strengthening the performance of IDPS may involve degaussing?
a.
managing memory
c.
managing storage
b.
managing bandwidth
d.
managing processors
10. How much space is typically needed to store IDPS data?
a.
a few hundred Kilobytes
c.
a megabyte or two
b.
a gigabyte or more
d.
at least a terabyte
COMPLETION
1. To manage the security information from the devices in a large network, you should establish a
security incident _________________ team.
2. You should review the logs and alerts created by your security devices, a process called _________
monitoring.
3. The ________________ command reviews the current connections and reports which ports a server is
listening to.
4. Each IDPS has _____________ that gather data passing through the gateway.
5. With ___________________ data collection, data from security devices goes to a management
console on its own local network.
6. You monitor and evaluate network traffic to gather evidence that indicates whether your IDPS
_________________ are working well or need to be updated.
7. _______________ management involves modifying equipment, systems, software, or procedures in a
sequential, planned way.
8. Groups known as ______________ teams are assembled to actively test a network.
9. One way to consolidate the data from several network and security devices is to transfer the
information to a central _______________.
10. A(n) ____________________ audit should look for accounts assigned to employees who have left the
company or user group.
MATCHING
a.
active defense in depth
f.
operational audit
b.
centralized data collection
g.
security event management program
c.
degaussing
h.
social engineering
d.
distributed data collection
i.
target-to-console ratio
e.
independent audit
j.
Tinkerbell program
1. an audit in which an outside firm inspects audit logs to ensure that an organization is collecting the
information it needs
2. a strong implementation of the DiD concept in which security personnel expect that attacks will occur
and try to anticipate them
3. a technique of tricking employees into divulging passwords or other information
4. the process of magnetically erasing an electronic device, such as a monitor or
a disk
5. the number of target computers on a network managed by a single command console
6. an audit by an organization’s own staff that examines system and security logs
7. a system in which an organization’s event and security data is funneled to a management console in
the main office
8. a program in which network connections are scanned and alerts are generated when logons are
attempted from a suspicious IDPS
9. a program that gathers and consolidates events from multiple sources so that the information can be
analyzed to improve network security
10. a system in which data from security devices goes to a management console on its own local network
SHORT ANSWER
1. List four type of events you should monitor as part of a security event management program.
2. If you determine that a Trojan program has been installed and is initiating a connection to a remote
host and you suspect passwords have been compromised, what steps should you take? List three of
them.
3. List the advantages of centralized data collection.
4. How does distributed data collection work when collecting data from multiple sensors?
5. Discuss the process of IDPS signature evaluation.
6. How can change adversely affect your network?
7. List three types of changes for which you should use change management.
8. What is security auditing and what type of information should be analyzed?
9. Discuss operational auditing. Include in your discussion what should be looked for in an operational
audit and what methods might be used in the audit.
10. List and define the areas for which DiD calls for maintenance.