โ† All COMPTIA Flashcard Decks

Network+ Network Monitoring and Logging Flashcards

7 cards from real COMPTIA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network+ Network Monitoring and Logging flashcards as text
  1. A network administrator wants to monitor bandwidth utilization on all WAN links in real time. Which protocol is most appropriate for collecting this data from routers?

    Answer: NetFlow

    NetFlow collects IP traffic statistics including bandwidth utilization per flow, making it ideal for WAN link monitoring.

  2. Which SNMP component is responsible for sending unsolicited alerts to the NMS when a threshold is exceeded?

    Answer: Trap

    SNMP Traps are unsolicited notifications sent by an agent to the NMS when a predefined threshold or event occurs.

  3. A syslog message has a severity level of 2. How should the administrator classify this message?

    Answer: Critical

    Syslog severity level 2 is 'Critical,' indicating serious conditions that require immediate attention.

  4. What is the primary advantage of using SNMPv3 over SNMPv1 in a production network?

    Answer: Authentication and encryption

    SNMPv3 adds user-based authentication and AES/DES encryption, addressing the security weaknesses of SNMPv1/v2c.

  5. An administrator notices that log timestamps across multiple network devices do not match. Which service should be implemented to resolve this?

    Answer: NTP

    NTP (Network Time Protocol) synchronizes clocks across all network devices, ensuring consistent log timestamps.

  6. Which tool would a network engineer use to capture and analyze raw packets traversing a network segment for troubleshooting?

    Answer: Protocol analyzer (packet sniffer)

    A protocol analyzer (such as Wireshark) captures raw packets for deep inspection of network traffic.

  7. A company wants to detect port scans and brute-force login attempts on its network. Which system should be deployed?

    Answer: IDS/IPS

    An Intrusion Detection/Prevention System (IDS/IPS) identifies and can block malicious activities like port scans and brute-force attacks.