PrepAway - Latest Free Exam Questions & Answers

Which two considerations about secure network monitoring are important?

Which two considerations about secure network monitoring are important? (Choose two.)

PrepAway - Latest Free Exam Questions & Answers

A.
log tampering

B.
encryption algorithm strength

C.
accurate time stamping

D.
off-site storage

E.
Use RADIUS for router commands authorization.

F.
Do not use a loopback interface for device management access.

Explanation:
A coordinated clock is important primarily to provide chronological, sequential, and coordinated
logs. If clock sources are hijacked, events posted to logs can be out of sequence and not
coordinated. The risks include:
•The date of clock events could be modified so that they would not appear on daily/weekly reports
•The date could be modified back far enough so that events would be instantly purged at the
logging server
•The dates on multiple devices could be modified so that causal events would not appear
correlated in time
The net result of such tampering would corrupt the logs, therefore crippling the forensic analysis of
events.
Reference: http://www.cisco.com/web/about/security/intelligence/05_11_nsa-scty-compliance.html


Leave a Reply