Monitoring Systems and Applications
Summary
PDF p.330Dashboards and reports assist with real-time monitoring of host systems and applications/services. This includes system monitors, application and cloud monitors, vulnerability scanners, antivirus, and data loss prevention tools.
In plain words
Supplementary — not from your PDFHosts and applications need monitoring too. System monitors and logs track health and provide an audit trail tied to specific users, which is why accounts must never be shared. Application and cloud monitors check heartbeats, sessions, bandwidth, CPU and memory, and errors. Vulnerability scanners report unmitigated issues per host. Next-generation antivirus (EPP) uses AI and behaviour analytics. DLP dashboards show policy violations over time.
Detailed explanation
PDF p.330System Monitors and Logs
- Functionality: Similar to network monitors for computer hosts.
- SNMP Traps: Report health status (e.g., CPU/memory load, disk capacity).
- Logs: Valuable for diagnosing availability issues and recording authorized/unauthorized resource use.
- Audit Trail: Logs provide a record of actions and early warnings of intrusion attempts.
- User Association: Logs typically associate actions with specific users, emphasizing the importance of not sharing login details.
Application and Cloud Monitors
- SNMP Limitations: Limited functionality.
- Proprietary Solutions: Available for infrastructure, application, database, and cloud environments.
- Monitoring Factors: Include heartbeat tests, session/request numbers, bandwidth consumption, CPU/memory utilization, error/security alerts.
- Cloud Services: Monitor network bandwidth, virtual machine status, application health.
Vulnerability Scanners
- Reports: Total number of unmitigated vulnerabilities for each host.
- Consolidation: Shows network-wide host status and highlights patch/configuration issues.
Antivirus
- Endpoint Protection Platforms (EPPs): Next-gen A-V suites detect malware by signature and integrate with user and entity behavior analytics (UEBA).
- AI-Backed Analysis: Detects threat actor behavior bypassing signature matching.
- Configuration: Automatically blocks detected threats and generates dashboard alerts/logs via SIEM integration.
Data Loss Prevention (DLP)
- Function: Mediates copying of tagged data to authorized media/services.
- Monitoring Statistics: Show DLP policy violations and trends over time.
Important terms
taken from the text above- Functionality
- Similar to network monitors for computer hosts.
- SNMP Traps
- Report health status (e.g., CPU/memory load, disk capacity).
- Logs
- Valuable for diagnosing availability issues and recording authorized/unauthorized resource use.
- Audit Trail
- Logs provide a record of actions and early warnings of intrusion attempts.
- User Association
- Logs typically associate actions with specific users, emphasizing the importance of not sharing login details.
- SNMP Limitations
- Limited functionality.
- Proprietary Solutions
- Available for infrastructure, application, database, and cloud environments.
- Monitoring Factors
- Include heartbeat tests, session/request numbers, bandwidth consumption, CPU/memory utilization, error/security alerts.
- Cloud Services
- Monitor network bandwidth, virtual machine status, application health.
- Reports
- Total number of unmitigated vulnerabilities for each host.
- Consolidation
- Shows network-wide host status and highlights patch/configuration issues.
- Endpoint Protection Platforms (EPPs)
- Next-gen A-V suites detect malware by signature and integrate with user and entity behavior analytics (UEBA).
- AI-Backed Analysis
- Detects threat actor behavior bypassing signature matching.
- Monitoring Statistics
- Show DLP policy violations and trends over time.
Examples & real-world scenarios
Supplementary — not from your PDF- A cloud monitor alerting when a VM stops responding.
- A dashboard of unpatched vulnerabilities per host.
- A DLP report on attempted uploads of tagged data.
Scenario
Two admins share one account, so logs can't show which of them deleted a critical file. Individual accounts make the audit trail meaningful.
Common mistakes
Supplementary — not from your PDF- Sharing accounts, which destroys accountability.
- Relying on SNMP for detailed application monitoring. It's limited.
Practical skills
Supplementary — not from your PDF- Pick monitoring metrics for a web application.
What I should remember
Key Points PDF p.330-
System Monitors and Logs
- Functionality: Health status, SNMP traps.
- Logs: Diagnose issues, record actions, early warnings.
- User Association: Importance of unique login details.
-
Application and Cloud Monitors
- SNMP Limitations: Limited functionality.
- Proprietary Solutions: Infrastructure, application, database, cloud.
- Monitoring Factors: Heartbeat tests, sessions, bandwidth, CPU/memory, alerts.
- Cloud Services: Network bandwidth, VM status, application health.
-
Vulnerability Scanners
- Reports: Unmitigated vulnerabilities.
- Consolidation: Network-wide status.
-
Antivirus
- EPPs: Next-gen A-V, UEBA integration.
- AI-Backed Analysis: Detects bypassed threats.
- Configuration: Automatic blocking, SIEM alerts/logs.
-
Data Loss Prevention (DLP)
- Function: Mediates data copying.
- Monitoring Statistics: Policy violations, trends.