Cyberstudy
PDF p.330 In progress

Monitoring Systems and Applications

Open PDF at p.330 22 flashcards

Summary

PDF p.330

Dashboards and reports assist with real-time monitoring of host systems and applications/services. This includes system monitors, application and cloud monitors, vulnerability scanners, antivirus, and data loss prevention tools.

In plain words

Supplementary — not from your PDF

Hosts and applications need monitoring too. System monitors and logs track health and provide an audit trail tied to specific users, which is why accounts must never be shared. Application and cloud monitors check heartbeats, sessions, bandwidth, CPU and memory, and errors. Vulnerability scanners report unmitigated issues per host. Next-generation antivirus (EPP) uses AI and behaviour analytics. DLP dashboards show policy violations over time.

Detailed explanation

PDF p.330

System Monitors and Logs

  • Functionality: Similar to network monitors for computer hosts.
  • SNMP Traps: Report health status (e.g., CPU/memory load, disk capacity).
  • Logs: Valuable for diagnosing availability issues and recording authorized/unauthorized resource use.
  • Audit Trail: Logs provide a record of actions and early warnings of intrusion attempts.
  • User Association: Logs typically associate actions with specific users, emphasizing the importance of not sharing login details.

Application and Cloud Monitors

  • SNMP Limitations: Limited functionality.
  • Proprietary Solutions: Available for infrastructure, application, database, and cloud environments.
  • Monitoring Factors: Include heartbeat tests, session/request numbers, bandwidth consumption, CPU/memory utilization, error/security alerts.
  • Cloud Services: Monitor network bandwidth, virtual machine status, application health.

Vulnerability Scanners

  • Reports: Total number of unmitigated vulnerabilities for each host.
  • Consolidation: Shows network-wide host status and highlights patch/configuration issues.

Antivirus

  • Endpoint Protection Platforms (EPPs): Next-gen A-V suites detect malware by signature and integrate with user and entity behavior analytics (UEBA).
  • AI-Backed Analysis: Detects threat actor behavior bypassing signature matching.
  • Configuration: Automatically blocks detected threats and generates dashboard alerts/logs via SIEM integration.

Data Loss Prevention (DLP)

  • Function: Mediates copying of tagged data to authorized media/services.
  • Monitoring Statistics: Show DLP policy violations and trends over time.

Important terms

taken from the text above
Functionality
Similar to network monitors for computer hosts.
SNMP Traps
Report health status (e.g., CPU/memory load, disk capacity).
Logs
Valuable for diagnosing availability issues and recording authorized/unauthorized resource use.
Audit Trail
Logs provide a record of actions and early warnings of intrusion attempts.
User Association
Logs typically associate actions with specific users, emphasizing the importance of not sharing login details.
SNMP Limitations
Limited functionality.
Proprietary Solutions
Available for infrastructure, application, database, and cloud environments.
Monitoring Factors
Include heartbeat tests, session/request numbers, bandwidth consumption, CPU/memory utilization, error/security alerts.
Cloud Services
Monitor network bandwidth, virtual machine status, application health.
Reports
Total number of unmitigated vulnerabilities for each host.
Consolidation
Shows network-wide host status and highlights patch/configuration issues.
Endpoint Protection Platforms (EPPs)
Next-gen A-V suites detect malware by signature and integrate with user and entity behavior analytics (UEBA).
AI-Backed Analysis
Detects threat actor behavior bypassing signature matching.
Monitoring Statistics
Show DLP policy violations and trends over time.
DLP Data Loss Prevention EPPs Endpoint Protection Platforms

Examples & real-world scenarios

Supplementary — not from your PDF
  • A cloud monitor alerting when a VM stops responding.
  • A dashboard of unpatched vulnerabilities per host.
  • A DLP report on attempted uploads of tagged data.

Scenario

Two admins share one account, so logs can't show which of them deleted a critical file. Individual accounts make the audit trail meaningful.

Common mistakes

Supplementary — not from your PDF
  • Sharing accounts, which destroys accountability.
  • Relying on SNMP for detailed application monitoring. It's limited.

Practical skills

Supplementary — not from your PDF
  • Pick monitoring metrics for a web application.

What I should remember

Key Points PDF p.330
  • System Monitors and Logs
    • Functionality: Health status, SNMP traps.
    • Logs: Diagnose issues, record actions, early warnings.
    • User Association: Importance of unique login details.
  • Application and Cloud Monitors
    • SNMP Limitations: Limited functionality.
    • Proprietary Solutions: Infrastructure, application, database, cloud.
    • Monitoring Factors: Heartbeat tests, sessions, bandwidth, CPU/memory, alerts.
    • Cloud Services: Network bandwidth, VM status, application health.
  • Vulnerability Scanners
    • Reports: Unmitigated vulnerabilities.
    • Consolidation: Network-wide status.
  • Antivirus
    • EPPs: Next-gen A-V, UEBA integration.
    • AI-Backed Analysis: Detects bypassed threats.
    • Configuration: Automatic blocking, SIEM alerts/logs.
  • Data Loss Prevention (DLP)
    • Function: Mediates data copying.
    • Monitoring Statistics: Policy violations, trends.