ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 364 - SY0-601 discussion

Report
Export

A security administrator is using UDP port 514 to send a syslog through an unsecure network to the SIEM server. Which of the following is the best way for the administrator to improve the process?

A.
Change the protocol to TCP.
Answers
A.
Change the protocol to TCP.
B.
Add LDAP authentication to the SIEM server.
Answers
B.
Add LDAP authentication to the SIEM server.
C.
Use a VPN from the internal server to the SIEM and enable DLP.
Answers
C.
Use a VPN from the internal server to the SIEM and enable DLP.
D.
Add SSL/TLS encryption and use a TCP 6514 port to send logs.
Answers
D.
Add SSL/TLS encryption and use a TCP 6514 port to send logs.
Suggested answer: D

Explanation:

SSL/TLS encryption is a method of securing the syslog traffic by using cryptographic protocols to encrypt and authenticate the data. SSL/TLS encryption can prevent eavesdropping, tampering, or spoofing of the syslog messages. TCP 6514 is the standard port for syslog over TLS, as defined by RFC 5425. Using this port can ensure compatibility and interoperability with other syslog implementations that support TLS.

asked 02/10/2024
Massimo Cerqui
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first