Southern New Hampshire University CYB 310 Module Four Lab Worksheet Complete this worksheet by replacing the bracketed phrases in the Response column with the relevant information. 1
Southern New Hampshire University Lab: Identifying & Analyzing Network Host Intrusion Detection System Alerts Prompt Response In the lab, "Analyzing Network Events Using Snorby," Step 18, take a screenshot of the alert window showing signature information and TCP header information. [Insert screenshot here.] In the lab section, "Network Security Monitoring with Squert," in the lab, "Analyzing Network Events Using Squert," Step 11, take a screenshot of the Squert window displaying filtered scans for ip 203.0.113.2. [Insert screenshot here.] In the lab section, "Network Security Monitoring with Squert," in the lab, "Analyzing Network Events Using Squert," Step 17, take a screenshot of the Squert window displaying no results when filtering events for ip 10.1.1.10. [Insert screenshot here.] There is a variety of network analyzers. Which tool did you feel was the most powerful and easiest to use? Why is it important to add network analyzer tools to your cybersecurity analyst skill set? How will you use network analyzer tools in a professional manner? [Insert short response here.] [Insert short response here.] [Insert short response here.] 2
Southern New Hampshire University Lab: Intrusion Detection Using Snort Prompt Response In the lab section, "Setting up the Sniffer," Step 19, type your name after the command prompt and take a screenshot of the output after running the tcpdump -i eth 1 command. In the lab section, "Detecting Unwanted Incoming Attacks," Step 9, take a screenshot of the results in the Bruter window after it has cycled through the dictionary words. In the lab, "Detecting Unwanted Outgoing Traffic," Step 6, type your name at the command prompt and take a screenshot of the output of the payload generated. How can you see what options are available for the tcpdump command? How can this tool be used by a security analyst? What command will display all of the Ethernet interfaces within Linux? How can this be valuable to a security analyst? [Insert screenshot here.] [Insert screenshot here.] [Insert screenshot here.] [Insert short response here.] [Insert short response here.] 3