Questions
As we conclude, here is a list of questions for you to test your knowledge regarding this chapter's material. You will find the answers in the Assessments section of the Appendix:
- Winlogbeat is used to collect what kind of data?
a. Windows event data
b. Windows performance metrics
c. Metrics about Beats installed on Windows systems
d. Windows network information
- Packetbeat is used to collect what kind of data?
a. Packet captures
b. Network traffic between Kibana and Elasticsearch
c. Application-type network events
d. Network performance metrics
- What is the central management app for Elastic Agent?
a. Fleet
b. Beats Central Manager
c. Group Policy
d. System Center Configuration Manager
- What are additions to Fleet policies called?
a. Modules
b. Plugins
c. Inputs
d. Integrations
- Which of the following Beats reports Sysmon events as a module?
a. Elastic Agent
b. Winlogbeat
c. Packetbeat
d. Auditbeat