Memory hook: Baseline normal; control change; restore what matters.
Must remember
Maintain asset inventory, IPAM, topology, cable/rack diagrams, wireless surveys and current configurations. Know hardware/software end-of-support dates and preserve recoverable configuration backups. Decommissioning includes access revocation, data sanitization, inventory updates and removing obsolete monitoring/DNS entries.
Monitoring sources answer different questions: SNMP polls counters/state, traps notify events, flow records summarize communications, packet captures expose visible protocol detail, syslog centralizes events and APIs support structured telemetry. SNMPv3 can provide authentication and privacy; older community-string modes are weaker. Port mirroring copies selected traffic to an analysis port but may lose packets if oversubscribed.
Establish baselines for utilization, latency, jitter, loss, errors and availability. Thresholds without context create noise. Correlate changes and multiple sources; a high CPU graph is a symptom, not a root cause by itself.
Change management includes authorization, impact, dependency review, testing, maintenance windows, backups, rollback and validation. Store production, baseline and backup configurations distinctly. Emergency changes still need an accountable process and retrospective records.
RPO is tolerable data loss; RTO target restoration time. MTTR measures average repair/recovery time as defined; MTBF estimates time between failures. Do not confuse measured averages with contractual targets. Active-active uses multiple serving systems; active-passive keeps a standby. Recovery sites trade readiness and cost.
Secure remote administration through approved VPN/SSH/API or console access with individual accounts and least privilege. Out-of-band access helps recover from production network failures. Test restoration of configuration, routing, DNS, identity, monitoring and application reachability together.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Identify traffic sources without full payload capture | Flow telemetry. |
| Recover after a bad change | Known-good configuration and tested rollback. |
| Production network unavailable | Protected out-of-band management. |
Traps
- Monitoring without baselines and response ownership produces dashboards, not reliability.
- A configuration backup must match hardware/software and be restorable.
Active recall
1. SNMP polling versus traps?
Polling asks for information; traps send event notifications.
2. Why can a mirrored capture miss traffic?
The mirror destination or capture system may be oversubscribed.
3. RTO versus MTTR?
RTO is a recovery target; MTTR is a measured/estimated average recovery metric.
4. What should follow a network change?
Verification of intended behavior and monitoring for adverse effects.
5. Why preserve an out-of-band path?
To administer devices when the normal forwarding network is unavailable.