CCNA AI and Network Operations Practice Question
A network engineer is configuring a Cisco Catalyst 9300 switch to send syslog messages to a centralized server at 10.10.10.50. The engineer also wants to ensure that only messages with severity level 4 (warnings) and above are logged locally and sent to the server. Which command set correctly configures the logging destination and severity filter on the switch?
⚠ Common exam trap
Candidates often confuse local logging severity commands like logging console with the remote syslog severity command logging trap.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
logging host 10.10.10.50 logging trap warnings
To send syslog messages to a remote server, the logging host command specifies the server IP address. The logging trap command sets the severity threshold for messages sent to that server. Using logging trap warnings ensures that only warnings (level 4) and more severe messages are transmitted. Local logging levels such as console or buffered are configured separately and do not control remote syslog filtering.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
logging trap 10.10.10.50 logging host warnings
Why it's wrong here
The syntax is reversed. logging trap expects a severity level, not an IP address, and logging host expects an IP address, not a severity level. This configuration would fail because the arguments are mismatched. The correct commands are logging host <ip> and logging trap <level>.
- ✗
logging server 10.10.10.50 logging severity 4
Why it's wrong here
The command logging server is not valid on Cisco IOS; the correct command is logging host. Additionally, logging severity is not a valid command; the correct command to set the trap level is logging trap. This option would result in syntax errors and fail to configure the desired behavior.
- ✗
logging host 10.10.10.50 logging console warnings
Why it's wrong here
While logging host correctly identifies the syslog server, logging console warnings controls which messages are displayed on the console, not which messages are sent to the syslog server. The requirement is to filter messages sent to the server, which is done with logging trap. Local console logging does not affect remote logging.
- ✓
logging host 10.10.10.50 logging trap warnings
Why this is correct
The logging host command specifies the syslog server, and logging trap warnings sets the severity level for messages sent to the server to warnings (level 4) and above. This matches the requirement to log warnings and higher severity messages to the remote server. The local logging level is separate and configured with logging console or logging buffered.
Go deeper
Related to this question
Learn chapter
IPv6 Address Types
Key term
Switch
A switch is a networking device that connects devices on a local area network and uses MAC addresses to forward data only to the intended recipient.
Key term
Syslog
Syslog is a standard protocol used to send and store log messages from network devices and servers to a central logging server for monitoring and troubleshooting.
About these practice questions
One of 1,450 original 200-301 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.