CCNA Network Services and Security Practice Question
A network team wants centralized logging and also wants log timestamps from different devices to line up accurately. Which combination best supports that goal?
⚠ Common exam trap
Don't confuse network management protocols like DHCP or NAT with logging and time synchronization functions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Syslog and NTP
The right combination is Syslog plus NTP. In plain language, Syslog gives the team a central place to collect and review device messages, while NTP makes sure the timestamps on those messages are consistent across the network. Centralized logs are useful on their own, but without synchronized clocks, incident timelines can become confusing and misleading. This pairing is a common operational best practice. Syslog handles the collection side, and NTP handles the time-correlation side. Other services such as DHCP, STP, or NAT do not solve this combination of requirements. The best answer is the one that recognizes that centralized logging and time synchronization are complementary, not competing, services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Syslog and NTP
Why this is correct
Syslog is the standard protocol for sending event messages to a central log server, enabling consolidated monitoring and troubleshooting. NTP synchronizes clocks across all networked devices, ensuring that log timestamps are consistent and can be accurately correlated during forensic analysis. Together, they form the foundational pair for centralized logging with reliable time alignment.
- ✗
DHCP and STP
Why it's wrong here
DHCP is responsible for automating IP address assignment, subnet masks, and other network parameters to clients, while STP prevents Layer 2 loops by blocking redundant paths. Neither mechanism exports system event logs to a central collector, nor does either adjust device clocks. Their combined function improves IP configuration and loop-free topology but leaves no central logging or synchronized time-stamping capability.
When this WOULD be correct
If the question were about ensuring devices on a network receive IP addresses and maintain loop-free connectivity, then a question asking for protocols that support network stability and address assignment could make this option correct.
- ✗
PAT and EtherChannel
Why it's wrong here
PAT (Port Address Translation) modifies source addresses and ports for outbound traffic, conserving public IPs, while EtherChannel aggregates multiple physical links into one logical link for higher bandwidth and redundancy. These features operate in the data and control planes but do not generate or forward syslog messages. They also have no effect on clock synchronization, so they cannot address centralized logging or timestamp correlation.
When this WOULD be correct
In a scenario where the question asks about optimizing bandwidth and managing multiple IP addresses for a group of devices, a question could focus on load balancing and IP address management, making PAT and EtherChannel the correct answer.
- ✗
ARP and CDP
Why it's wrong here
ARP resolves a known IPv4 address to a MAC address within a broadcast domain, enabling frame delivery, and CDP is a Cisco proprietary protocol that advertises device identity and capabilities to directly connected neighbors. Although CDP provides useful inventory information, it does not collect or transport log messages to a central repository. Neither protocol influences device time settings, making them irrelevant for synchronized centralized logging.
When this WOULD be correct
If the exam question asked about enhancing network device discovery and neighbor information sharing, then ARP and CDP could be the correct answer. For example, a question focused on improving network topology visibility would make this option valid.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓Syslog and NTPCorrect answer▾
Why this is correct
Syslog is the standard protocol for sending event messages to a central log server, enabling consolidated monitoring and troubleshooting. NTP synchronizes clocks across all networked devices, ensuring that log timestamps are consistent and can be accurately correlated during forensic analysis. Together, they form the foundational pair for centralized logging with reliable time alignment.
✗DHCP and STPWrong answer — click to see why▾
Why this is wrong here
DHCP dynamically assigns IP addresses and STP prevents loops in Layer 2 networks; neither provides centralized logging or time synchronization. Without NTP, timestamps from different devices would not align, making log correlation impossible.
★ When this WOULD be the correct answer
If the question were about ensuring devices on a network receive IP addresses and maintain loop-free connectivity, then a question asking for protocols that support network stability and address assignment could make this option correct.
Why candidates choose this
Students might think DHCP and STP are fundamental network services that could somehow contribute to logging or time accuracy, but they serve completely different purposes and do not address the requirements.
✗PAT and EtherChannelWrong answer — click to see why▾
Why this is wrong here
PAT (a form of NAT) translates private IP addresses to public ones, and EtherChannel bundles multiple links for redundancy and bandwidth; neither offers centralized logging or time synchronization. These technologies are unrelated to the goal.
★ When this WOULD be the correct answer
In a scenario where the question asks about optimizing bandwidth and managing multiple IP addresses for a group of devices, a question could focus on load balancing and IP address management, making PAT and EtherChannel the correct answer.
Why candidates choose this
Test-takers might confuse PAT with logging due to the term 'address translation' or think EtherChannel's link aggregation could help with log transport, but they do not provide the required functionality.
✗ARP and CDPWrong answer — click to see why▾
Why this is wrong here
ARP resolves IP addresses to MAC addresses, and CDP discovers directly connected Cisco devices; neither provides centralized logging or time synchronization. These protocols are for neighbor discovery and Layer 2 resolution, not for log management.
★ When this WOULD be the correct answer
If the exam question asked about enhancing network device discovery and neighbor information sharing, then ARP and CDP could be the correct answer. For example, a question focused on improving network topology visibility would make this option valid.
Why candidates choose this
Students might think CDP's device discovery could help identify logging sources or that ARP is involved in network communication for logs, but they do not fulfill the specific requirements of centralized logging and accurate timestamps.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Device File Management with SFTP and SCP
Key term
DHCP
Dynamic Host Configuration Protocol (DHCP) automatically assigns IP addresses and network settings to devices on a network, so they can communicate without manual configuration.
Key term
NAT
NAT (Network Address Translation) is a method that allows multiple devices on a private network to share a single public IP address when accessing the internet.
About these practice questions
This 200-301 question is part of Courseiva's 1,389-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.