CCNA AI and Network Operations Practice Question
An operations team uses an AI-based tool that correlates syslog messages, interface counters, and routing events to suggest probable root causes. After a recent change to the logging configuration, the tool's suggestions become noticeably less accurate. Which logging-related change most plausibly explains the degraded correlation?
⚠ Common exam trap
The trap here is focusing on message volume or transport path when the real dependency for cross-device correlation is a consistent, synchronized timeline.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Devices were reconfigured to send syslog messages with local device clocks that are no longer synchronized to a common time source.
AI correlation builds a timeline across devices, so event ordering must be trustworthy. When device clocks drift, the platform places events at incorrect points on that timeline and draws wrong relationships between routing changes, interface counters, and syslog entries. Restoring synchronization through a common time source directly repairs the temporal alignment that root-cause analysis depends on.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The syslog severity level was lowered so that only emergency and alert messages are forwarded to the collector.
Why it's wrong here
Filtering to only the highest severities reduces message volume, but the remaining messages still carry correct timestamps and content. The tool would see fewer events rather than misordered ones, so its suggestions might become less detailed but would not be systematically wrong in the correlated way described.
- ✗
Devices were configured to include their hostname in the syslog message header rather than only their IP address.
Why it's wrong here
Adding the hostname improves identification of the source device and typically helps correlation rather than harming it. The content and timing of events are unchanged, so the analytics engine still receives the same sequence of messages. This change cannot account for a sudden drop in the accuracy of suggested root causes.
- ✗
The syslog collector was moved to a different subnet that requires routing through an additional Layer 3 hop.
Why it's wrong here
An extra routed hop changes transport path and possibly latency, but syslog messages still arrive with their original content and device-generated timestamps. Unless packets are dropped, correlation inputs remain intact, so the degraded root-cause accuracy described in the scenario is not explained by a longer network path.
- ✓
Devices were reconfigured to send syslog messages with local device clocks that are no longer synchronized to a common time source.
Why this is correct
Correlation depends on ordering events from different devices on a shared timeline. If device clocks drift apart, the platform aligns a routing event with the wrong interface or syslog entry, producing plausible but incorrect root causes. Restoring a common time source re-establishes the temporal relationships the analytics engine relies on.
Go deeper
Related to this question
Learn chapter
Distance Vector vs Link-State Routing
Key term
Interface
An interface is a point of connection or interaction between two systems, devices, or software components that allows them to exchange information or signals.
Key term
Syslog
Syslog is a standard protocol used to send and store log messages from network devices and servers to a central logging server for monitoring and troubleshooting.
About these practice questions
Courseiva writes every 200-301 question from scratch — 1,450 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.