Courseiva
Network Services and SecurityeasyMultiple SelectObjective-mapped

CCNA Network Services and Security Practice Question

Which two statements correctly describe syslog severity levels?

⚠ Common exam trap

A common mistake is assuming that higher syslog severity numbers mean more critical issues, but the opposite is true—lower numbers indicate higher severity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Level 0 is the most severe

Syslog uses numbered severity levels where lower numbers indicate more critical events. Level 0 (Emergency) is the most severe, and Level 7 (Debugging) is the least. Option D is incorrect because severity levels are a syslog function, not specific to NTP. Option E is wrong because syslog defines eight severity levels (0–7), not four.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Level 0 is the most severe

    Why this is correct

    Severity level 0 is 'emergency' and is indeed the most severe, indicating that the system is unusable and requires immediate attention. It is assigned the highest priority, meaning any message with this level should be processed and reported before all others. The severity scale decreases numerically as urgency increases, so 0 outranks 1 ('alert'), 2 ('critical'), and every other level up to 7.

  • Level 7 is debugging

    Why this is correct

    Syslog severity level 7 is labeled 'debugging' and represents the least severe of the eight standard levels, not the most critical. It is intended for verbose, low-priority diagnostic messages that are typically used only when troubleshooting a system. Although it is the lowest severity, it is still a fully valid and standardized level within the 0–7 RFC 5424 scale.

  • Higher numbers always mean more critical issues

    Why it's wrong here

    Higher numbers do not indicate more critical issues; in fact, the opposite is true. The syslog severity scale is inversely ordered: 0 is the most severe, and 7 is the least severe. A message with level 5 ('notice') is less urgent than one with level 2 ('critical'), so interpreting higher numbers as more critical would misorder event priority and lead to improper incident response.

    When this WOULD be correct

    This option would be correct if the question described a different logging system where severity increases with number, such as some custom logging frameworks or Windows Event Viewer where higher levels indicate more critical events.

  • Severity levels are used only by NTP

    Why it's wrong here

    Severity levels are not exclusive to NTP; they are a core component of the syslog protocol and are used by routers, switches, servers, and countless applications to indicate message urgency. NTP (Network Time Protocol) is just one of many services that may generate syslog messages, and it has no special claim on these levels. Any process that sends syslog output can assign a severity level to its message.

    When this WOULD be correct

    If the question asked 'Which protocol uses syslog severity levels exclusively for its own logging?' then D would be correct, as NTP does utilize syslog for its event logging.

  • Syslog has only four severity levels

    Why it's wrong here

    The claim that syslog has only four severity levels is incorrect because the standard defines exactly eight levels, numbered 0 through 7. These levels are: emergency (0), alert (1), critical (2), error (3), warning (4), notice (5), informational (6), and debugging (7). Confusing the count often arises from grouping some levels together, but each numeric value has a distinct name and meaning.

    When this WOULD be correct

    This option would be correct if the question asked about syslog facility codes or another protocol with only four severity levels, such as SNMP traps (which have 0–3).

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.

Level 0 is the most severeCorrect answer

Why this is correct

Severity level 0 is 'emergency' and is indeed the most severe, indicating that the system is unusable and requires immediate attention. It is assigned the highest priority, meaning any message with this level should be processed and reported before all others. The severity scale decreases numerically as urgency increases, so 0 outranks 1 ('alert'), 2 ('critical'), and every other level up to 7.

Higher numbers always mean more critical issuesWrong answer — click to see why

Why this is wrong here

In syslog, lower numbers indicate higher severity (0 is emergency, most severe). Higher numbers (e.g., 7) are less severe (debugging). Thus, higher numbers do not mean more critical issues.

★ When this WOULD be the correct answer

This option would be correct if the question described a different logging system where severity increases with number, such as some custom logging frameworks or Windows Event Viewer where higher levels indicate more critical events.

Why candidates choose this

Candidates may intuitively think that higher numbers represent greater severity, similar to scales like earthquake magnitude or test scores, without knowing that syslog reverses this convention.

Severity levels are used only by NTPWrong answer — click to see why

Why this is wrong here

Syslog severity levels are used by many network devices and applications, not only NTP. NTP uses syslog for logging but is not the sole user.

★ When this WOULD be the correct answer

If the question asked 'Which protocol uses syslog severity levels exclusively for its own logging?' then D would be correct, as NTP does utilize syslog for its event logging.

Why candidates choose this

Candidates may associate syslog with NTP because NTP is a common protocol that generates syslog messages, leading to the mistaken belief that severity levels are NTP-specific.

Syslog has only four severity levelsWrong answer — click to see why

Why this is wrong here

Syslog has eight severity levels (0–7), not four. Level 0 is Emergency, and Level 7 is Debugging.

★ When this WOULD be the correct answer

This option would be correct if the question asked about syslog facility codes or another protocol with only four severity levels, such as SNMP traps (which have 0–3).

Why candidates choose this

Candidates may confuse syslog severity levels with other logging systems that have fewer levels, or they might misremember the number of levels due to common oversimplifications in study materials.

Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every 200-301 question from scratch — 1,389 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.