300-410 Infrastructure Security Practice Question
A network engineer is configuring a Cisco IOS XE router to send syslog messages to a remote server for security auditing. The engineer wants to ensure that the syslog messages are protected from eavesdropping and tampering. The router already has a CA trustpoint configured. Which command should the engineer use to enable secure syslog?
⚠ Common exam trap
The trap here is assuming that specifying port 6514 alone enables TLS, but the transport must be explicitly set to 'tls' to activate encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
logging host 10.10.10.10 transport tls port 6514
The requirement is to protect syslog messages from eavesdropping and tampering, which necessitates encryption and integrity protection. Syslog over TLS (often called secure syslog) uses Transport Layer Security to encrypt and authenticate messages. The command 'logging host 10.10.10.10 transport tls port 6514' enables TLS transport, leveraging the existing CA trustpoint for certificate-based authentication. Other transport methods like UDP or plain TCP do not provide encryption. Therefore, the correct configuration is to use the 'tls' transport option.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
logging host 10.10.10.10 transport tcp port 6514
Why it's wrong here
This command configures syslog over TCP on port 6514, which is the default port for syslog over TLS, but it does not enable TLS encryption. Without the 'secure' keyword, the router will send syslog messages in plaintext over TCP, leaving them vulnerable to eavesdropping and tampering. Therefore, it does not meet the requirement for secure syslog.
- ✓
logging host 10.10.10.10 transport tls port 6514
Why this is correct
This command enables secure syslog over TLS by specifying the 'tls' transport and port 6514. The router will use the configured CA trustpoint to establish a TLS connection to the syslog server, ensuring confidentiality and integrity of the syslog messages. This meets the requirement for secure syslog.
- ✗
logging host 10.10.10.10 transport udp port 514
Why it's wrong here
This command configures syslog over UDP on port 514, which is the traditional insecure method. UDP does not provide encryption or integrity protection, so syslog messages can be intercepted or modified. It does not satisfy the need for secure syslog.
- ✗
logging host 10.10.10.10 transport tcp port 514
Why it's wrong here
This command configures syslog over TCP on port 514, which is non-standard because syslog over TCP typically uses port 601 or 6514. More importantly, it does not enable TLS encryption, so the messages are sent in plaintext. This fails to provide the required security for syslog messages.
Quick reference
OSI Model Reference
| Layer | Name | PDU | Key Protocols / Devices |
|---|---|---|---|
| 7 | Application | Data | HTTP, HTTPS, DNS, SMTP, FTP, SSH |
| 6 | Presentation | Data | TLS / SSL, JPEG, ASCII encoding |
| 5 | Session | Data | NetBIOS, RPC, SIP |
| 4 | Transport | Segment / Datagram | TCP, UDP |
| 3 | Network | Packet | IP, ICMP, OSPF — Routers |
| 2 | Data Link | Frame | Ethernet, Wi-Fi, PPP — Switches, Bridges |
| 1 | Physical | Bits | Cables, NICs, Hubs, Repeaters |
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.