mediumMultiple Choice
300-410 Practice Question: A router is configured to send syslog messages to…
A router is configured to send syslog messages to two servers: 10.1.1.100 and 10.1.1.200. The engineer notices that only server 10.1.1.100 is receiving messages. The configuration shows 'logging host 10.1.1.100' and 'logging host 10.1.1.200'. Both servers are reachable via ping. What is the most likely cause?
⚠ Common exam trap
The trap is assuming that ping success guarantees syslog delivery, ignoring that ping tests ICMP while syslog uses UDP port 514, which may be blocked by a firewall or the service may be down.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The syslog service on 10.1.1.200 is not running or is blocked by a firewall.
The router is configured to send syslog messages to two servers, and both are reachable via ping. If only one server receives messages, the most likely cause is that the syslog service on the second server is not running or is blocked by a firewall. Ping only tests ICMP reachability, not UDP port 514, so a firewall blocking syslog traffic would not be detected by ping.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The syslog service on 10.1.1.200 is not running or is blocked by a firewall.
Why this is correct
Both hosts are configured and reachable at the network layer, so routing is not the fault. Syslog is UDP-based and fire-and-forget, meaning the router cannot detect a non-listening daemon or blocked port 514 on 10.1.1.200, which silently drops the messages.
- ✗
The router can only send to one syslog server at a time.
Why it's wrong here
Cisco IOS supports multiple simultaneous 'logging host' entries, each receiving the same stream, so the one-server limit does not exist. A single-destination constraint would apply to features such as a solitary SNMP trap host, not to syslog logging destinations.
- ✗
The 'logging host 10.1.1.200' command is missing the 'transport udp' keyword.
Why it's wrong here
UDP is the default transport for Cisco syslog, so omitting 'transport udp' still sends messages to that host; the keyword is only needed to override the default with TCP. Specifying transport is correct when a server requires TCP syslog on port 1468 instead of the standard UDP 514.
- ✗
The second server is configured with a different severity level using 'logging trap' under the host.
Why it's wrong here
Severity filtering is applied globally with the 'logging trap' command, not per host under 'logging host', so a per-server severity level cannot be configured this way. Per-host severity would be the answer if the platform actually supported independent trap levels for each destination.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.