mediumMultiple Choice
300-410 Practice Question: An engineer is troubleshooting a router that is…
An engineer is troubleshooting a router that is generating syslog messages with incorrect timestamps. The router has 'service timestamps log datetime msec' configured, but the timestamps show the wrong time zone. The router's clock is set correctly via NTP. What is the most likely cause?
⚠ Common exam trap
The trap here is assuming that NTP provides timezone information, but NTP only synchronizes UTC; the router's timezone must be set separately with 'clock timezone'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The 'clock timezone' command is not configured on the router.
The 'service timestamps log datetime msec' command tells the router to timestamp syslog messages with the date and time, including milliseconds. However, 'datetime' uses the router's configured time zone, which is set by the 'clock timezone' command. If 'clock timezone' is not configured, the router defaults to UTC, so the timestamps appear in UTC even though NTP has set the clock correctly. Therefore, the most likely cause is that the time zone has not been explicitly configured.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The 'clock timezone' command is not configured on the router.
Why this is correct
The 'service timestamps log datetime msec' command formats timestamps but does not set the zone. Without 'clock timezone', the router displays UTC despite NTP synchronising the clock correctly, producing timestamps in the wrong local zone.
- ✗
The NTP server is not providing timezone information.
Why it's wrong here
NTP distributes UTC only; it never conveys timezone or offset data, so this cannot explain a wrong zone. The router derives local time from its own 'clock timezone' setting, which is absent here. NTP is correctly used for synchronising the clock itself, which the stem confirms already works.
- ✗
The 'service timestamps log' command should use 'localtime' instead of 'datetime'.
Why it's wrong here
The 'datetime' keyword already timestamps events using the router's clock, so swapping to 'localtime' changes nothing about time-zone offset; the cause lies in the clock's time-zone setting itself. It is tempting because 'localtime' sounds like it applies local offset, but it only affects display formatting.
- ✗
The syslog server is overwriting the timestamps with its own.
Why it's wrong here
Syslog servers receive and store messages; they do not rewrite embedded timestamp fields generated by the router. Server-side timestamping is relevant when correlating arrival times across collectors, but the wrong time zone originates in the router's own logging configuration, not the collector.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.