Courseiva
mediumMultiple Choice

350-401 Practice Question: Consider the following partial syslog…

Consider the following partial syslog configuration on a Cisco IOS-XE switch:

logging host 10.10.10.1 transport udp port 514
logging trap 6
logging source-interface Loopback0
logging on

Which statement is true about this configuration?

⚠ Common exam trap

Cisco often tests the misconception that `logging trap 6` means only severity 6 messages are sent, when in fact it sends all messages with severity 0 through 6 (inclusive).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Syslog messages will be sourced from the IP address of Loopback0 interface.

The `logging source-interface Loopback0` command forces all syslog messages to use the IP address of Loopback0 as the source IP in the packet, regardless of the egress interface. This ensures the syslog server sees a consistent source address, which is critical for filtering and logging reliability. The configuration is correct, so option B is true.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Syslog messages with severity level 7 (Debugging) will be sent to 10.10.10.1.

    Why it's wrong here

    The 'logging trap 6' command sets the severity threshold to 6, meaning the router forwards syslog messages with severity levels 0 through 6 (Emergency through Informational) to the configured server. Severity level 7 (Debugging) is above this threshold and is therefore filtered out. As a result, debug messages will not be sent to 10.10.10.1, making the statement false.

  • ✓

    Syslog messages will be sourced from the IP address of Loopback0 interface.

    Why this is correct

    When 'logging source-interface Loopback0' is configured, the router uses the IP address assigned to Loopback0 as the source address for all outgoing syslog packets, regardless of which interface is used to route toward the syslog server. This provides a stable, predictable source IP that syslog servers can rely on for filtering and correlation. Since the command explicitly selects Loopback0, the statement is correct.

  • ✗

    The syslog server must be configured to receive messages on TCP port 514.

    Why it's wrong here

    The configuration in the question explicitly specifies 'transport udp port 514' for the syslog host, meaning the router will send syslog messages as UDP datagrams to destination port 514. UDP is the default and most common transport for syslog, but here it is specifically mandated by the configuration. Therefore, the syslog server must be configured to listen on UDP port 514, not TCP port 514, so the claim is incorrect.

  • ✗

    Only syslog messages with severity level 6 (Informational) will be sent.

    Why it's wrong here

    The parameter 'logging trap 6' establishes a threshold, not an exact severity filter. It instructs the router to send all syslog messages with severity 0 through 6, since level 6 is the least severe included in the range. This includes Emergency (0), Alert (1), Critical (2), Error (3), Warning (4), Notification (5), and Informational (6). Thus, the statement that only level 6 messages will be sent is false.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.