Courseiva
Network OperationsmediumMultiple ChoiceObjective-mapped

N10-009 Network Operations Practice Question

A network administrator wants to configure routers to send syslog messages only for events of severity 'error' (3) or higher (more severe). Which severity level should be set as the trap level?

⚠ Common exam trap

The trap here is that candidates often mistakenly think the trap level filters only that exact severity, when in fact it includes that level and all numerically lower (more severe) levels, leading them to choose a lower number like 2 or 0 instead of the correct 3.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

3 (errors)

Setting the trap level to 3 (errors) instructs the router to send syslog messages for severity 3 and all numerically lower (more severe) levels (0, 1, 2, 3). This matches the requirement to capture events of severity 'error' (3) or higher severity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • 0 (emergencies)

    Why it's wrong here

    Configuring the syslog level to 'emergencies' (severity level 0) is the most restrictive possible setting. This would only send messages for events of the absolute highest severity, specifically those classified as 'emergencies' (level 0). Consequently, it would completely omit 'errors' (level 3), 'critical' (level 2), and 'alerts' (level 1) messages, failing to meet the fundamental requirement to include error events in the syslog stream.

    When this WOULD be correct

    This option would be correct if the question asked: 'A network administrator wants to receive syslog messages only for emergencies (severity 0). Which severity level should be set as the trap level?'

  • 3 (errors)

    Why this is correct

    Configuring the router to send syslog messages for 'errors' (severity level 3) is the correct choice. In syslog, severity levels are numerical, where lower numbers indicate higher urgency. Setting the logging level to 3 means the router will send messages for this level and all numerically lower, more severe levels (0-emergencies, 1-alerts, 2-critical). This precisely captures all 'errors' and any events of greater importance, fulfilling the requirement.

  • 2 (critical)

    Why it's wrong here

    Selecting 'critical' (severity level 2) would configure the router to send messages for events at this level and all numerically lower, more severe levels (0-emergencies, 1-alerts). While this includes highly urgent events, it specifically excludes messages classified as 'errors' (severity level 3). Since the question explicitly requires 'errors' to be included, this setting is too restrictive and would miss crucial information.

    When this WOULD be correct

    If the question asked to send syslog messages only for events of severity 'critical' (2) or higher (more severe), then setting the trap level to 2 would be correct.

  • 4 (warnings)

    Why it's wrong here

    Choosing 'warnings' (severity level 4) would instruct the router to send syslog messages for events at this level and all numerically lower, more severe levels (0-emergencies, 1-alerts, 2-critical, 3-errors). While this certainly encompasses 'errors', it also includes 'warnings' and potentially 'notifications' (level 5) if the system interprets "level 4 and higher" as "level 4 and numerically lower (more severe) levels." This setting is too broad, potentially flooding the syslog server with less critical information than desired.

    When this WOULD be correct

    If the question asked to send syslog messages for events of severity 'warning' (4) or higher (more severe), then setting the trap level to 4 would be correct, as it includes warnings and all more severe levels (0-3).

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.

3 (errors)Correct answer

Why this is correct

Configuring the router to send syslog messages for 'errors' (severity level 3) is the correct choice. In syslog, severity levels are numerical, where lower numbers indicate higher urgency. Setting the logging level to 3 means the router will send messages for this level and all numerically lower, more severe levels (0-emergencies, 1-alerts, 2-critical). This precisely captures all 'errors' and any events of greater importance, fulfilling the requirement.

0 (emergencies)Wrong answer — click to see why

Why this is wrong here

Setting the trap level to 0 (emergencies) would only send syslog messages for severity 0 events, not for severity 3 or higher. The trap level includes the specified severity and all more severe levels, so level 0 excludes errors (3), critical (2), and warnings (4).

★ When this WOULD be the correct answer

This option would be correct if the question asked: 'A network administrator wants to receive syslog messages only for emergencies (severity 0). Which severity level should be set as the trap level?'

Why candidates choose this

Candidates may mistakenly think that setting a lower number (like 0) captures more events, not realizing that the trap level includes the specified level and all numerically lower (more severe) levels, so level 0 only captures emergencies.

2 (critical)Wrong answer — click to see why

Why this is wrong here

Setting the trap level to 2 (critical) would only send syslog messages for severity 0, 1, and 2, excluding severity 3 (errors). The requirement is to include severity 3 and higher, so level 3 is needed.

★ When this WOULD be the correct answer

If the question asked to send syslog messages only for events of severity 'critical' (2) or higher (more severe), then setting the trap level to 2 would be correct.

Why candidates choose this

Candidates may confuse the trap level with a threshold that includes all severities below the number, or they might think 'critical' is the highest severity and thus covers all, not realizing that lower numbers indicate higher severity.

4 (warnings)Wrong answer — click to see why

Why this is wrong here

Setting the trap level to 4 (warnings) would include events of severity 4 and higher (0-4), which includes warnings (4) and excludes errors (3). The requirement is to send messages for severity 3 (error) or higher, so level 4 would not capture errors.

★ When this WOULD be the correct answer

If the question asked to send syslog messages for events of severity 'warning' (4) or higher (more severe), then setting the trap level to 4 would be correct, as it includes warnings and all more severe levels (0-3).

Why candidates choose this

Candidates may confuse the direction of severity levels, thinking that a higher number includes more severe events, or they may misread 'higher (more severe)' to mean numerically higher values, when in fact lower numbers indicate higher severity.

Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every N10-009 question from scratch — 464 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.