N10-009 Network Operations Practice Question
A network administrator wants to configure routers to send syslog messages only for events of severity 'error' (3) or higher (more severe). Which severity level should be set as the trap level?
⚠ Common exam trap
The trap here is that candidates often mistakenly think the trap level filters only that exact severity, when in fact it includes that level and all numerically lower (more severe) levels, leading them to choose a lower number like 2 or 0 instead of the correct 3.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
3 (errors)
Setting the trap level to 3 (errors) instructs the router to send syslog messages for severity 3 and all numerically lower (more severe) levels (0, 1, 2, 3). This matches the requirement to capture events of severity 'error' (3) or higher severity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
0 (emergencies)
Why it's wrong here
Configuring the syslog level to 'emergencies' (severity level 0) is the most restrictive possible setting. This would only send messages for events of the absolute highest severity, specifically those classified as 'emergencies' (level 0). Consequently, it would completely omit 'errors' (level 3), 'critical' (level 2), and 'alerts' (level 1) messages, failing to meet the fundamental requirement to include error events in the syslog stream.
When this WOULD be correct
This option would be correct if the question asked: 'A network administrator wants to receive syslog messages only for emergencies (severity 0). Which severity level should be set as the trap level?'
- ✓
3 (errors)
Why this is correct
Configuring the router to send syslog messages for 'errors' (severity level 3) is the correct choice. In syslog, severity levels are numerical, where lower numbers indicate higher urgency. Setting the logging level to 3 means the router will send messages for this level and all numerically lower, more severe levels (0-emergencies, 1-alerts, 2-critical). This precisely captures all 'errors' and any events of greater importance, fulfilling the requirement.
- ✗
2 (critical)
Why it's wrong here
Selecting 'critical' (severity level 2) would configure the router to send messages for events at this level and all numerically lower, more severe levels (0-emergencies, 1-alerts). While this includes highly urgent events, it specifically excludes messages classified as 'errors' (severity level 3). Since the question explicitly requires 'errors' to be included, this setting is too restrictive and would miss crucial information.
When this WOULD be correct
If the question asked to send syslog messages only for events of severity 'critical' (2) or higher (more severe), then setting the trap level to 2 would be correct.
- ✗
4 (warnings)
Why it's wrong here
Choosing 'warnings' (severity level 4) would instruct the router to send syslog messages for events at this level and all numerically lower, more severe levels (0-emergencies, 1-alerts, 2-critical, 3-errors). While this certainly encompasses 'errors', it also includes 'warnings' and potentially 'notifications' (level 5) if the system interprets "level 4 and higher" as "level 4 and numerically lower (more severe) levels." This setting is too broad, potentially flooding the syslog server with less critical information than desired.
When this WOULD be correct
If the question asked to send syslog messages for events of severity 'warning' (4) or higher (more severe), then setting the trap level to 4 would be correct, as it includes warnings and all more severe levels (0-3).
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓3 (errors)Correct answer▾
Why this is correct
Configuring the router to send syslog messages for 'errors' (severity level 3) is the correct choice. In syslog, severity levels are numerical, where lower numbers indicate higher urgency. Setting the logging level to 3 means the router will send messages for this level and all numerically lower, more severe levels (0-emergencies, 1-alerts, 2-critical). This precisely captures all 'errors' and any events of greater importance, fulfilling the requirement.
✗0 (emergencies)Wrong answer — click to see why▾
Why this is wrong here
Setting the trap level to 0 (emergencies) would only send syslog messages for severity 0 events, not for severity 3 or higher. The trap level includes the specified severity and all more severe levels, so level 0 excludes errors (3), critical (2), and warnings (4).
★ When this WOULD be the correct answer
This option would be correct if the question asked: 'A network administrator wants to receive syslog messages only for emergencies (severity 0). Which severity level should be set as the trap level?'
Why candidates choose this
Candidates may mistakenly think that setting a lower number (like 0) captures more events, not realizing that the trap level includes the specified level and all numerically lower (more severe) levels, so level 0 only captures emergencies.
✗2 (critical)Wrong answer — click to see why▾
Why this is wrong here
Setting the trap level to 2 (critical) would only send syslog messages for severity 0, 1, and 2, excluding severity 3 (errors). The requirement is to include severity 3 and higher, so level 3 is needed.
★ When this WOULD be the correct answer
If the question asked to send syslog messages only for events of severity 'critical' (2) or higher (more severe), then setting the trap level to 2 would be correct.
Why candidates choose this
Candidates may confuse the trap level with a threshold that includes all severities below the number, or they might think 'critical' is the highest severity and thus covers all, not realizing that lower numbers indicate higher severity.
✗4 (warnings)Wrong answer — click to see why▾
Why this is wrong here
Setting the trap level to 4 (warnings) would include events of severity 4 and higher (0-4), which includes warnings (4) and excludes errors (3). The requirement is to send messages for severity 3 (error) or higher, so level 4 would not capture errors.
★ When this WOULD be the correct answer
If the question asked to send syslog messages for events of severity 'warning' (4) or higher (more severe), then setting the trap level to 4 would be correct, as it includes warnings and all more severe levels (0-3).
Why candidates choose this
Candidates may confuse the direction of severity levels, thinking that a higher number includes more severe events, or they may misread 'higher (more severe)' to mean numerically higher values, when in fact lower numbers indicate higher severity.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Network Documentation and Diagrams
Key term
Syslog
Syslog is a standard protocol used to send and store log messages from network devices and servers to a central logging server for monitoring and troubleshooting.
Key term
Router
A router is a networking device that connects different networks together and directs data traffic between them by choosing the best path for data to travel.
About these practice questions
Courseiva writes every N10-009 question from scratch — 464 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.