Courseiva
Network OperationsmediumMultiple ChoiceObjective-mapped

N10-009 Network Operations Practice Question

A network administrator is configuring a syslog server to receive logs from network devices. The administrator wants to capture all messages with a severity level of 'critical' (2) and higher (more severe). What severity threshold should be set on the devices?

⚠ Common exam trap

Many exam-takers think setting a threshold of 2 captures only level 2 messages, but in syslog, the threshold includes all lower-numbered (more severe) levels as well.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

2 (critical)

Syslog severity levels are numbered 0 (most severe) through 7 (least severe). When you set a severity threshold on a device, it captures messages at that level and all lower-numbered (more severe) levels. To capture 'critical' (2) and higher (i.e., levels 0, 1, and 2), you must set the threshold to 2. Option C is correct because level 2 includes itself and all more severe levels (0 and 1).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • 0 (emergency)

    Why it's wrong here

    A threshold set to 0, or 'emergency,' is the most restrictive syslog configuration, causing the server to only log messages of the highest severity: emergency. This setting would completely omit critical (severity 2) and alert (severity 1) messages, which are crucial for identifying and responding to serious system problems before they escalate to an emergency state. Consequently, it does not satisfy the administrator's objective to receive critical and higher severity logs, potentially missing vital warnings.

    When this WOULD be correct

    This option would be correct if the question asked to capture only emergency-level messages (severity 0) and nothing else, or if the threshold was defined as 'only messages at this level or lower' (i.e., more severe) and the requirement was to capture only emergencies.

  • 1 (alert)

    Why it's wrong here

    Configuring the syslog threshold to 1, or 'alert,' would result in the server only receiving messages with severity levels 0 (emergency) and 1 (alert). This setting explicitly excludes messages classified as critical (severity 2), which are less severe than alerts but still represent significant issues the administrator intends to capture. Therefore, it fails to meet the requirement of including critical messages, leading to a gap in crucial event monitoring.

    When this WOULD be correct

    If the requirement were to capture only messages of severity 'alert' (1) and higher (more severe), i.e., only emergencies and alerts, then threshold 1 would be correct.

  • 2 (critical)

    Why this is correct

    Setting the syslog severity threshold to 2, or 'critical,' ensures that the server receives messages categorized as critical (severity 2) and all numerically lower, more severe levels. This includes emergency (0) and alert (1) messages, precisely meeting the requirement to capture 'critical and higher' events for comprehensive monitoring of significant system issues. This configuration provides the desired balance, capturing vital information without overwhelming the server with less urgent logs.

  • 3 (error)

    Why it's wrong here

    A threshold of 3/error would include error and all lower numbers (more severe), so it would also capture critical and above. However, the administrator specifically wants only critical and higher, not error. So setting to 2 is more precise to exclude error messages.

    When this WOULD be correct

    If the question asked to capture all messages with severity 'error' (3) and higher (more severe), then setting the threshold to 3 would be correct. For example: 'The administrator wants to capture all messages with a severity level of error and higher.'

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.

2 (critical)Correct answer

Why this is correct

Setting the syslog severity threshold to 2, or 'critical,' ensures that the server receives messages categorized as critical (severity 2) and all numerically lower, more severe levels. This includes emergency (0) and alert (1) messages, precisely meeting the requirement to capture 'critical and higher' events for comprehensive monitoring of significant system issues. This configuration provides the desired balance, capturing vital information without overwhelming the server with less urgent logs.

0 (emergency)Wrong answer — click to see why

Why this is wrong here

Setting a threshold of 0 (emergency) would only capture messages with severity 0, missing critical (2) and alert (1) messages. The question requires capturing critical and higher, which includes levels 0, 1, and 2, so the threshold must be 2.

★ When this WOULD be the correct answer

This option would be correct if the question asked to capture only emergency-level messages (severity 0) and nothing else, or if the threshold was defined as 'only messages at this level or lower' (i.e., more severe) and the requirement was to capture only emergencies.

Why candidates choose this

Candidates may mistakenly think that setting a lower threshold number (0) captures more severe messages, but in syslog, lower numbers are more severe and the threshold includes that level and higher numbers (less severe). They might also confuse the threshold with a filter that only allows that exact level.

1 (alert)Wrong answer — click to see why

Why this is wrong here

Setting a threshold of 1 (alert) would capture only messages with severity 0 and 1, excluding critical (2) messages, which the administrator wants to include.

★ When this WOULD be the correct answer

If the requirement were to capture only messages of severity 'alert' (1) and higher (more severe), i.e., only emergencies and alerts, then threshold 1 would be correct.

Why candidates choose this

Candidates may confuse the threshold meaning, thinking that setting a lower number captures more messages, but in syslog, the threshold includes messages at that level and lower numbers (more severe), so threshold 1 excludes level 2.

3 (error)Wrong answer — click to see why

Why this is wrong here

Setting the threshold to 3 (error) would capture messages with severity 3 and higher (0-3), which includes 'error' messages but excludes 'critical' (2) and higher severity messages like 'alert' (1) and 'emergency' (0). The requirement is to capture 'critical' and higher, so the threshold must be 2.

★ When this WOULD be the correct answer

If the question asked to capture all messages with severity 'error' (3) and higher (more severe), then setting the threshold to 3 would be correct. For example: 'The administrator wants to capture all messages with a severity level of error and higher.'

Why candidates choose this

Candidates may confuse the threshold direction, thinking that a higher number captures more severe messages, or they may misremember the severity levels and think 'error' is more severe than 'critical'.

Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every N10-009 question from scratch — 464 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.