mediumMultiple Choice
SSCP Practice Question: Uses a central syslog server to collect logs from…
An organization uses a central syslog server to collect logs from firewalls, servers, and network devices. Recently, the security team noticed that some critical events from the firewall are missing from the syslog server. The firewall configuration sends syslog messages using UDP to the syslog server. The syslog server administrator reports that the server is receiving a high volume of logs and occasionally drops packets due to buffer overflow. The team needs to ensure reliable delivery of all syslog messages without losing any. Which solution should the team implement?
⚠ Common exam trap
The trap here is assuming that tuning UDP (buffer size, aggregation, load balancing) can make it reliable — UDP is inherently lossy, and only a connection-oriented protocol like TCP/TLS guarantees delivery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Switch to TCP-based syslog with TLS.
Syslog over UDP is fire-and-forget with no delivery guarantees, so packet loss from buffer overflow is expected. Switching to TCP-based syslog (ideally with TLS, i.e., RFC 5425) provides connection-oriented, reliable delivery with acknowledgments and retransmission, ensuring no messages are lost.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Switch to TCP-based syslog with TLS.
Why this is correct
TCP-based syslog with TLS provides acknowledged, ordered delivery, so dropped or lost packets are retransmitted rather than silently discarded. TLS also protects log integrity and confidentiality in transit, directly satisfying the requirement for reliable delivery without loss.
- ✗
Increase the UDP buffer size on the syslog server.
Why it's wrong here
Enlarging the UDP receive buffer only delays overflow; UDP remains connectionless with no acknowledgement or retransmission, so packets are still lost under sustained load. It is tempting because it is a quick server-side tuning change, and would be correct if drops were caused by brief bursts rather than the protocol's lack of delivery guarantees.
- ✗
Implement log aggregation at each network segment.
Why it's wrong here
Aggregating logs per network segment still forwards them over the same lossy UDP path to the central server, so buffer-overflow drops persist. It is tempting because aggregation reduces WAN traffic and consolidates sources, which suits bandwidth-constrained or distributed topologies, but it does not provide delivery acknowledgement or retransmission.
- ✗
Use a load balancer for syslog receivers.
Why it's wrong here
A load balancer spreads syslog traffic across multiple receivers, yet UDP itself offers no acknowledgement or retransmission, so packets dropped at any receiver's buffer are still lost. It is tempting because load balancing genuinely scales high-volume ingestion, and would be correct where throughput, not guaranteed delivery, is the constraint.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.