LPIC-1 Essential System Services and Networking Practice Question
Exhibit
*.* @192.168.1.100:514
Refer to the exhibit. A system administrator finds this line in /etc/rsyslog.conf. What is the effect of this configuration?
⚠ Common exam trap
Candidates often confuse the single `@` (UDP) with double `@@` (TCP), or misinterpret `*.*` as a specific facility filter rather than the universal wildcard for all syslog messages.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
All syslog messages are forwarded via UDP to the server at 192.168.1.100 on port 514.
The line `*.* @192.168.1.100:514` in rsyslog.conf uses the `@` symbol to indicate UDP forwarding. The `*.*` selector means all facilities and all priorities, so every syslog message is forwarded via UDP to the server at 192.168.1.100 on port 514. This is a standard rsyslog syntax for remote logging.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Only messages with facility *.info are forwarded.
Why it's wrong here
The facility is a wildcard, so every facility is matched; the priority after the dot sets the minimum severity, not a facility named info. It is tempting because the syntax places the priority after the dot, which reads like a facility filter if you misremember which side of the dot carries which field.
- ✗
All syslog messages are forwarded via TCP to the server.
Why it's wrong here
A single '@' forwards over UDP; TCP requires '@@'. The line therefore does not use TCP. It is tempting because forwarding to a remote syslog server is exactly what the line does, and TCP is often assumed for reliable delivery, but the transport is chosen solely by the '@' or '@@' prefix.
- ✓
All syslog messages are forwarded via UDP to the server at 192.168.1.100 on port 514.
Why this is correct
The selector * matches every facility and severity, and the single @ prefix specifies forwarding over UDP to 192.168.1.100 on the default syslog port 514. This satisfies the exhibit's requirement to relay all messages to that remote collector.
- ✗
Only authentication-related messages are forwarded.
Why it's wrong here
The selector's facility and priority determine which messages match; nothing in the line restricts forwarding to authentication services such as authpriv. It is tempting because authpriv logging is a common rsyslog use case, and a line naming a specific facility would indeed forward only those messages.
Go deeper
Related to this question
About these practice questions
Courseiva writes every LPIC-1 question from scratch — 402 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This LPIC-1 practice question is part of Courseiva's free LPI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the LPIC-1 exam.