EX200 Essential Tools Practice Question
A company policy requires that all cron jobs run by non-root users must be logged to a specific file /var/log/usercron.log. The system administrator decides to use rsyslog to capture these messages. Which configuration directive should be added to /etc/rsyslog.conf or a file in /etc/rsyslog.d/ to achieve this?
⚠ Common exam trap
Test-takers frequently confuse the `cron` facility with the `user` facility, mistakenly thinking user cron jobs are logged under `user.*` instead of the dedicated `cron` facility.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
cron.* /var/log/usercron.log
The cron facility in rsyslog captures messages generated by the cron daemon, including cron jobs run by non-root users. By adding the directive `cron.* /var/log/usercron.log` to the rsyslog configuration, all cron messages (regardless of priority) are logged to the specified file, satisfying the policy requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
user.* /var/log/usercron.log
Why it's wrong here
The 'user' facility in syslog is reserved for user-level application messages, not for system daemons like cron. Cron uses its own dedicated facility, traditionally 'cron' (and on most Linux systems the rsyslog selector is simply 'cron'). Therefore, a 'user.*' rule would capture arbitrary user-process logs and completely miss crond's execution records, failing the policy's requirement. In practice, nothing from cron is ever filed under 'user', so this directive would produce an empty or irrelevant usercron.log.
- ✓
cron.* /var/log/usercron.log
Why this is correct
The 'cron' facility is the designated syslog source for all messages generated by the cron daemon, such as job launches, completions, and errors. Using the '*' priority wildcard ensures that every severity level—from debug to emergency—is recorded, capturing the full cron activity stream without dropping lower-priority messages. This makes 'cron.*' the precise, policy-compliant directive for sending cron logging to /var/log/usercron.log.
- ✗
*.* /var/log/usercron.log
Why it's wrong here
The '*.*' selector matches every possible facility (auth, daemon, kern, cron, mail, etc.) and every possible priority, so it would redirect the entire system's syslog stream into /var/log/usercron.log. This is wildly over-inclusive: kernel, boot, security, and application messages would all be merged with cron data, making the log file noisy and difficult to audit. It violates the principle of least privilege in logging, because the policy specifically asks for cron job records, not a full system log dump.
- ✗
authpriv.* /var/log/usercron.log
Why it's wrong here
The 'authpriv' facility is used exclusively for authentication and security events, such as login attempts, sudo invocations, and su usage. Cron job execution is not considered an authentication event, so an 'authpriv.*' rule would write login/sudo records to usercron.log while completely ignoring crond's activity. This would not satisfy the monitoring requirement because no cron job output would ever appear in the targeted file.
Go deeper
Related to this question
About these practice questions
Courseiva writes every EX200 question from scratch — 427 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This EX200 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX200 exam.