N10-009 exam dumps

N10-009 practice question 76 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 76

Single answerSyslog: 514

A network administrator has configured several switches and firewalls to send logs to a centralized logging server at 10.20.30.50. After a firewall rule cleanup, the devices are still reachable by ping and SSH, but no new log entries are appearing on the logging server. The administrator wants to restore standard syslog traffic with the least change to the environment. Which firewall rule should be added?

  1. A

    Allow UDP traffic from the network devices to 10.20.30.50 on port 514

  2. B

    Allow TCP traffic from the logging server to the network devices on port 514

  3. C

    Allow UDP traffic from 10.20.30.50 to the network devices on port 161

  4. D

    Allow TCP traffic from the network devices to 10.20.30.50 on port 443

Show answer and explanation

Correct answer: A

Explanation

This scenario tests practical knowledge of syslog transport and traffic direction. Traditional syslog uses UDP port 514, with network devices acting as senders and the centralized log host acting as the receiver. Because the devices can still be reached via ping and SSH, basic IP connectivity exists, so the issue is likely that the firewall no longer permits the required syslog traffic. The least disruptive fix is to allow UDP 514 from the devices to the syslog server. This aligns with widely used syslog behavior documented in BSD syslog conventions and reflected in common vendor implementations. Candidates should also recognize common distractors: SNMP uses UDP 161/162, and HTTPS uses TCP 443. While some modern logging solutions can use TCP or TLS-secured syslog on other ports such as 6514, the question asks for standard syslog traffic, which points to UDP 514.

  • A. Correct.

    Correct. Standard syslog commonly uses UDP port 514, with client devices such as switches, routers, and firewalls sending log messages to a centralized syslog server. If connectivity for management protocols like ping and SSH still works but logs are not arriving, permitting outbound UDP 514 from the devices to the syslog server is the most direct and minimal fix.

  • B. Incorrect.

    Incorrect. This reverses the traffic flow. In a typical syslog deployment, the network devices initiate log transmission to the syslog server; the server does not normally initiate sessions to collect standard syslog messages on port 514. Also, standard syslog is most commonly associated with UDP 514, not this server-to-device TCP flow.

  • C. Incorrect.

    Incorrect. Port 161/UDP is used for SNMP polling, not syslog. Someone might choose this because both SNMP and syslog are common network management services, but allowing UDP 161 would help monitoring systems query devices, not send log messages to a syslog collector.

  • D. Incorrect.

    Incorrect. TCP 443 is HTTPS, typically used for secure web management interfaces or web APIs. It is not the standard port/protocol combination for traditional syslog delivery. Choosing this option confuses general secure management access with log transport.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam