CompTIA CySA+ (CS0-003)Security OperationsEasy
A SOC analyst is configuring log forwarding and needs to ensure that only the most critical events (system unusable, requires immediate action) are forwarded to an on-call pager system. Per standard syslog severity levels, which severity value should the filter match?
- ASeverity 5 – Notice
- BSeverity 7 – Debug
- CSeverity 0 – Emergency
- DSeverity 3 – Error
Show answer & explanationAnswer & explanation
Correct answer: C. Severity 0 – Emergency
Syslog severity levels range from 0 (Emergency, system unusable) to 7 (Debug). Emergency (0) is the highest and most critical level, exactly matching 'system unusable, requires immediate action.'
Why the other options are wrong
- A. Notice (5) is normal but significant condition, far below emergency.
- B. Debug (7) is the lowest severity used for diagnostic detail.
- D. Error (3) indicates a non-urgent failure, not an unusable system.
Syslog Severity Levels
A standardized 0–7 scale (RFC 5424) used to classify the urgency of log messages, from Emergency (0) to Debug (7).
- 0=Emergency, 1=Alert, 2=Critical, 3=Error
- 4=Warning, 5=Notice, 6=Informational, 7=Debug
- Lower numbers = higher severity/urgency
Memory trick: 'Every Awesome Cop Eats Warm Nachos In Diners' (Emergency,Alert,Critical,Error,Warning,Notice,Info,Debug)