CompTIA CySA+ (CS0-003)Security OperationsEasy

A SOC analyst is configuring log forwarding and needs to ensure that only the most critical events (system unusable, requires immediate action) are forwarded to an on-call pager system. Per standard syslog severity levels, which severity value should the filter match?

  1. ASeverity 5 – Notice
  2. BSeverity 7 – Debug
  3. CSeverity 0 – Emergency
  4. DSeverity 3 – Error
Show answer & explanation

Correct answer: C. Severity 0 – Emergency

Syslog severity levels range from 0 (Emergency, system unusable) to 7 (Debug). Emergency (0) is the highest and most critical level, exactly matching 'system unusable, requires immediate action.'

Why the other options are wrong

  • A. Notice (5) is normal but significant condition, far below emergency.
  • B. Debug (7) is the lowest severity used for diagnostic detail.
  • D. Error (3) indicates a non-urgent failure, not an unusable system.

Syslog Severity Levels

A standardized 0–7 scale (RFC 5424) used to classify the urgency of log messages, from Emergency (0) to Debug (7).

  • 0=Emergency, 1=Alert, 2=Critical, 3=Error
  • 4=Warning, 5=Notice, 6=Informational, 7=Debug
  • Lower numbers = higher severity/urgency

Memory trick: 'Every Awesome Cop Eats Warm Nachos In Diners' (Emergency,Alert,Critical,Error,Warning,Notice,Info,Debug)

More Security Operations questions