Cisco Certified Support Technician (CCST) NetworkingIP ServicesMedium
A network security team needs to centralize logging from all network devices (routers, switches, firewalls) to a dedicated server for security analysis and auditing. Which IP service is used for this purpose?
- ADHCP
- BNTP
- CSNMP
- DSyslog
Show answer & explanationAnswer & explanation
Correct answer: D. Syslog
Syslog is a standard protocol used to send system log or event messages to a central server. This centralization is vital for security monitoring, troubleshooting, and compliance auditing across diverse network devices.
Why the other options are wrong
- A. DHCP assigns IP addresses, unrelated to log collection.
- B. NTP synchronizes time, not involved in log collection.
- C. SNMP is for monitoring and managing devices, not primarily for sending event logs.
Syslog
A standard for message logging that allows network devices to send event messages to a centralized logging server.
- Centralizes log collection.
- Supports various log levels (severities).
- Uses UDP port 514 by default.
Memory trick: Syslog: System Logs, Sent Locally Or Globally.