CompTIA Network+ (N10-009)Network OperationsMedium
A network engineer is configuring a new firewall and wants to ensure that all administrative access attempts, security alerts, and critical system events are sent to a centralized logging server for auditing and analysis. Which protocol should be configured on the firewall to forward these types of messages?
- ASyslog
- BNTP
- CNetFlow
- DSNMP
Show answer & explanationAnswer & explanation
Correct answer: A. Syslog
Syslog is the standard protocol for forwarding system log messages, including administrative access attempts, security alerts, and critical system events, from various network devices to a centralized logging server.
Why the other options are wrong
- B. NTP is used for time synchronization, not for sending log messages.
- C. NetFlow is used for collecting IP traffic flow statistics, not system event logs.
- D. SNMP is used for monitoring and managing network devices, and while it can send traps for alerts, Syslog is more general for detailed log messages.
Syslog
A standard protocol used for sending system log or event messages from a network device to a centralized logging server. It allows for the collection and analysis of logs from various sources.
- Standard for collecting diverse log messages.
- Uses UDP port 514 by default.
- Messages include facility and severity levels for categorization.
Memory trick: Logging needs a 'Sys'tematic 'Log' collector.