exam questions

Exam N10-008 All Questions

View all questions & answers for the N10-008 exam

Exam N10-008 topic 1 question 232 discussion

Actual exam question from CompTIA's N10-008
Question #: 232
Topic #: 1
[All N10-008 Questions]

A technician performed a manual reconfiguration of a firewall, and network connectivity was reestablished. Some connection events that were previously sent to a syslog server are no longer being generated by the firewall. Which of the following should the technician perform to fix the issue?

  • A. Adjust the proper logging level on the new firewall.
  • B. Tune the filter for logging the severity level on the syslog server.
  • C. Activate NetFlow traffic between the syslog server and the firewall.
  • D. Restart the SNMP service running on the syslog server.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
JakeCharles
Highly Voted 1 year, 10 months ago
Selected Answer: A
The correct answer is A. Adjust the proper logging level on the new firewall. If the firewall has been manually reconfigured, it's possible that the logging level has been changed or disabled, which could explain why connection events are no longer being generated. The technician should check the logging configuration on the firewall and adjust it as necessary to ensure that the desired events are being logged.
upvoted 13 times
...
JakeCharles
Highly Voted 1 year, 10 months ago
Option B, tune the filter for logging the severity level on the syslog server, is not a valid solution to the problem described. The syslog server is responsible for receiving and storing log messages, not generating them. Option C, activating NetFlow traffic between the syslog server and the firewall, is also not a valid solution to the problem. NetFlow is a network protocol used to collect and analyze network traffic data, and has nothing to do with logging or generating log messages. Option D, restarting the SNMP service running on the syslog server, is also not a valid solution. SNMP (Simple Network Management Protocol) is a protocol used for managing and monitoring network devices, and has no bearing on the generation of log messages.
upvoted 5 times
...
agfencer
Most Recent 5 months, 1 week ago
Selected Answer: B
The question states that he is reconfiguring a firewall, so how can the correct answer be adjust proper logging on the NEW firewall when it's the same one?
upvoted 2 times
...
Mehsotopes
11 months, 3 weeks ago
Selected Answer: A
NetFlow Analyzers allow network administrators to understand the impact of application traffic on the network. For instance, they can identify unusual network loads, such as video content or large file transfers, and measure how application and policy changes affect costly WAN/SD-WAN traffic.
upvoted 1 times
...
Mehsotopes
11 months, 3 weeks ago
Selected Answer: A
Syslog can be configured to show logs at certain thresholds of severity from 7 (Debugging) to 0 (Emergency). If not set properly, you could miss certain logs/notifications that would have otherwise been important.
upvoted 1 times
...
osmaster
1 year ago
Selected Answer: B
B. Tune the filter for logging the severity level on the syslog server. If certain connection events that were previously sent to a syslog server are no longer being generated by the firewall after a manual reconfiguration, it's likely that the severity level or filter settings for those events on the syslog server were affected. You should adjust the filtering settings on the syslog server to ensure it captures the appropriate log events from the firewall. This will help reestablish the logging of the required events without having to modify the firewall's configuration.
upvoted 1 times
...
lordguck
2 years ago
B: Reason: the severe problem has been solved and the fw (old one, so no new one as stated under A) does not report those issues anymore. Hence, if the tech wants to see lower grade reports, he has to modify the filter on the syslog server. C: AFAIK Netflow data insertion into syslog needs a converter and this happens on the syslog server (correct me, if I am wrong) D: The question states, the fw does not generate the messages anymore, so restarting the daemon on the syslog server makes no sense.
upvoted 1 times
...
A_CCSI
2 years ago
Selected Answer: A
If the syslog server is no longer receiving previous messages from the firewall after changes were done to the firewall, I think it makes more sense to adjust something on the firewall so those messages get sent to the syslog server again.
upvoted 2 times
...
AaronS1990
2 years ago
Selected Answer: A
Hard to say, but first thing i would note on wbear's answer is that it's not a router he configured, it's a firewall. It said he manually reconfigured it so I think it is a "new" firewall in the sense that it has a different configuration, rather than being new in the sense that we might expect as in " fresh out of the box". Most firewalls are software after all. For me, Answers B, C, D lean towards an issue with the syslog server which has not been changed according to the information given in the question. I think the answer given (A) is simply implying they have made a mistake whilst manually configuring the firewall (which is easily done) and so they need to rectify that mistake.
upvoted 4 times
...
wbear
2 years, 1 month ago
Selected Answer: B
leaning towards. B in this case, some logging is taken place, just not all as before, this is not a new router it was a manual reconfiguration, same, device, same connections.
upvoted 1 times
...
onikafei
2 years, 1 month ago
A indicates it's a new firewall when the question doesn't State anything about a new firewall wouldn't that be the wrong answer then?
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago