300-410 Embedded Event Manager (EEM) • Complete Question Bank
Complete 300-410 Embedded Event Manager (EEM) question bank — all 0 questions with answers and detailed explanations.
A network engineer runs the following command on Router R1:
R1# show event manager policy registered
No. Type Time Created Name 1 applet 00:01:23 UTC Mar 1 2025 EIGRP_Neighbor_Down 2 applet 00:01:23 UTC Mar 1 2025 OSPF_Neighbor_Flap
Based on this output, which statement is correct?
A network engineer runs the following command on Router R1:
R1# show event manager history events
Event History: No. Time Type Name 1 00:01:30 UTC Mar 1 syslog EIGRP_Neighbor_Down 2 00:01:31 UTC Mar 1 syslog OSPF_Neighbor_Flap 3 00:01:32 UTC Mar 1 syslog EIGRP_Neighbor_Down 4 00:01:33 UTC Mar 1 syslog OSPF_Neighbor_Flap
Based on this output, what is the most likely problem?
A network engineer runs the following command on Router R1:
R1# show event manager policy registered
No. Type Time Created Name 1 applet 00:01:23 UTC Mar 1 2025 BGP_Session_Reset
R1# show event manager history events
Event History: No. Time Type Name 1 00:02:00 UTC Mar 1 syslog BGP_Session_Reset 2 00:02:05 UTC Mar 1 syslog BGP_Session_Reset 3 00:02:10 UTC Mar 1 syslog BGP_Session_Reset
Based on this output, which statement is correct?
A network engineer runs the following command on Router R1:
R1# show event manager policy registered
No. Type Time Created Name 1 applet 00:01:23 UTC Mar 1 2025 OSPF_Neighbor_Down
R1# show ip ospf neighbor Neighbor ID Pri State Dead Time Address Interface 10.1.1.2 1 FULL/DR 00:00:36 192.168.1.2 GigabitEthernet0/0
Based on this output, what is the most likely conclusion?
A network engineer runs the following command on Router R1:
R1# show event manager policy registered
No. Type Time Created Name 1 applet 00:01:23 UTC Mar 1 2025 BGP_Neighbor_Down
R1# show bgp summary
BGP router identifier 10.0.0.1, local AS number 65001 BGP table version is 1, main routing table version 1
Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd 192.168.1.2 4 65002 5 5 1 0 0 00:02:00 Established
Based on this output, which statement is correct?
A network engineer runs the following command on Router R1:
R1# show event manager policy registered
No. Type Time Created Name 1 applet 00:01:23 UTC Mar 1 2025 EIGRP_Neighbor_Down
R1# show ip eigrp neighbors
IP-EIGRP neighbors for process 100 H Address Interface Hold Uptime SRTT RTO Q Seq (sec) (ms) Cnt Num 0 192.168.1.2 Gi0/0 13 00:02:00 40 200 0 5
Based on this output, what is the most likely problem?
A network engineer runs the following command on Router R1:
R1# show event manager history events
Event History: No. Time Type Name 1 00:01:30 UTC Mar 1 syslog OSPF_Neighbor_Down 2 00:01:31 UTC Mar 1 syslog OSPF_Neighbor_Up 3 00:01:32 UTC Mar 1 syslog OSPF_Neighbor_Down 4 00:01:33 UTC Mar 1 syslog OSPF_Neighbor_Up
Based on this output, which statement is correct?
A network engineer runs the following command on Router R1:
R1# show event manager policy registered
No. Type Time Created Name 1 applet 00:01:23 UTC Mar 1 2025 EIGRP_Neighbor_Down
R1# show event manager history events
Event History: No. Time Type Name 1 00:01:30 UTC Mar 1 syslog EIGRP_Neighbor_Down
Based on this output, which statement is correct?
A network engineer runs the following command on Router R1:
R1# show event manager policy registered
No. Type Time Created Name 1 applet 00:01:23 UTC Mar 1 2025 BGP_Neighbor_Down
R1# show bgp neighbors 192.168.1.2
BGP neighbor is 192.168.1.2, remote AS 65002, external link BGP version 4, remote router ID 10.0.0.2 BGP state = Idle Last read 00:00:05, hold time is 180, keepalive interval is 60 seconds
Neighbor sessions:
1 active, is not multisession capable
Based on this output, what is the most likely conclusion?
Consider the following EEM applet configuration:
!--- event manager applet CHECK_OSPF event syslog pattern "OSPF-5-ADJCHG" action 1.0 cli command "enable" action 2.0 cli command "show ip ospf neighbor" action 3.0 mail server "smtp.example.com" to "admin@example.com" from "router@example.com" subject "OSPF Adjacency Change" body "An OSPF adjacency change has been detected." !---
What is the effect of this configuration?
Examine the following EEM applet configuration:
!--- event manager applet LOGIN_ALERT event syslog occurs 1 period 60 action 1.0 syslog msg "Login event detected" !---
What is the problem with this configuration?
Consider the following EEM applet configuration:
!--- event manager applet INTERFACE_DOWN event syslog pattern "%LINEPROTO-5-UPDOWN" action 1.0 if $syslog_severity eq 5 action 2.0 cli command "enable" action 3.0 cli command "clear counters" !---
What will happen when a syslog message matching the pattern is generated?
Examine the following EEM applet configuration:
!--- event manager applet BACKUP_CONFIG event timer watchdog time 86400 action 1.0 cli command "enable" action 2.0 cli command "copy running-config tftp://192.168.1.100/backup.cfg" !---
What is the effect of this configuration?
Consider the following EEM applet configuration:
!--- event manager applet HIGH_CPU event snmp oid 1.3.6.1.4.1.9.9.109.1.1.1.1.3.1 get-type exact entry-op gt entry-val 90 poll-interval 10 action 1.0 syslog msg "CPU utilization exceeded 90%" !---
What is the problem with this configuration?
Examine the following EEM applet configuration:
!--- event manager applet RELOAD_NOTIFY event syslog pattern "%SYS-5-RELOAD" action 1.0 cli command "enable" action 2.0 cli command "send log "Router is reloading"" !---
What is the effect of this configuration?
A network engineer runs the following command to troubleshoot an EEM issue:
R1# show event manager policy registered
No. Class Type Version Time Created Name 1 applet system 1.0 Mar 1 00:00:12 2025 TRACK-INTERFACE 2 applet system 1.0 Mar 1 00:00:15 2025 BGP-RESET 3 applet user 1.0 Mar 1 00:02:30 2025 LOG-ERROR
What does this output indicate?
A network engineer runs the following command to troubleshoot an EEM issue:
R1# show event manager history events
Event History: Event Type : syslog Time : Mar 1 00:05:23 Pattern : OSPF-5-ADJCHG Trigger count : 1
Event Type : timer Time : Mar 1 00:06:00 Timer Type : absolute Timer Name : MY-TIMER Trigger count : 1
What does this output indicate?
A network engineer runs the following command to troubleshoot an EEM issue:
R1# debug event manager action cli
EEM Action CLI debugging is on
R1#
Mar 1 00:10:15.123: %HA_EM-6-ACTION: applet TRACK-INTERFACE: action cli command: 'show ip int brief' executed Mar 1 00:10:15.456: %HA_EM-6-ACTION: applet TRACK-INTERFACE: action cli output: 'Interface IP-Address OK? Method Status Protocol
GigabitEthernet0/0 192.168.1.1 YES NVRAM up up GigabitEthernet0/1 10.0.0.1 YES NVRAM up up Loopback0 1.1.1.1 YES NVRAM up up'
What does this output indicate?
A network engineer runs the following command to troubleshoot an EEM issue:
R1# show event manager policy active
No. Class Type Version Time Created Name 1 applet system 1.0 Mar 1 00:00:12 2025 TRACK-INTERFACE Event Type: syslog (pattern OSPF-5-ADJCHG) Action: cli command 'show ip route'
What does this output indicate?
A network engineer runs the following command to troubleshoot an EEM issue:
R1# show event manager environment all
No. Variable Name Value 1 _exit_status 1 2 _event_type syslog 3 _syslog_msg %OSPF-5-ADJCHG: Process 1, Nbr 10.0.0.2 on GigabitEthernet0/0 from LOADING to FULL, Loading Done 4 _syslog_severity 5 5 _syslog_facility OSPF 6 _syslog_mnemonic ADJCHG
What does this output indicate?
A network engineer runs the following command to troubleshoot an EEM issue:
R1# show event manager history applet TRACK-INTERFACE
Applet TRACK-INTERFACE: Time Created : Mar 1 00:00:12 2025 Time Last Triggered : Mar 1 00:15:30 2025 Time Last Executed : Mar 1 00:15:30 2025 Trigger Count : 5 Execution Count : 5 Last Event Type : syslog Last Event Detail : OSPF-5-ADJCHG Last Action Executed : show ip route Last Action Result : Success
What does this output indicate?
A network engineer runs the following command to troubleshoot an EEM issue:
R1# show event manager detector
Detector Name : syslog Detector Type : system Detector State : enabled Detector Queue Size : 100 Detector Queue Max : 200 Detector Events Triggered : 15
Detector Name : timer Detector Type : system Detector State : enabled Detector Queue Size : 0 Detector Queue Max : 50 Detector Events Triggered : 3
What does this output indicate?
A network engineer runs the following command to troubleshoot an EEM issue:
R1# show event manager policy configuration TRACK-INTERFACE
Applet TRACK-INTERFACE event syslog pattern "OSPF-5-ADJCHG" action 1.0 cli command "show ip route" action 2.0 cli command "show ip ospf neighbor" action 3.0 syslog msg "OSPF adjacency change detected"
What does this output indicate?
A network engineer runs the following command to troubleshoot an EEM issue:
R1# debug event manager action syslog
EEM Action Syslog debugging is on
R1#
Mar 1 00:20:45.789: %HA_EM-6-ACTION: applet TRACK-INTERFACE: action syslog msg: 'OSPF adjacency change detected'
What does this output indicate?