Courseiva
Network Assurance →mediumMultiple Choice

CCNP Network Assurance Practice Question

A network engineer is troubleshooting a routing loop between two OSPF areas. To verify the path that packets are taking, the engineer decides to use the Cisco IOS Embedded Event Manager (EEM) to generate a syslog message when the OSPF neighbor state changes. Which EEM applet configuration is required to trigger on the OSPF neighbor state change?

⚠ Common exam trap

Many exam-takers confuse the CLI event detector with the syslog event detector; the CLI detector triggers on command input, not on syslog messages.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

event tag ospf-neighbor syslog pattern "%OSPF-5-ADJCHG"

The correct configuration uses a syslog event detector to match the OSPF adjacency change message. When OSPF neighbor state changes, the router generates a %OSPF-5-ADJCHG syslog message. An EEM applet with a syslog event detector and the appropriate pattern will trigger actions based on that message. This provides immediate, event-driven monitoring without polling. The other options either use inappropriate event detectors or incorrect syntax for this purpose.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    event tag ospf-neighbor timer watchdog time 60

    Why it's wrong here

    This applet uses a timer event detector that triggers every 60 seconds. It does not specifically react to OSPF neighbor state changes; it would run periodically regardless of OSPF events. This is useful for periodic tasks, but not for event-driven monitoring of OSPF adjacencies. The engineer needs immediate notification, so a timer is inappropriate.

  • ✗

    event tag ospf-neighbor cli pattern "show ip ospf neighbor"

    Why it's wrong here

    This applet uses a CLI event detector that triggers when the command output matches a pattern. However, the CLI event detector is used to trigger on command-line input, not on the output of show commands. To monitor OSPF neighbor states, the engineer would need to poll with a timer and parse the output, which is more complex and not event-driven. This is not a valid trigger for OSPF state changes.

  • ✓

    event tag ospf-neighbor syslog pattern "%OSPF-5-ADJCHG"

    Why this is correct

    This applet uses a syslog event detector that matches the OSPF adjacency change syslog message. When the router logs a %OSPF-5-ADJCHG message, the EEM applet triggers. This is a common method to monitor OSPF neighbor state changes without polling. The pattern must match the exact syslog text, and the tag is used to associate actions.

  • ✗

    event tag ospf-neighbor snmp oid 1.3.6.1.2.1.14.10.1.6

    Why it's wrong here

    This applet uses an SNMP event detector to poll the OSPF neighbor state OID. While SNMP can monitor OSPF, it requires SNMP configuration and polling, which is not as immediate as syslog. The OID 1.3.6.1.2.1.14.10.1.6 corresponds to ospfNbrState, but triggering on SNMP traps for state changes would require the router to send traps, not an EEM SNMP event. This is not the typical way to trigger on OSPF state changes.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.