CCNP Network Assurance Practice Question
A network engineer is troubleshooting a routing loop between two OSPF areas. To verify the path that packets are taking, the engineer decides to use the Cisco IOS Embedded Event Manager (EEM) to generate a syslog message when the OSPF neighbor state changes. Which EEM applet configuration is required to trigger on the OSPF neighbor state change?
⚠ Common exam trap
Many exam-takers confuse the CLI event detector with the syslog event detector; the CLI detector triggers on command input, not on syslog messages.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
event tag ospf-neighbor syslog pattern "%OSPF-5-ADJCHG"
The correct configuration uses a syslog event detector to match the OSPF adjacency change message. When OSPF neighbor state changes, the router generates a %OSPF-5-ADJCHG syslog message. An EEM applet with a syslog event detector and the appropriate pattern will trigger actions based on that message. This provides immediate, event-driven monitoring without polling. The other options either use inappropriate event detectors or incorrect syntax for this purpose.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
event tag ospf-neighbor timer watchdog time 60
Why it's wrong here
This applet uses a timer event detector that triggers every 60 seconds. It does not specifically react to OSPF neighbor state changes; it would run periodically regardless of OSPF events. This is useful for periodic tasks, but not for event-driven monitoring of OSPF adjacencies. The engineer needs immediate notification, so a timer is inappropriate.
- ✗
event tag ospf-neighbor cli pattern "show ip ospf neighbor"
Why it's wrong here
This applet uses a CLI event detector that triggers when the command output matches a pattern. However, the CLI event detector is used to trigger on command-line input, not on the output of show commands. To monitor OSPF neighbor states, the engineer would need to poll with a timer and parse the output, which is more complex and not event-driven. This is not a valid trigger for OSPF state changes.
- ✓
event tag ospf-neighbor syslog pattern "%OSPF-5-ADJCHG"
Why this is correct
This applet uses a syslog event detector that matches the OSPF adjacency change syslog message. When the router logs a %OSPF-5-ADJCHG message, the EEM applet triggers. This is a common method to monitor OSPF neighbor state changes without polling. The pattern must match the exact syslog text, and the tag is used to associate actions.
- ✗
event tag ospf-neighbor snmp oid 1.3.6.1.2.1.14.10.1.6
Why it's wrong here
This applet uses an SNMP event detector to poll the OSPF neighbor state OID. While SNMP can monitor OSPF, it requires SNMP configuration and polling, which is not as immediate as syslog. The OID 1.3.6.1.2.1.14.10.1.6 corresponds to ospfNbrState, but triggering on SNMP traps for state changes would require the router to send traps, not an EEM SNMP event. This is not the typical way to trigger on OSPF state changes.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.