Courseiva

200-901 Cisco Platforms and Development Practice Question

An engineer wants to trigger an EEM applet when a specific syslog message appears. Which event detector should be used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

event syslog pattern

EEM's syslog event detector triggers on syslog messages matching a pattern.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    event timer cron

    Why it's wrong here

    The cron event detector fires on a scheduled time or calendar interval, so it cannot react to a syslog message arriving. It is tempting because cron is the standard detector for recurring maintenance tasks, but matching log output requires the syslog event detector instead.

  • ✗

    event interface

    Why it's wrong here

    The interface event detector triggers on interface state changes such as line protocol up or down, not on log text. It is tempting because interface events are common EEM triggers for link monitoring, but a syslog message requires the syslog event detector to match the pattern.

  • ✗

    event cli pattern

    Why it's wrong here

    The cli pattern detector matches commands typed at the CLI, not syslog output generated by the device. It is tempting because pattern matching sounds applicable, but it watches interactive command input; the syslog event detector is what matches incoming log messages.

  • ✓

    event syslog pattern

    Why this is correct

    The event syslog pattern detector matches incoming syslog messages against a regular expression, triggering the applet when the specified text appears. This directly satisfies the requirement to react to a specific syslog message rather than a timer or interface event.

About these practice questions

Courseiva writes every 200-901 question from scratch — 975 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.