Courseiva
mediumMultiple Choice

300-410 Practice Question: Runs the following command to troubleshoot an EEM…

A network engineer runs the following command to troubleshoot an EEM issue:

R1# show event manager policy registered

No. Class Type Version Time Created Name 1 applet system 1.0 Mar 1 00:00:12 2025 TRACK-INTERFACE 2 applet system 1.0 Mar 1 00:00:15 2025 BGP-RESET 3 applet user 1.0 Mar 1 00:02:30 2025 LOG-ERROR

What does this output indicate?

⚠ Common exam trap

300-410 often tests the ability to interpret EEM output fields — candidates may misread the 'Type' column (system vs. user) and incorrectly count the number of user-defined applets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Three EEM applets are registered, including two system-defined and one user-defined.

The 'show event manager policy registered' output lists three EEM applets: TRACK-INTERFACE and BGP-RESET are of class 'applet' and type 'system', meaning they are system-defined (built-in) applets, while LOG-ERROR is of type 'user', meaning it was created by an administrator. Therefore, the output indicates two system-defined and one user-defined applet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Three EEM applets are registered, including two system-defined and one user-defined.

    Why this is correct

    The Class column shows three applets, and the Type column marks two as system and one as user. That combination confirms three registered EEM applets comprising two system-defined and one user-defined policy, exactly as the option describes.

  • ✗

    Three EEM applets are registered, all user-defined.

    Why it's wrong here

    Only LOG-ERROR shows Type 'user'; the other two are 'system', so the claim that all three are user-defined contradicts the Type column. The Type field is the right column to read, and it would confirm all user-defined applets only if every row displayed 'user'.

  • ✗

    Three EEM applets are registered, all system-defined.

    Why it's wrong here

    The Type column reads 'system' for TRACK-INTERFACE and BGP-RESET but 'user' for LOG-ERROR, so only two applets are system-defined. The Type field is tempting because it does record who registered each policy, and a listing where every row showed 'system' would indeed mean all were system-defined.

  • ✗

    The output shows the EEM applets that are currently executing.

    Why it's wrong here

    This command lists registered policies and their attributes; it reports no execution state, and the Up/Down-style runtime data lives elsewhere. Registration output is tempting because it is the standard EEM verification command, and it would be the correct choice when confirming which policies are registered rather than which are running.

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 300-410

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A network engineer runs the following command on Router R1: R1# show event manager policy registered No. Type Time Created Name 1 applet 00:01:23 UTC Mar 1 2025 EIGRP_Neighbor_Down 2 applet 00:01:23 UTC Mar 1 2025 OSPF_Neighbor_Flap Based on this output, which statement is correct?

medium
  • ✓ A.Two EEM applet policies are registered and active.
  • B.Two EEM applet policies are registered but disabled.
  • C.Only one EEM applet policy is registered.
  • D.The EEM applet policies are triggered by syslog events.

Why A: The output of 'show event manager policy registered' lists two applet policies: EIGRP_Neighbor_Down and OSPF_Neighbor_Flap. The command displays registered policies, and by default, these are active unless explicitly disabled. The output does not indicate they are disabled, so they are active.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.