hardMultiple Choice
300-410 Practice Question: Is troubleshooting a router that is not…
A network engineer is troubleshooting a router that is not generating any EEM applet actions even though the applets are configured and enabled. The engineer checks the 'show event manager status' command and sees that the EEM server is running. The engineer also checks the syslog and sees that the trigger events are occurring. What is the most likely cause?
⚠ Common exam trap
The trap is assuming the EEM server or logging is at fault; the exam tests whether you know that syntax errors silently prevent applet registration, so you must verify with 'show event manager policy registered'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The EEM applets are not registered due to a syntax error in the configuration.
If EEM applets are configured and enabled but not triggering despite events occurring, the most likely cause is that the applets failed to register due to a syntax error in the configuration. EEM applets must be successfully parsed and registered with the EEM server; a syntax error prevents registration, so the applet never runs. The engineer should check 'show event manager policy registered' to confirm.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The EEM applets are not registered due to a syntax error in the configuration.
Why this is correct
EEM applets with configuration syntax errors fail to register with the EEM server, so no actions fire despite the server running and trigger events appearing in syslog. Registration failure is the specific mechanism that explains silent applets, distinguishing it from a stopped server or missing event detectors.
- ✗
The EEM server is not listening for syslog events.
Why it's wrong here
The EEM server already runs and processes events; syslog triggers are firing, so the server is listening. This option confuses the transport with the actual fault. Disabling syslog event reception is a deliberate configuration choice, correct only when you want EEM to ignore syslog and rely solely on SNMP or CLI triggers.
- ✗
The router's logging level is set to emergencies only.
Why it's wrong here
Syslog already shows the trigger events occurring, so logging severity is not suppressing them; EEM reacts to events that reach the log. Restricting logging to emergencies is a deliberate hardening measure, correct when minimising log volume on a device, not when diagnosing missing applet actions.
- ✗
The EEM applets are configured with 'event none' and need manual triggering.
Why it's wrong here
An applet registered with 'event none' never fires from a trigger, yet the stem confirms trigger events are occurring, so this contradicts the observed syslog. It is tempting because 'event none' does exist for manual applets, and would be correct if no trigger events were being logged at all.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.