hardMultiple Choice
300-410 Practice Question: Is troubleshooting a router that is not executing…
A network engineer is troubleshooting a router that is not executing an EEM applet that is supposed to run when a specific interface goes down. The applet is configured with event syslog pattern 'LINK-3-UPDOWN' and matches the interface with a regex. The engineer checks the syslog and sees the message 'LINK-3-UPDOWN: GigabitEthernet0/1, changed state to down' but the applet does not run. What is the most likely cause?
⚠ Common exam trap
The trap is assuming that EEM relies on external syslog servers or logging levels; candidates may overlook that EEM uses internal syslog and that regex must match exactly, including interface naming.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The regex pattern in the applet does not match the syslog message.
The EEM applet uses a regex pattern to match the syslog message, and if the pattern does not exactly match the interface name or the message format, the applet will not trigger. The syslog message shows 'GigabitEthernet0/1', but the regex might be expecting a different format (e.g., 'Gi0/1' or missing the full name), causing a mismatch. Therefore, the most likely cause is that the regex pattern does not match the syslog message.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The EEM applet is disabled.
Why it's wrong here
A disabled applet produces no execution regardless of pattern matching, but the stem gives no evidence of administrative shutdown, and the regex mismatch against the actual interface name is the concrete failure. Disabling is tempting because it is a common, quick cause of silent applets in lab troubleshooting.
- ✗
The syslog message is not being sent to the EEM server due to logging level restrictions.
Why it's wrong here
EEM applets consume syslog messages internally from the logging buffer, independent of console or server destinations, so logging level restrictions do not gate applet triggering. It is tempting because syslog server filtering genuinely suppresses remote logging, which would be the cause if the applet subscribed to an external syslog feed.
- ✓
The regex pattern in the applet does not match the syslog message.
Why this is correct
EEM matches the syslog pattern against the raw message text, so the regex must accommodate the actual interface string. If it expects a different format than 'GigabitEthernet0/1', the applet never triggers despite the LINK-3-UPDOWN event firing.
- ✗
The interface is not being monitored because it is a subinterface.
Why it's wrong here
EEM syslog event matching keys on the message text, not interface type; a subinterface still generates LINK-3-UPDOWN syslog messages that the pattern and regex can match. It is tempting because subinterface events can be filtered separately, but that requires explicit configuration, not automatic exclusion.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.