Courseiva
easyMultiple Choice

300-410 Practice Question: Is troubleshooting a router that is sending…

A network engineer is troubleshooting a router that is sending duplicate SNMP traps for interface state changes. The engineer finds two EEM applets that both trigger on the same syslog pattern 'LINK-3-UPDOWN' and both send SNMP traps. What should the engineer do to resolve the duplicate traps?

⚠ Common exam trap

The trap is that candidates try to suppress symptoms (disable logging, change destination, increase queue) instead of identifying the root cause — two EEM applets triggering on the same syslog pattern.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Remove one of the duplicate EEM applets.

Duplicate SNMP traps are being generated because two EEM applets are both triggered by the same syslog pattern and both execute an SNMP trap action. Removing one of the duplicate applets eliminates the redundant trigger and restores a single trap per event. This is the direct, root-cause fix.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable syslog logging for interface state changes.

    Why it's wrong here

    Disabling syslog logging for interface state changes suppresses the 'LINK-3-UPDOWN' messages that both EEM applets match, silencing the traps entirely rather than removing the duplicate. The fix is to delete or disable one redundant applet. Syslog logging is correctly disabled when message volume must be reduced, not to resolve overlapping EEM triggers.

  • ✓

    Remove one of the duplicate EEM applets.

    Why this is correct

    Both EEM applets match the same LINK-3-UPDOWN syslog pattern and each fires an SNMP trap, so the duplication stems from redundant applet definitions. Removing one applet eliminates the second trap source while preserving the remaining applet's notification behaviour.

  • ✗

    Change the SNMP trap destination to a different host for one applet.

    Why it's wrong here

    Redirecting one applet's trap destination still fires both traps, so the duplicate SNMP notifications persist; only the receiving host changes. The engineer must remove or disable one of the two overlapping EEM applets. Trap destination configuration is legitimately used to fan alerts out to multiple management stations, not to deduplicate identical events.

  • ✗

    Increase the SNMP trap queue size.

    Why it's wrong here

    The duplication stems from two EEM applets matching the same syslog pattern and each firing a trap; enlarging the trap queue only buffers more messages and cannot remove the redundant trigger. Queue sizing would be the right fix when traps are dropped because the buffer overflows under high event volume.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.