Courseiva
hardMultiple Choice

300-410 Practice Question: Runs the following command on Router R1: R1# show…

A network engineer runs the following command on Router R1:

R1# show event manager history events

Event History: No. Time Type Name 1 00:01:30 UTC Mar 1 syslog EIGRP_Neighbor_Down 2 00:01:31 UTC Mar 1 syslog OSPF_Neighbor_Flap 3 00:01:32 UTC Mar 1 syslog EIGRP_Neighbor_Down 4 00:01:33 UTC Mar 1 syslog OSPF_Neighbor_Flap

Based on this output, what is the most likely problem?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The router is experiencing network instability causing repeated neighbor state changes.

The 'show event manager history events' command shows the last triggered events. The output shows repeated syslog events for EIGRP neighbor down and OSPF neighbor flap within a short timeframe, indicating a flapping condition. The correct answer is that the router is experiencing network instability causing repeated neighbor state changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The EEM policies are not configured correctly.

    Why it's wrong here

    The history lists syslog events that EEM detected, proving policies are registered and running; misconfiguration would show missing or malformed entries. EEM policy misconfiguration is the right diagnosis when applets fail to trigger or actions do not fire, not when events are logged correctly.

  • ✓

    The router is experiencing network instability causing repeated neighbor state changes.

    Why this is correct

    Repeated EIGRP and OSPF neighbour down and flap events within seconds indicate the routing adjacencies are repeatedly resetting. That pattern reflects underlying network instability, such as link flapping or interface errors, rather than a configuration or authentication fault.

  • ✗

    The EEM applet policies are disabled.

    Why it's wrong here

    Disabled applets would not appear as detected events; the history shows EEM actively matching and recording syslog entries, so policies are enabled. Disabled applets are the correct diagnosis when configured policies exist but no events are captured or actions executed.

  • ✗

    The syslog server is not reachable.

    Why it's wrong here

    EEM records events locally in its history buffer regardless of remote syslog reachability, so the populated list does not indicate an unreachable server. An unreachable syslog server is the correct diagnosis when local logging works but no messages arrive at the collector.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 300-410

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A network engineer runs the following command on Router R1: R1# show event manager history events Event History: No. Time Type Name 1 00:01:30 UTC Mar 1 syslog OSPF_Neighbor_Down 2 00:01:31 UTC Mar 1 syslog OSPF_Neighbor_Up 3 00:01:32 UTC Mar 1 syslog OSPF_Neighbor_Down 4 00:01:33 UTC Mar 1 syslog OSPF_Neighbor_Up Based on this output, which statement is correct?

medium
  • A.The OSPF neighbor is stable.
  • ✓ B.The OSPF neighbor is flapping.
  • C.The EEM policy is not configured.
  • D.The OSPF neighbor is down permanently.

Why B: The event history shows the OSPF neighbor transitioning Down → Up → Down → Up within a four-second window, which is the textbook signature of an unstable adjacency. Rapid repeated state changes indicate the neighbor relationship is flapping rather than being stable or permanently down.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.