hardMultiple Choice
300-410 Practice Question: Runs the following command on Router R1: R1# show…
A network engineer runs the following command on Router R1:
R1# show event manager history events
Event History: No. Time Type Name 1 00:01:30 UTC Mar 1 syslog EIGRP_Neighbor_Down 2 00:01:31 UTC Mar 1 syslog OSPF_Neighbor_Flap 3 00:01:32 UTC Mar 1 syslog EIGRP_Neighbor_Down 4 00:01:33 UTC Mar 1 syslog OSPF_Neighbor_Flap
Based on this output, what is the most likely problem?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The router is experiencing network instability causing repeated neighbor state changes.
The 'show event manager history events' command shows the last triggered events. The output shows repeated syslog events for EIGRP neighbor down and OSPF neighbor flap within a short timeframe, indicating a flapping condition. The correct answer is that the router is experiencing network instability causing repeated neighbor state changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The EEM policies are not configured correctly.
Why it's wrong here
The history lists syslog events that EEM detected, proving policies are registered and running; misconfiguration would show missing or malformed entries. EEM policy misconfiguration is the right diagnosis when applets fail to trigger or actions do not fire, not when events are logged correctly.
- ✓
The router is experiencing network instability causing repeated neighbor state changes.
Why this is correct
Repeated EIGRP and OSPF neighbour down and flap events within seconds indicate the routing adjacencies are repeatedly resetting. That pattern reflects underlying network instability, such as link flapping or interface errors, rather than a configuration or authentication fault.
- ✗
The EEM applet policies are disabled.
Why it's wrong here
Disabled applets would not appear as detected events; the history shows EEM actively matching and recording syslog entries, so policies are enabled. Disabled applets are the correct diagnosis when configured policies exist but no events are captured or actions executed.
- ✗
The syslog server is not reachable.
Why it's wrong here
EEM records events locally in its history buffer regardless of remote syslog reachability, so the populated list does not indicate an unreachable server. An unreachable syslog server is the correct diagnosis when local logging works but no messages arrive at the collector.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 300-410
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A network engineer runs the following command on Router R1: R1# show event manager history events Event History: No. Time Type Name 1 00:01:30 UTC Mar 1 syslog OSPF_Neighbor_Down 2 00:01:31 UTC Mar 1 syslog OSPF_Neighbor_Up 3 00:01:32 UTC Mar 1 syslog OSPF_Neighbor_Down 4 00:01:33 UTC Mar 1 syslog OSPF_Neighbor_Up Based on this output, which statement is correct?
medium- A.The OSPF neighbor is stable.
- ✓ B.The OSPF neighbor is flapping.
- C.The EEM policy is not configured.
- D.The OSPF neighbor is down permanently.
Why B: The event history shows the OSPF neighbor transitioning Down → Up → Down → Up within a four-second window, which is the textbook signature of an unstable adjacency. Rapid repeated state changes indicate the neighbor relationship is flapping rather than being stable or permanently down.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.