Courseiva
mediumMultiple Choice

300-410 Practice Question: Runs the following command on Router R1: R1# show…

A network engineer runs the following command on Router R1:

R1# show event manager history events

Event History: No. Time Type Name 1 00:01:30 UTC Mar 1 syslog OSPF_Neighbor_Down 2 00:01:31 UTC Mar 1 syslog OSPF_Neighbor_Up 3 00:01:32 UTC Mar 1 syslog OSPF_Neighbor_Down 4 00:01:33 UTC Mar 1 syslog OSPF_Neighbor_Up

Based on this output, which statement is correct?

⚠ Common exam trap

The trap is reading the alternating Down/Up entries as two separate stable events rather than recognizing the rapid oscillation pattern that defines flapping.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The OSPF neighbor is flapping.

The event history shows the OSPF neighbor transitioning Down → Up → Down → Up within a four-second window, which is the textbook signature of an unstable adjacency. Rapid repeated state changes indicate the neighbor relationship is flapping rather than being stable or permanently down.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The OSPF neighbor is stable.

    Why it's wrong here

    Four state transitions within three seconds show the adjacency flapping, not stable operation; a stable neighbour would produce no down/up pairs. It is tempting because up events appear in the log, but the interleaved downs contradict stability. This option would be correct if the history showed only an initial up event with no subsequent downs.

  • ✓

    The OSPF neighbor is flapping.

    Why this is correct

    The repeated Down/Up pairs one second apart show the adjacency repeatedly failing and re-forming, which is the definition of flapping. The event history records syslog events triggered by the Embedded Event Manager, confirming the neighbour state changes occurred rather than a single transient drop.

  • ✗

    The EEM policy is not configured.

    Why it's wrong here

    The history table lists four syslog events, which proves EEM is registered and detecting OSPF state changes; an unconfigured policy would show no entries. It is tempting because an empty history does indicate no EEM applets, but here events exist. This option would be right if the output showed no events at all.

  • ✗

    The OSPF neighbor is down permanently.

    Why it's wrong here

    The final entry shows OSPF_Neighbor_Up, so the adjacency is currently established, not permanently down; the log records flapping rather than a persistent failure. It is tempting because down events dominate the sequence, but the last event governs current state. This option would be correct if the most recent entry were OSPF_Neighbor_Down with no recovery.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.