Courseiva
mediumMultiple Choice

300-410 Practice Question: Runs the following command on Router R1: R1# show…

A network engineer runs the following command on Router R1:

R1# show event manager policy registered

No. Type Time Created Name 1 applet 00:01:23 UTC Mar 1 2025 BGP_Session_Reset

R1# show event manager history events

Event History: No. Time Type Name 1 00:02:00 UTC Mar 1 syslog BGP_Session_Reset 2 00:02:05 UTC Mar 1 syslog BGP_Session_Reset 3 00:02:10 UTC Mar 1 syslog BGP_Session_Reset

Based on this output, which statement is correct?

⚠ Common exam trap

The trap is misreading the output as showing a single event or assuming the policy is inactive — candidates must count the history entries and correlate them with the policy name to determine frequency.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The BGP session reset event has occurred three times.

The 'show event manager history events' output lists three syslog events with the name BGP_Session_Reset, indicating that the EEM policy has triggered three times. Each entry corresponds to an event occurrence, so the BGP session reset event has occurred three times. This is a direct interpretation of the event history output.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The BGP session reset event has occurred three times.

    Why this is correct

    The history table lists three syslog-triggered entries for the BGP_Session_Reset applet, each timestamped five seconds apart, confirming the policy fired three separate times. The registered-policy output only confirms the applet exists, so the event count must come from the history events, which records three occurrences.

  • ✗

    The EEM policy is not triggering any events.

    Why it's wrong here

    The applet is registered and has triggered three syslog events, so claiming no events fire contradicts the history output. It is tempting because an applet with no configured trigger genuinely sits idle, and that is the scenario where this statement would hold — but here the syslog entries prove activation.

  • ✗

    The BGP session is stable.

    Why it's wrong here

    The applet is registered and firing repeatedly, so the session is not stable. The history shows three syslog-triggered executions within ten seconds, indicating a recurring reset condition rather than a settled adjacency. A stable session would produce no repeated policy invocations; this option ignores the event history entirely.

  • ✗

    The EEM policy is disabled.

    Why it's wrong here

    A disabled policy would not appear as registered and would generate no history entries; three syslog events confirm it is active. This would be correct only if the policy had been removed or unregistered from the event manager.

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 300-410

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A network engineer runs the following command on Router R1: R1# show event manager policy registered No. Type Time Created Name 1 applet 00:01:23 UTC Mar 1 2025 EIGRP_Neighbor_Down R1# show event manager history events Event History: No. Time Type Name 1 00:01:30 UTC Mar 1 syslog EIGRP_Neighbor_Down Based on this output, which statement is correct?

easy
  • ✓ A.The EIGRP neighbor down event has occurred once.
  • B.The EIGRP neighbor is currently down.
  • C.The EEM policy is disabled.
  • D.The EIGRP neighbor is flapping.

Why A: The 'show event manager history events' output lists exactly one syslog event matching the EIGRP_Neighbor_Down policy, indicating the event fired once. The registered policy confirms the applet exists and is active, so the single history entry means the trigger has occurred one time.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.