Courseiva
hardMultiple Choice

300-410 Practice Question: An engineer configures an EEM applet to react to…

An engineer configures an EEM applet to react to BGP prefix changes using the event syslog pattern 'BGP-5-ADJCHANGE'. The applet sends a custom SNMP trap. The BGP session between two routers is established, but when a route is withdrawn due to next-hop-self requirement for iBGP, the EEM applet does not trigger. Which is the most likely explanation?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The BGP-5-ADJCHANGE syslog is only generated for session state changes, not for individual route updates.

The BGP-5-ADJCHANGE syslog message is generated only when the BGP session state changes (e.g., from Established to Idle or vice versa). It is not generated for individual prefix updates or withdrawals. When a route is withdrawn due to next-hop-self requirement, the BGP session remains established, so no ADJCHANGE event occurs. The EEM applet will not trigger because the syslog pattern does not match any generated message.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The BGP-5-ADJCHANGE syslog is only generated for session state changes, not for individual route updates.

    Why this is correct

    The BGP-5-ADJCHANGE syslog fires only on neighbour session state transitions (Idle, Active, Established), not on prefix withdrawal or next-hop-self route changes. Since the session stayed established, no syslog event was generated, so the EEM applet's pattern match never triggered.

  • ✗

    The EEM applet must be configured with 'event bgp' to monitor BGP prefix changes.

    Why it's wrong here

    EEM has no 'event bgp' trigger; BGP monitoring relies on syslog patterns such as BGP-5-ADJCHANGE, which fires on neighbour state changes, not prefix withdrawals. It is tempting because a dedicated BGP event seems logical, but no such event exists in IOS EEM.

  • ✗

    The next-hop-self requirement causes a BGP notification that generates a different syslog pattern.

    Why it's wrong here

    A next-hop-self change alters the path attribute and triggers a prefix update or withdrawal, not a BGP notification, so no BGP-5-ADJCHANGE syslog is generated. It is tempting because notifications do produce syslog messages, but they signal session errors, not route changes.

  • ✗

    The EEM applet requires the 'event manager directory' to be set for SNMP traps.

    Why it's wrong here

    The 'event manager directory' command only sets the working directory for EEM policy files and Tcl scripts; it has no bearing on SNMP trap delivery. It is tempting because EEM applets that write files or run scripts do require a directory, but here the applet never fires, so the syslog pattern itself is the issue.

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.