Certification793 problems· 22 reviewed

CCNA

793 incident response problems that help with CCNA prep.

All problems (793)

NETWORK-013IPv6 precedence slows connections for only some clientsIPv6 precedence slows connections for only some clients is a hands-on troubleshooting drill. A situation in a dual-stack environment where poor IPv6 path quality causes connection delays for only certain users. Firewall and Proxy Paths needs to be checked by narrowing scope, r...NetworkAdvanced26 minProNETWORK-016Packets arrive, but new connections fail due to conntrack table saturationA situation where the firewall and network are alive but new sessions cannot open due to the kernel connection-tracking limit.NetworkAdvanced29 minProNETWORK-1559A WAN failover drill succeeds and one branch still blackholes return trafficOne branch blackholes return traffic only after a failover drill.NetworkAdvanced12 minProNETWORK-1351A Cloudflare Tunnel app stays reachable and WebSocket upgrades failA Cloudflare Tunnel app stays reachable and WebSocket upgrades fail focuses on protocol-interoperability and asks the reader to isolate the key signal in NGINX. Realtime failures behind proxies often come from route-specific header handling r...NetworkAdvanced15 minProNETWORK-1328A Cloudflare Tunnel WebSocket path flakes only on one serviceA service behind Tunnel is healthy for ordinary requests and only its real-time channel fails intermittently after a proxy change.NetworkAdvanced15 minProNETWORK-1339A Tunnel and WARP path look healthy and one internal app still failsA Tunnel and WARP path look healthy and one internal app still fails focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Identity headers can be lost after the edge if internal proxy routing is not exp...NetworkAdvanced15 minProNETWORK-1397An MLAG pair carries normal traffic and a disaster-recovery test failsAn MLAG pair carries normal traffic and a disaster-recovery test fails focuses on cluster-maintenance and asks the reader to isolate the key signal in Cisco. Recovery paths can drift silently because they are invisible during steady-state operation.NetworkAdvanced15 minProNETWORK-1387An MLAG pair looks stable and one VLAN blackholes east-west trafficAn MLAG pair looks stable and one VLAN blackholes east-west traffic focuses on incident-response and asks the reader to isolate the key signal in Cisco. Native VLAN drift hides until an untagged recovery path is the only path left.NetworkAdvanced15 minProNETWORK-1349An NGINX auth flow works for normal pages and Cloudflare Access headers...An NGINX auth flow works for normal pages and Cloudflare Access headers... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Identity loss behind a proxy often happens on local rewrites long after...NetworkAdvanced15 minProNETWORK-154A management VRF can reach the TACACS server, but the source interface changed after a chassis swap and the AAA server rejects the unknown client addressReachability exists, yet trust is anchored to a previous device identity.NetworkAdvanced16 minProNETWORK-1287A BFD-assisted routing failover flaps repeatedlyFast failover becomes unstable after a QoS change even though throughput tests show the path is otherwise healthy.NetworkAdvanced17 minProNETWORK-1271A BGP session stays Established but traffic preference changesA provider-facing BGP session remains healthy while traffic suddenly shifts to another path after an upstream policy change.NetworkAdvanced17 minProNETWORK-1283A VRRP or HSRP pair appears healthy but east-west traffic breaksA first-hop redundancy event finishes and only some segments continue blackholing traffic toward the old gateway MAC.NetworkAdvanced17 minProNETWORK-133An IP SLA object track recovers immediately, but without hysteresis the WAN edge oscillates on every brief probe successThe failover design is correct in principle, yet recovery logic is too eager for the quality of the circuit.NetworkAdvanced17 minProNETWORK-1258An IS-IS adjacency never formsA backbone link carries traffic normally but IS-IS adjacencies never come up across it.NetworkAdvanced17 minProNETWORK-096HSRP preempt delay is shorter than upstream route convergence and gateway flaps twice on recoveryFailover succeeds initially, but recovery creates another outage because the active gateway returns before its upstream dependencies are ready.NetworkAdvanced17 minProNETWORK-1264A backup Layer 2 path wakes up during maintenance and spanning tree instantly blocks itNetwork incident scenario used for structured troubleshooting practice.NetworkAdvanced18 minProNETWORK-1269A backup Layer 2 path wakes up during maintenance and spanning tree instantly blocks itA maintenance change activates a backup trunk that has not forwarded in months and an access segment immediately becomes unstable.NetworkAdvanced18 minProNETWORK-1278A BGP keepalive path is stable but larger updates failA peering looks healthy until one change introduces larger update sets and route learning becomes inconsistent.NetworkAdvanced18 minProNETWORK-100Anycast DNS stays reachable but one site serves stale zone data after an AXFR policy changeThe service appears up globally, yet answers diverge because one anycast site stopped receiving zone transfers under the new policy.NetworkAdvanced18 minPro