Certification793 problems· 22 reviewed

CCNA

793 incident response problems that help with CCNA prep.

All problems (793)

NETWORK-1407A storage recovery VLAN restores half the serversA storage recovery VLAN restores half the servers focuses on l2-switching and asks the reader to isolate the key signal in Arista. MLAG recovery problems often come from asymmetry between peers, not from the peer-link itself failing.NetworkAdvanced14 minProNETWORK-1395A validating resolver answers quickly and one internal zone fails DNSSECA validating resolver answers quickly and one internal zone fails DNSSEC focuses on reverse-proxy-security and asks the reader to isolate the key signal in Linux. High-availability DNS exceptions can quietly weaken validati...NetworkAdvanced14 minProNETWORK-1452An EVPN type-5 route is learned and never installedExternal prefixes never appear in forwarding after adding a second vendor into an EVPN fabric.NetworkAdvanced14 minProNETWORK-1431An HTTP/3 edge rollout passes smoke tests and breaks origin authAn HTTP/3 edge rollout passes smoke tests and breaks origin auth focuses on edge-routing and asks the reader to isolate the key signal in NGINX. Protocol upgrades can change the signed representation of request metadata even when t...NetworkAdvanced14 minProNETWORK-1411An HTTP/3 edge rollout passes smoke tests and signed origin requests failAn HTTP/3 edge rollout passes smoke tests and signed origin requests fail focuses on edge-routing and asks the reader to isolate the key signal in NGINX. Protocol upgrades can quietly change the byte representation of values used for o...NetworkAdvanced14 minProNETWORK-1401An HTTP/3 listener works for browsers and breaks signed backend authAn HTTP/3 listener works for browsers and breaks signed backend auth focuses on edge-routing and asks the reader to isolate the key signal in NGINX. Protocol upgrades can subtly change how edge layers normalize authority information be...NetworkAdvanced14 minProNETWORK-1421An HTTP/3 rollout succeeds and signed origin requests failAn HTTP/3 rollout succeeds and signed origin requests fail focuses on edge-routing and asks the reader to isolate the key signal in NGINX. Protocol upgrades can change the exact bytes used for origin auth even when the logical host looks identical.NetworkAdvanced14 minProNETWORK-1365An NGINX reverse proxy fronting OpenSearch serves queries and bulk ingest...An NGINX reverse proxy fronting OpenSearch serves queries and bulk ingest... focuses on protocol-interoperability and asks the reader to isolate the key signal in NGINX. Healthy read traffic does not prove high-volume write routes kept the sam...NetworkAdvanced14 minProNETWORK-1319A BFD-assisted failover never triggers the backup routeA network adds ACL hardening and later one redundant path stops failing over quickly despite healthy-looking interface counters.NetworkAdvanced15 minProNETWORK-1432A BGP failback never restores the preferred ISPA BGP failback never restores the preferred ISP focuses on bgp and asks the reader to isolate the key signal in Cisco. BGP failback bugs often come from attribute handling on reflected paths rather than from neighbor health.NetworkAdvanced15 minProNETWORK-1422A BGP failback never restores the primary ISPA BGP failback never restores the primary ISP focuses on bgp and asks the reader to isolate the key signal in Cisco. BGP preference bugs often come from attribute handling on reflection rather than from neighbor health.NetworkAdvanced15 minProNETWORK-1412A BGP failover never restores the preferred ISPA BGP failover never restores the preferred ISP focuses on bgp and asks the reader to isolate the key signal in Cisco. BGP recovery bugs often come from attribute loss during reflection rather than from neighbor reachability itself.NetworkAdvanced15 minProNETWORK-1323A BGP session stays up and reachability still diesA provider handoff is redesigned and only then one BGP neighbor starts flapping or refusing traffic despite correct passwords and addresses.NetworkAdvanced15 minProNETWORK-1345A Cisco DHCP relay looks healthy and the server still logs the wrong sourceA Cisco DHCP relay looks healthy and the server still logs the wrong source focuses on firewall-policy-basics and asks the reader to isolate the key signal in Cisco. DHCP relay failures after VRF moves often come from source context drift, not...NetworkAdvanced15 minProNETWORK-1315A Cloudflare cache rule speeds up one static route and later stale security headers persistA zone hardens response headers and one route continues serving an older header set even after the transform rule is changed.NetworkAdvanced15 minProNETWORK-1321A Cloudflare proxied hostname returns 526 only from one backend pool memberA Cloudflare proxied hostname returns 526 only from one backend pool member focuses on protocol-interoperability and asks the reader to isolate the key signal in Cloudflare. Intermittent 526 errors often mean your origins are not serving the...NetworkAdvanced15 minProNETWORK-1393A firewall failover appears clean and return traffic breaksA failover test passes basic reachability but one app with policy-routed WAN egress dies only after the standby becomes active.NetworkAdvanced15 minProNETWORK-1374A firewall policy appears correct and health checks still failA firewall policy appears correct and health checks still fail focuses on network-segmentation and asks the reader to isolate the key signal in netgate. Health checks fail just as often on the way back as they do on the way in.NetworkAdvanced15 minProNETWORK-1290A load balancer can reach the service IP but health checks still failA service behind a load balancer never becomes healthy even though the backend responds from the same subnet during manual testing.NetworkIntermediate15 minProNETWORK-1377A new leaf switch joins cleanly and duplicate MAC dampening starts flapping one rackA single rack develops intermittent endpoint reachability after a leaf replacement, even though LACP and VLAN checks all pass.NetworkAdvanced15 minPro