CCNA
793 incident response problems that help with CCNA prep.
먼저 읽을 가이드
추천 문제
All problems (793)
NETWORK-1334A Palo Alto decryption bypass fixes browsers and one API client still failsA Palo Alto decryption bypass fixes browsers and one API client still fails focuses on protocol-interoperability and asks the reader to isolate the key signal in palo-alto. TLS validation often depends on auxiliary hosts beyond the visible appl...NetworkAdvanced15 minProNETWORK-1383A pfSense HA pair syncs states and failover still drops one appA pfSense HA pair syncs states and failover still drops one app focuses on incident-response and asks the reader to isolate the key signal in netgate. HA firewalls can fail only for apps whose reply path uses an address outside t...NetworkAdvanced15 minProNETWORK-1332A pfSense or Netgate policy route appears correct and return traffic still...A pfSense or Netgate policy route appears correct and return traffic still... focuses on firewall-policy-basics and asks the reader to isolate the key signal in netgate. Stateful firewall return-path behavior can override a route that loo...NetworkAdvanced15 minProNETWORK-1273A port-channel comes up partially but traffic still hashes badlyAn EtherChannel looks mostly healthy after a maintenance change and later only certain flows or VLANs misbehave.NetworkIntermediate15 minProNETWORK-1296A port-channel reports up but multicast behaves strangelyA port-channel looks healthy in summaries and only multicast-dependent services begin failing after a template rollout.NetworkIntermediate15 minProNETWORK-1376A resolver can query authorities over UDP and some domains still failA resolver can query authorities over UDP and some domains still fail focuses on network-segmentation and asks the reader to isolate the key signal in Linux. A DNS path can look healthy under UDP-only tests while TCP fallback is silently b...NetworkAdvanced15 minProNETWORK-1402A route reflector cluster keeps preferring the wrong exitA route reflector cluster keeps preferring the wrong exit focuses on bgp and asks the reader to isolate the key signal in Cisco. BGP policy bugs often come from the order in which attributes are mutated, not from the absence of the inte...NetworkAdvanced15 minProNETWORK-1325A split horizon DNS setup works on LAN and fails at the edgeA hybrid network uses different answers for internal and public clients and later some edge users resolve to the wrong target after an upstream cache change.NetworkAdvanced15 minProNETWORK-1314A Traefik edge route works on HTTP and fails on WebSocketsA reverse proxy hardening change lands and only long-lived upgraded connections begin failing while standard traffic remains healthy.NetworkAdvanced15 minProNETWORK-1326A Traefik passthrough route works with one certificate and later breaksA Traefik passthrough route works with one certificate and later breaks focuses on protocol-interoperability and asks the reader to isolate the key signal in traefik. Passthrough routers are coupled to hostname identity even when they do...NetworkAdvanced15 minProNETWORK-1357An EVPN fabric converges and one VLAN floods after a leaf replacementA leaf switch replacement appears successful and later mobility-heavy workloads trigger flooding or intermittent loss on one VLAN.NetworkAdvanced15 minProNETWORK-1347An EVPN fabric learns MAC moves and still floods one VLANA new leaf is introduced into an EVPN fabric and later one VLAN begins flooding or blackholing after mobility events.NetworkAdvanced15 minProNETWORK-1367An EVPN fabric looks healthy and one VLAN floods after a leaf replacementA new leaf is inserted into an EVPN fabric and later mobility-heavy workloads start triggering flooding or intermittent reachability loss.NetworkAdvanced15 minProNETWORK-1341An NGINX ingress passes health checks and long uploads failAn NGINX ingress passes health checks and long uploads fail focuses on protocol-interoperability and asks the reader to isolate the key signal in NGINX. Health checks rarely exercise the timeout and buffering profile of the largest request path.NetworkAdvanced15 minProNETWORK-1331An NGINX reverse proxy keeps one upstream marked healthyAn NGINX reverse proxy keeps one upstream marked healthy focuses on reverse-proxy-security and asks the reader to isolate the key signal in NGINX. A healthy keepalive pool can hide failures that only happen on new TLS handshakes.NetworkAdvanced15 minProNETWORK-1336An OpenSearch cluster exposed (nginx-buffering-timeout-broke-opensearch-bulk-ingest)An OpenSearch cluster exposed (nginx-buffering-timeout-broke-opensearch-bulk... focuses on reverse-proxy-security and asks the reader to isolate the key signal in NGINX. Edge proxies can be the bottleneck when UI and ingest paths share one...NetworkAdvanced15 minProNETWORK-1305Full strict mode returns 526 only on an alternate hostnameA new vanity or fallback hostname is added and only that path starts returning 526 through Cloudflare.NetworkAdvanced15 minProNETWORK-1308Large DNS lookups fail only on TCP fallbackOnly large DNS responses or DNSSEC-heavy queries fail through a path that otherwise seems to resolve names correctly.NetworkAdvanced15 minProNETWORK-1371One member in a proxied origin pool works from direct tests and Cloudflare...One member in a proxied origin pool works from direct tests and Cloudflare... focuses on reverse-proxy-security and asks the reader to isolate the key signal in Cloudflare. TLS issues behind a pool can hide on one member when direct test...NetworkAdvanced15 minProNETWORK-125Policy-based routing on the SVI forces user traffic toward a firewall but also bypasses the local DHCP relay pathSecurity steering works, but address assignment becomes unstable because a local service path was not exempted from the policy.NetworkIntermediate15 minPro