Certification793 problems· 22 reviewed

CCNA

793 incident response problems that help with CCNA prep.

All problems (793)

NETWORK-1372Two OSPF neighbors stay in EXSTART after a VLAN migrationA routed VLAN migration completes and later one OSPF adjacency never progresses beyond EXSTART despite matching interface configs at the subinterface layer.NetworkAdvanced15 minProNETWORK-139A CAPWAP access point reaches the controller, but DTLS setup failsLayer-3 reachability is fine, yet management onboarding stalls on the trust layer.NetworkIntermediate16 minProNETWORK-1304A Cloudflare Tunnel reports healthy and WebSocket traffic still failsCloudflare Tunnel works for ordinary HTTP routes and later one real-time feature fails only through a new upstream proxy hop.NetworkAdvanced16 minProNETWORK-1311A Cloudflare Tunnel stays healthy and origin mTLS still failsA private service is published through Tunnel and later only the mTLS-protected route fails after an origin proxy change.NetworkAdvanced16 minProNETWORK-1320A Cloudflare WARP to Tunnel path reaches the origin and application auth...A Cloudflare WARP to Tunnel path reaches the origin and application auth... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Path success through Zero Trust does not prove origin ACLs recognize the new caller...NetworkAdvanced16 minProNETWORK-1312A Palo Alto decryption policy excludes the hostname and traffic still breaksA Palo Alto decryption policy excludes the hostname and traffic still breaks focuses on protocol-interoperability and asks the reader to isolate the key signal in palo-alto. Pinned apps can fail on regional certificate differences even when h...NetworkAdvanced16 minProNETWORK-1301A Palo Alto security rule looks correct but sessions still miss itA firewall change window updates NAT and only afterward one access policy appears to stop matching with no clear deny log explanation.NetworkAdvanced16 minProNETWORK-1310A route reflector shows every prefix and one client still blackholesA route policy cleanup on a reflector changes data-plane reachability without dropping any BGP session.NetworkAdvanced16 minProNETWORK-155A routing summary is correct in normal conditions, but when the only specific route fails the summary still attracts traffic into a black holeAggregation reduced table size, yet it also masked the absence of any viable child route.NetworkIntermediate16 minProNETWORK-393A static summary route is valid while the tracking object for the real downstream next hop was repointed to an interface that stays up during failure during a staged decommissionThe summary remains installed long after the useful path is gone. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.NetworkIntermediate16 minProNETWORK-1284A trunk carries the expected VLANs but one voice VLAN still failsPhones that worked on the old switch fleet stop joining the expected voice VLAN after a mixed-vendor refresh.NetworkIntermediate16 minProNETWORK-1260A trunk comes up electrically but spanning tree blocks it with inconsistent port typeA new switch trunk is introduced and immediately lands in blocking with RECV_1Q_NON_TRUNK or similar inconsistency messages.NetworkIntermediate16 minProNETWORK-1330An anycast gateway migration keeps the VLAN online and still creates...An anycast gateway migration keeps the VLAN online and still creates... focuses on incident-response and asks the reader to isolate the key signal in Cisco. Fabric convergence is often multi-stage and each table can believe...NetworkAdvanced16 minProNETWORK-1337An Arista or EVPN leaf pair keeps flooding one segmentA mobility-heavy workload is migrated and later one segment shows flooding and intermittent loss even though the MAC has settled.NetworkAdvanced16 minProNETWORK-1317An EVPN gateway migration preserves VLANs and still blackholes one segmentA fabric migration introduces an anycast gateway change and only one segment experiences intermittent blackholes afterward.NetworkAdvanced16 minProNETWORK-1302An SSL decryption exception seems broad enough and still breaks one mobile appA mobile app breaks after decryption is enabled even though the visible hostname was already exempted.NetworkAdvanced16 minProNETWORK-109Gateway tracking monitors only the interface state while the upstream SLA probe is already failingThe local interface is up, but the default gateway should have failed over earlier because the real dependency is beyond the first-hop link.NetworkAdvanced16 minProNETWORK-159NAT translations survive failover, but route-map based NAT exemption references an old object group and VPN traffic gets translated unexpectedlyConnectivity still exists, yet one policy layer stopped recognizing protected traffic after an object rename.NetworkIntermediate16 minProNETWORK-1306Policy-based forwarding on a Palo Alto firewall sends outbound traffic to the...Policy-based forwarding on a Palo Alto firewall sends outbound traffic to... focuses on incident-response and asks the reader to isolate the key signal in palo-alto. PBF success on outbound traffic can still create session failure on the reverse path.NetworkAdvanced16 minProNETWORK-1217Port appears healthy but PoE-powered phones still flapA voice access migration keeps one phone segment unstable even though interfaces show up and forwarding correctly.NetworkIntermediate16 minPro