CCNA
793 incident response problems that help with CCNA prep.
먼저 읽을 가이드
추천 문제
All problems (793)
NETWORK-1394A TCP stream proxy still passes traffic and client IP allowlists failA TCP stream proxy still passes traffic and client IP allowlists fail focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Source identity failures can come from protocol version mismatch even when tr...NetworkIntermediate11 minProNETWORK-1396An edge auth rule should block a path and one localized URL stays openA multilingual or encoded URL path reaches an origin route that should have been blocked by edge auth.NetworkIntermediate11 minProNETWORK-1400An ingest tier cutover looks complete and one proxy pool keeps using the old...An ingest tier cutover looks complete and one proxy pool keeps using the... focuses on incident-response and asks the reader to isolate the key signal in Opensearch. Negative caching can distort cutovers even when positive record TTLs are...NetworkIntermediate11 minProNETWORK-1384An NGINX stream proxy accepts TLS and backend auth breaksAn NGINX stream proxy accepts TLS and backend auth breaks focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Proxy protocol misalignment often shows up as auth or allowlist failures rather th...NetworkIntermediate11 minProNETWORK-1390An OpenSearch ingest node remains reachable and query latency spikesAn OpenSearch ingest node remains reachable and query latency spikes focuses on incident-response and asks the reader to isolate the key signal in Opensearch. Infrastructure cutovers often fail at intermediate cache layers that keep targeti...NetworkIntermediate11 minProNETWORK-1450An SRV cutover looks correct in dig output and still fails in appsApplications keep failing after a service-discovery cutover even though direct queries show the intended answers.NetworkIntermediate11 minProNETWORK-1440An SRV cutover looks correct in direct dig and still fails in appsAn SRV cutover looks correct in direct dig and still fails in apps focuses on Service Discovery and asks the reader to isolate the key signal in ubuntu. SRV migrations can fail at the target-label level even when the top-level record already loo...NetworkIntermediate11 minProNETWORK-1392A BGP route reflector session is healthy and one site's routes lose preferenceA BGP route reflector session is healthy and one site's routes lose preference focuses on routing-protocols and asks the reader to isolate the key signal in Cisco. Route preference bugs often come from attribute mutation upst...NetworkIntermediate12 minProNETWORK-1382A BGP session is established and routes never winA BGP session is established and routes never win focuses on routing-protocols and asks the reader to isolate the key signal in Cisco. Route policy chains can break when one stage renames communities another stage still depends...NetworkIntermediate12 minProNETWORK-1373A Cloudflare tunnel path works over TCP and one browser class still failsA secure tunnel works after an inspection exception and later a subset of browsers or clients still fail to connect reliably.NetworkIntermediate12 minProNETWORK-1358A DNS service resolves small answers and signed domains failA DNS service resolves small answers and signed domains fail focuses on dns-resolution and asks the reader to isolate the key signal in Cloudflare. Stub success does not prove the recursive server can complete its own fallback path.NetworkIntermediate12 minProNETWORK-1366A DNS service resolves small records and DNSSEC-heavy zones failA DNS service resolves small records and DNSSEC-heavy zones fail focuses on dns-resolution and asks the reader to isolate the key signal in Cloudflare. Stub success does not prove the recursive server can finish its own fallback behavior.NetworkIntermediate12 minProNETWORK-1379A HA sync succeeds and a package upgrade still breaks TLSAn HA pair survives a software upgrade and later failover lands on a node that cannot present the expected certificate chain.NetworkIntermediate12 minProNETWORK-1375A log ingest NGINX location works for normal requests and large client posts...A log ingest NGINX location works for normal requests and large client... focuses on runtime-configuration and asks the reader to isolate the key signal in NGINX. Breaking a server block into includes can silently shrink limits on paths that d...NetworkIntermediate12 minProNETWORK-1364A Netgate policy route sends packets out the intended WAN and health probes still failA multi-WAN design appears correct on paper and later operators see health checks and user traffic disagree on which path is active.NetworkIntermediate12 minProNETWORK-1416A path-based auth gateway protects the admin UI and one encoded traversal...A path-based auth gateway protects the admin UI and one encoded traversal... focuses on proxy-headers and asks the reader to isolate the key signal in NGINX. URI security bugs often come from normalization order mismatches between layers, not...NetworkIntermediate12 minProNETWORK-1406A reverse proxy authenticates normal paths and leaks one admin endpointA reverse proxy authenticates normal paths and leaks one admin endpoint focuses on proxy-headers and asks the reader to isolate the key signal in NGINX. Proxy auth gaps often live in normalization order, not in the visible location pattern its...NetworkIntermediate12 minProNETWORK-1370A reverse proxy real-IP fix works for the app and automated bans still hit...A reverse proxy real-IP fix works for the app and automated bans still hit... focuses on incident-response and asks the reader to isolate the key signal in NGINX. Real-IP fixes are incomplete until every security parser reads the same trusted...NetworkIntermediate12 minProNETWORK-1380A WAF bypass rule appears correct and never matchesA CDN logging format is updated and later allowlists, bypass rules, or enrichment behave as though every request came from the wrong IP.NetworkIntermediate12 minProNETWORK-1426An auth gateway protects a path and an encoded traversal still reaches the...An auth gateway protects a path and an encoded traversal still reaches the... focuses on proxy-headers and asks the reader to isolate the key signal in NGINX. Path protection bugs often come from normalization order differences rather than fr...NetworkIntermediate12 minPro