CCNA
793 incident response problems that help with CCNA prep.
먼저 읽을 가이드
추천 문제
All problems (793)
NETWORK-1201Spanning-tree looks stable but one trunk still discards the VLANOperators focus on spanning tree because the path is intermittent after a change. Community threads point out that one trunk never had the VLAN in its allowed list.NetworkIntermediate18 minProNETWORK-1190WebSocket path fails only through reverse proxyA network team validates normal HTTP traffic and DNS, yet upgraded sessions still fail because one proxy hop never forwards the needed semantics.NetworkIntermediate18 minProNETWORK-030Blue-green cutover misses webhook callback allowlistThe new stack goes live, but one callback provider still points at the old address because its allowlist and DNS cutover are out of sync.NetworkIntermediate19 minProNETWORK-1195Reverse proxy returns 499 and upstream timeout togetherA team reads public NGINX troubleshooting threads and focuses on 499 status codes. The real problem is a backend path slow enough that clients disconnect first.NetworkIntermediate19 minProNETWORK-1197Load balancer keeps reusing an old backend pathA cutover follows runbook timing, but the edge still uses the old backend because one layer caches the resolution path longer than the service owner assumed.NetworkIntermediate20 minProNETWORK-1193Packet capture proves SYN reaches the host but the reply leaves on the wrong interfaceInbound traffic is visible, yet the connection still fails because the response follows a different egress path than the one the client can actually return through.NetworkIntermediate20 minProNETWORK-022Internal DNS resolves the old targetMost clients pick up the new destination, but a subset stays on the stale IP because resolver behavior is inconsistent.NetworkIntermediate21 minProNETWORK-028TLS handshake fails only through one CDN POPTLS handshake fails only (Certificate Trust Failure) is a hands-on troubleshooting drill. Most regions succeed, but a single edge location negotiates an older TLS path and breaks the request. Azure Firewall and Proxy Paths needs to be checked by narrowing scope, recent change,...NetworkIntermediate22 minProNETWORK-008Packet loss that recurs only between the application and the DBStep-by-step narrowing of a situation where the whole network looks fine but loss occurs on only a specific path.NetworkAdvanced26 minProNETWORK-005Only certain gRPC requests intermittently fail due to an MTU mismatchTracks MTU and segment size in a situation where small requests work but only large requests break in the middle.NetworkAdvanced27 minProNETWORK-023Packet loss appears only under east-west service mesh trafficPacket loss appears only (Firewall and Proxy Paths) is a hands-on troubleshooting drill. North-south traffic looks stable, but encrypted internal mesh traffic drops packets under burst load. Firewall and Proxy Paths needs to be checked by narrowing scope, recent change, and th...NetworkAdvanced27 minProNETWORK-029Conntrack eviction hurts new connections before CPU looks busyConntrack eviction hurts new connections (Resource Exhaustion) is a hands-on troubleshooting drill. The host still has spare CPU, but new flows fail because connection tracking entries are evicted too aggressively. DNS and Routing needs to be checked by narrowing scope, recent...NetworkAdvanced29 minProNETWORK-134A LACP bundle works until one side silently flips to passive during replacement and the port-channel collapses to a single linkMost traffic still passes, but capacity and redundancy disappear because only one side is actively negotiating now.NetworkIntermediate15 minProNETWORK-157A Wi-Fi controller advertises the correct guest SSID, but the upstream switch trunk prunes the new VLAN after a template reapplyClients can associate, yet the data plane for the new segment never exists end to end.NetworkIntermediate15 minProNETWORK-140Both HSRP routers relay DHCP, and clients intermittently receive duplicate offersGateway redundancy is healthy, but an adjacent service now answers twice because both paths forward the same broadcast.NetworkIntermediate15 minProNETWORK-118LLDP-MED advertises the voice VLAN, but the access switch data policy overrides it after a bouncePhones boot into the right segment once, then move unexpectedly because another edge policy reclassifies the port after link renegotiation.NetworkIntermediate15 minProNETWORK-150A DNS resolver cluster answers internally, but the monitoring probe queries over TCP only and a firewall change now blocks fallback responses for large recordsMost lookups seem fine until oversized replies require a protocol path the probe no longer reaches.NetworkIntermediate16 minProNETWORK-363A resolver answers from cache while one DNS64 or split-horizon view changed only on the authoritative path and new clients fail immediately during a staged decommissionWarm clients look healthy, cold clients prove the design drifted. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.NetworkIntermediate16 minProNETWORK-351A VLAN handoff trunks correctly while one voice endpoint still receives LLDP policy from a switch profile that no longer matches the access template during a staged decommissionLayer 2 reachability exists and endpoint policy negotiation does not. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.NetworkIntermediate16 minProNETWORK-142A VLAN translation on the access switch is correct for user traffic, but LLDP frames stay untranslated and IP phones never discover the voice policyData works while onboarding fails because control-plane frames did not follow the same translation assumption.NetworkIntermediate16 minPro