Certification795 problems· 7 reviewed

CCNP Enterprise

795 incident response problems that help with CCNP Enterprise prep.

All problems (795)

NETWORK-1439A newly onboarded export hostname fails from one campusA newly onboarded SaaS export domain fails only from one policy-routed campus path.NetworkAdvanced13 minProNETWORK-1449A newly onboarded export hostname fails from one campusA new export domain fails only from one campus path after a trust bundle update.NetworkAdvanced13 minProNETWORK-1409A SaaS export endpoint fails only from one campusA SaaS export endpoint fails only from one campus focuses on edge-routing and asks the reader to isolate the key signal in Cloudflare. Shared CDN policy trees can misclassify new hostnames long after DNS looks correct everywhere else.NetworkAdvanced13 minProNETWORK-1399A URL filtering exception covers the main SaaS host and file exports still...A URL filtering exception covers the main SaaS host and file exports still... focuses on incident-response and asks the reader to isolate the key signal in Palo Alto Networks. Feature-specific SaaS traffic often uses shared CDN hostna...NetworkAdvanced13 minProNETWORK-1443An HA firewall pair syncs sessions and still breaks voiceVoice traffic survives failover and becomes unusable only on the standby-forwarded path.NetworkAdvanced13 minProNETWORK-1441An HTTP/3 origin check passes in staging and fails in productionAn HTTP/3 origin check passes in staging and fails in production focuses on edge-routing and asks the reader to isolate the key signal in Cloudflare. Transport upgrades can change header normalization in ways signature code never anticipated.NetworkAdvanced13 minProNETWORK-1455An NGINX stream SNI route sends traffic to the default upstreamA new privacy feature rollout sends traffic to the default upstream only on the stream ingress tier.NetworkAdvanced13 minProNETWORK-1451An OSPF adjacency reaches two-way and still never advancesAn adjacency appears half-alive and never reaches full after a link refresh changed one side's interface defaults.NetworkAdvanced13 minProNETWORK-1442A BGP failback never happensPrimary links recover and traffic stays on the backup path until manual intervention.NetworkAdvanced14 minProNETWORK-1391A CDN hostname serves HTTP/2 cleanly and API uploads fail over HTTP/3Uploads fail only for clients that negotiate HTTP/3 while ordinary browsing and HTTP/2 API calls remain healthy.NetworkAdvanced14 minProNETWORK-1355A Cisco OSPF adjacency stays two-wayA routing policy cleanup introduces passive-interface default and later one neighbor remains stuck in two-way despite matching hello parameters.NetworkAdvanced14 minProNETWORK-1343A Cloudflare cache purge succeeds for URLs and stale content remainsA caching optimization rollout works initially and later targeted purges stop removing stale content even though the API accepts every request.NetworkAdvanced14 minProNETWORK-1361A Cloudflare proxied hostname returns intermittent 526A proxied site looks healthy and later only some requests return 526 when traffic lands on a specific origin server.NetworkAdvanced14 minProNETWORK-1403A dual-WAN firewall syncs NAT state to its peer and failover still breaks...A dual-WAN firewall syncs NAT state to its peer and failover still breaks... focuses on nat and asks the reader to isolate the key signal in netgate. Session sync can preserve state and still lose the route-selection context needed to cont...NetworkAdvanced14 minProNETWORK-1423A firewall HA failover preserves sessions and still breaks voice qualityA firewall HA failover preserves sessions and still breaks voice quality focuses on nat and asks the reader to isolate the key signal in netgate. State sync can preserve connectivity while still losing the policy context that drives QoS treatment.NetworkAdvanced14 minProNETWORK-1433A firewall HA pair preserves sessions and still ruins voice qualityA firewall HA pair preserves sessions and still ruins voice quality focuses on nat and asks the reader to isolate the key signal in netgate. Session continuity does not guarantee policy continuity when HA sync omits classification context.NetworkAdvanced14 minProNETWORK-1413A firewall HA pair syncs sessions and one branch still loses VoIP on failoverA firewall HA pair syncs sessions and one branch still loses VoIP on failover focuses on nat and asks the reader to isolate the key signal in netgate. HA state sync can preserve connection tuples without preserving the policy context needed for QoS...NetworkAdvanced14 minProNETWORK-1363A Palo Alto decryption exception fixes browsers and mobile clients still failA decryption bypass is created for an app and later only mobile or modern clients keep failing while browsers recover.NetworkAdvanced14 minProNETWORK-1353A Palo Alto URL category exception fixes browsers and the API still failsA decryption policy is tuned for an app and later only mobile or modern clients keep failing while browsers work.NetworkAdvanced14 minProNETWORK-1389A Palo Alto URL filtering change looks correct and one SaaS app fails only on...A Palo Alto URL filtering change looks correct and one SaaS app fails only... focuses on incident-response and asks the reader to isolate the key signal in Palo Alto Networks. Multi-host SaaS apps often break on the one upload or media hostname...NetworkAdvanced14 minPro