Certification795 problems· 7 reviewed

CCNP Enterprise

795 incident response problems that help with CCNP Enterprise prep.

All problems (795)

NETWORK-1323A BGP session stays up and reachability still diesA provider handoff is redesigned and only then one BGP neighbor starts flapping or refusing traffic despite correct passwords and addresses.NetworkAdvanced15 minProNETWORK-1345A Cisco DHCP relay looks healthy and the server still logs the wrong sourceA Cisco DHCP relay looks healthy and the server still logs the wrong source focuses on firewall-policy-basics and asks the reader to isolate the key signal in Cisco. DHCP relay failures after VRF moves often come from source context drift, not...NetworkAdvanced15 minProNETWORK-1315A Cloudflare cache rule speeds up one static route and later stale security headers persistA zone hardens response headers and one route continues serving an older header set even after the transform rule is changed.NetworkAdvanced15 minProNETWORK-1321A Cloudflare proxied hostname returns 526 only from one backend pool memberA Cloudflare proxied hostname returns 526 only from one backend pool member focuses on protocol-interoperability and asks the reader to isolate the key signal in Cloudflare. Intermittent 526 errors often mean your origins are not serving the...NetworkAdvanced15 minProNETWORK-1393A firewall failover appears clean and return traffic breaksA failover test passes basic reachability but one app with policy-routed WAN egress dies only after the standby becomes active.NetworkAdvanced15 minProNETWORK-1374A firewall policy appears correct and health checks still failA firewall policy appears correct and health checks still fail focuses on network-segmentation and asks the reader to isolate the key signal in netgate. Health checks fail just as often on the way back as they do on the way in.NetworkAdvanced15 minProNETWORK-1290A load balancer can reach the service IP but health checks still failA service behind a load balancer never becomes healthy even though the backend responds from the same subnet during manual testing.NetworkIntermediate15 minProNETWORK-1377A new leaf switch joins cleanly and duplicate MAC dampening starts flapping one rackA single rack develops intermittent endpoint reachability after a leaf replacement, even though LACP and VLAN checks all pass.NetworkAdvanced15 minProNETWORK-1334A Palo Alto decryption bypass fixes browsers and one API client still failsA Palo Alto decryption bypass fixes browsers and one API client still fails focuses on protocol-interoperability and asks the reader to isolate the key signal in palo-alto. TLS validation often depends on auxiliary hosts beyond the visible appl...NetworkAdvanced15 minProNETWORK-1383A pfSense HA pair syncs states and failover still drops one appA pfSense HA pair syncs states and failover still drops one app focuses on incident-response and asks the reader to isolate the key signal in netgate. HA firewalls can fail only for apps whose reply path uses an address outside t...NetworkAdvanced15 minProNETWORK-1332A pfSense or Netgate policy route appears correct and return traffic still...A pfSense or Netgate policy route appears correct and return traffic still... focuses on firewall-policy-basics and asks the reader to isolate the key signal in netgate. Stateful firewall return-path behavior can override a route that loo...NetworkAdvanced15 minProNETWORK-1273A port-channel comes up partially but traffic still hashes badlyAn EtherChannel looks mostly healthy after a maintenance change and later only certain flows or VLANs misbehave.NetworkIntermediate15 minProNETWORK-1296A port-channel reports up but multicast behaves strangelyA port-channel looks healthy in summaries and only multicast-dependent services begin failing after a template rollout.NetworkIntermediate15 minProNETWORK-1376A resolver can query authorities over UDP and some domains still failA resolver can query authorities over UDP and some domains still fail focuses on network-segmentation and asks the reader to isolate the key signal in Linux. A DNS path can look healthy under UDP-only tests while TCP fallback is silently b...NetworkAdvanced15 minProNETWORK-1402A route reflector cluster keeps preferring the wrong exitA route reflector cluster keeps preferring the wrong exit focuses on bgp and asks the reader to isolate the key signal in Cisco. BGP policy bugs often come from the order in which attributes are mutated, not from the absence of the inte...NetworkAdvanced15 minProNETWORK-1325A split horizon DNS setup works on LAN and fails at the edgeA hybrid network uses different answers for internal and public clients and later some edge users resolve to the wrong target after an upstream cache change.NetworkAdvanced15 minProNETWORK-1314A Traefik edge route works on HTTP and fails on WebSocketsA reverse proxy hardening change lands and only long-lived upgraded connections begin failing while standard traffic remains healthy.NetworkAdvanced15 minProNETWORK-1326A Traefik passthrough route works with one certificate and later breaksA Traefik passthrough route works with one certificate and later breaks focuses on protocol-interoperability and asks the reader to isolate the key signal in traefik. Passthrough routers are coupled to hostname identity even when they do...NetworkAdvanced15 minProNETWORK-1357An EVPN fabric converges and one VLAN floods after a leaf replacementA leaf switch replacement appears successful and later mobility-heavy workloads trigger flooding or intermittent loss on one VLAN.NetworkAdvanced15 minProNETWORK-1347An EVPN fabric learns MAC moves and still floods one VLANA new leaf is introduced into an EVPN fabric and later one VLAN begins flooding or blackholing after mobility events.NetworkAdvanced15 minPro