Certification795 problems· 7 reviewed

CCNP Enterprise

795 incident response problems that help with CCNP Enterprise prep.

All problems (795)

NETWORK-1367An EVPN fabric looks healthy and one VLAN floods after a leaf replacementA new leaf is inserted into an EVPN fabric and later mobility-heavy workloads start triggering flooding or intermittent reachability loss.NetworkAdvanced15 minProNETWORK-1341An NGINX ingress passes health checks and long uploads failAn NGINX ingress passes health checks and long uploads fail focuses on protocol-interoperability and asks the reader to isolate the key signal in NGINX. Health checks rarely exercise the timeout and buffering profile of the largest request path.NetworkAdvanced15 minProNETWORK-1331An NGINX reverse proxy keeps one upstream marked healthyAn NGINX reverse proxy keeps one upstream marked healthy focuses on reverse-proxy-security and asks the reader to isolate the key signal in NGINX. A healthy keepalive pool can hide failures that only happen on new TLS handshakes.NetworkAdvanced15 minProNETWORK-1336An OpenSearch cluster exposed (nginx-buffering-timeout-broke-opensearch-bulk-ingest)An OpenSearch cluster exposed (nginx-buffering-timeout-broke-opensearch-bulk... focuses on reverse-proxy-security and asks the reader to isolate the key signal in NGINX. Edge proxies can be the bottleneck when UI and ingest paths share one...NetworkAdvanced15 minProNETWORK-1305Full strict mode returns 526 only on an alternate hostnameA new vanity or fallback hostname is added and only that path starts returning 526 through Cloudflare.NetworkAdvanced15 minProNETWORK-1308Large DNS lookups fail only on TCP fallbackOnly large DNS responses or DNSSEC-heavy queries fail through a path that otherwise seems to resolve names correctly.NetworkAdvanced15 minProNETWORK-1371One member in a proxied origin pool works from direct tests and Cloudflare...One member in a proxied origin pool works from direct tests and Cloudflare... focuses on reverse-proxy-security and asks the reader to isolate the key signal in Cloudflare. TLS issues behind a pool can hide on one member when direct test...NetworkAdvanced15 minProNETWORK-125Policy-based routing on the SVI forces user traffic toward a firewall but also bypasses the local DHCP relay pathSecurity steering works, but address assignment becomes unstable because a local service path was not exempted from the policy.NetworkIntermediate15 minProNETWORK-1372Two OSPF neighbors stay in EXSTART after a VLAN migrationA routed VLAN migration completes and later one OSPF adjacency never progresses beyond EXSTART despite matching interface configs at the subinterface layer.NetworkAdvanced15 minProNETWORK-139A CAPWAP access point reaches the controller, but DTLS setup failsLayer-3 reachability is fine, yet management onboarding stalls on the trust layer.NetworkIntermediate16 minProNETWORK-1304A Cloudflare Tunnel reports healthy and WebSocket traffic still failsCloudflare Tunnel works for ordinary HTTP routes and later one real-time feature fails only through a new upstream proxy hop.NetworkAdvanced16 minProNETWORK-1311A Cloudflare Tunnel stays healthy and origin mTLS still failsA private service is published through Tunnel and later only the mTLS-protected route fails after an origin proxy change.NetworkAdvanced16 minProNETWORK-1320A Cloudflare WARP to Tunnel path reaches the origin and application auth...A Cloudflare WARP to Tunnel path reaches the origin and application auth... focuses on Identity And Access and asks the reader to isolate the key signal in Cloudflare. Path success through Zero Trust does not prove origin ACLs recognize the new caller...NetworkAdvanced16 minProNETWORK-138A local preference change is present in policy, but without soft reconfiguration the edge never reevaluates existing paths until a clearThe route-map is correct, yet the live table still reflects yesterday's decision because policy reevaluation never happened.NetworkAdvanced16 minProNETWORK-1312A Palo Alto decryption policy excludes the hostname and traffic still breaksA Palo Alto decryption policy excludes the hostname and traffic still breaks focuses on protocol-interoperability and asks the reader to isolate the key signal in palo-alto. Pinned apps can fail on regional certificate differences even when h...NetworkAdvanced16 minProNETWORK-1301A Palo Alto security rule looks correct but sessions still miss itA firewall change window updates NAT and only afterward one access policy appears to stop matching with no clear deny log explanation.NetworkAdvanced16 minProNETWORK-1310A route reflector shows every prefix and one client still blackholesA route policy cleanup on a reflector changes data-plane reachability without dropping any BGP session.NetworkAdvanced16 minProNETWORK-155A routing summary is correct in normal conditions, but when the only specific route fails the summary still attracts traffic into a black holeAggregation reduced table size, yet it also masked the absence of any viable child route.NetworkIntermediate16 minProNETWORK-393A static summary route is valid while the tracking object for the real downstream next hop was repointed to an interface that stays up during failure during a staged decommissionThe summary remains installed long after the useful path is gone. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.NetworkIntermediate16 minProNETWORK-1284A trunk carries the expected VLANs but one voice VLAN still failsPhones that worked on the old switch fleet stop joining the expected voice VLAN after a mixed-vendor refresh.NetworkIntermediate16 minPro