Certification795 problems· 7 reviewed

CCNP Enterprise

795 incident response problems that help with CCNP Enterprise prep.

All problems (795)

NETWORK-1260A trunk comes up electrically but spanning tree blocks it with inconsistent port typeA new switch trunk is introduced and immediately lands in blocking with RECV_1Q_NON_TRUNK or similar inconsistency messages.NetworkIntermediate16 minProNETWORK-1330An anycast gateway migration keeps the VLAN online and still creates...An anycast gateway migration keeps the VLAN online and still creates... focuses on incident-response and asks the reader to isolate the key signal in Cisco. Fabric convergence is often multi-stage and each table can believe...NetworkAdvanced16 minProNETWORK-1337An Arista or EVPN leaf pair keeps flooding one segmentA mobility-heavy workload is migrated and later one segment shows flooding and intermittent loss even though the MAC has settled.NetworkAdvanced16 minProNETWORK-1317An EVPN gateway migration preserves VLANs and still blackholes one segmentA fabric migration introduces an anycast gateway change and only one segment experiences intermittent blackholes afterward.NetworkAdvanced16 minProNETWORK-1302An SSL decryption exception seems broad enough and still breaks one mobile appA mobile app breaks after decryption is enabled even though the visible hostname was already exempted.NetworkAdvanced16 minProNETWORK-109Gateway tracking monitors only the interface state while the upstream SLA probe is already failingThe local interface is up, but the default gateway should have failed over earlier because the real dependency is beyond the first-hop link.NetworkAdvanced16 minProNETWORK-159NAT translations survive failover, but route-map based NAT exemption references an old object group and VPN traffic gets translated unexpectedlyConnectivity still exists, yet one policy layer stopped recognizing protected traffic after an object rename.NetworkIntermediate16 minProNETWORK-1306Policy-based forwarding on a Palo Alto firewall sends outbound traffic to the...Policy-based forwarding on a Palo Alto firewall sends outbound traffic to... focuses on incident-response and asks the reader to isolate the key signal in palo-alto. PBF success on outbound traffic can still create session failure on the reverse path.NetworkAdvanced16 minProNETWORK-1217Port appears healthy but PoE-powered phones still flapA voice access migration keeps one phone segment unstable even though interfaces show up and forwarding correctly.NetworkIntermediate16 minProNETWORK-1256Two OSPF neighbors stay in ExStart or ExchangeA routing change enables OSPF between devices that can ping each other but never complete adjacency formation.NetworkIntermediate16 minProNETWORK-1276A backup trunk wakes up during maintenance and causes root-inconsistent blockingA redundancy test activates a little-used link and suddenly one segment is blocked or err-disabled by spanning-tree policy.NetworkAdvanced17 minProNETWORK-345A BGP edge prefers the right path (Rollout Stuck)A BGP edge prefers the right path (Rollout Stuck) focuses on Routing And Failover Paths and asks the reader to isolate Rollout Stuck in Cisco. 실무에서는 rollout-stuck 이슈를 볼 때 DNS, 라우팅, ACL/방화벽, 목적지 응답을 계층별로 잘라서 확인하면 장애 구간을 훨씬 빠르게 좁힐 수 있습니다.NetworkAdvanced17 minProNETWORK-1291A BGP session stays up but the preferred path disappearsA routing optimization on a reflector leads one downstream edge to change behavior without any session flap.NetworkAdvanced17 minProNETWORK-160A campus fabric migration preserves the SVI gateway addresses, but one downstream ACL still keys off the old chassis MAC and security monitoring floods with false anomaliesRouting is fine, yet dependent controls still expect the previous gateway identity.NetworkAdvanced17 minProNETWORK-399A first-hop redundancy group fails over the gateway IP while one NAC or security system still authorizes the old active member based on switch identity during a staged decommissionGateway continuity hides an adjacent policy engine that keys off the old box. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.NetworkAdvanced17 minProNETWORK-153A GRE over IPsec tunnel survives WAN failover, but MSS adjustment stays on the old physical interface and large HTTP transfers start hangingOverlay continuity exists, yet payload sizing logic remained attached to the wrong underlay object.NetworkAdvanced17 minProNETWORK-1295A NAT exemption survives on paper but one backup path still translatesA VPN path works on the active firewall and fails only after failover or during HA testing.NetworkAdvanced17 minProNETWORK-148A PBR next-hop tracks the firewall IP, but the firewall can still answer ARP while the service process behind it is deadThe tracked object remains reachable even though the real dependency has failed.NetworkAdvanced17 minProNETWORK-1297A PMTUD issue affects only DNSSEC responsesUsers resolve common domains correctly and validation-heavy DNS workflows fail in one network path.NetworkAdvanced17 minProNETWORK-369A QoS policy marks the right classes while tunnel overhead changed and one class now fragments or drops before the shaped queue ever sees it during a staged decommissionClassification is correct, but the packet size math no longer fits the path. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.NetworkAdvanced17 minPro