Certification795 problems· 7 reviewed

CCNP Enterprise

795 incident response problems that help with CCNP Enterprise prep.

All problems (795)

NETWORK-175A mitigation community is set at the source and stripped before it reaches the edge that should act on it after an environment identity renameThe intent exists in one domain and disappears in the middle of the network. The functional path still exists, but one identity, namespace, or naming assumption still points at the previous environment contract.NetworkAdvanced20 minProNETWORK-178A mitigation community is set at the source and stripped before it reaches the edge that should act on it during a rollback rehearsalThe intent exists in one domain and disappears in the middle of the network. The steady path hides the problem until the system is asked to move backward through the dependency chain.NetworkAdvanced20 minProNETWORK-631A static summary route is valid (Rollout Stuck)A static summary route is valid (Rollout Stuck) focuses on Routing And Failover Paths and asks the reader to isolate Rollout Stuck in Cisco. 실무에서는 rollout-stuck 이슈를 볼 때 DNS, 라우팅, ACL/방화벽, 목적지 응답을 계층별로 잘라서 확인하면 장애 구간을 훨씬 빠르게 좁힐 수 있습니다.NetworkIntermediate20 minProNETWORK-088GRE keepalives pass but PMTUD blackholes the applicationTunnel control looks healthy, yet large application payloads fail because path MTU discovery signals never make it back through an intermediate filter.NetworkAdvanced20 minProNETWORK-077GRE tunnel MTU is too high and BGP over the tunnel flaps only during large updatesSmall keepalives succeed, but route churn triggers session instability because the encapsulated path cannot carry larger update packets cleanly.NetworkAdvanced20 minProNETWORK-095Route leaking between VRFs works in one direction but the return path missesForward reachability is proven, yet replies fail because the destination VRF only imports part of the leaked prefix set.NetworkAdvanced20 minProNETWORK-1230STP root placement looks intentional but one access stack goes root-inconsistentA backup uplink that is rarely used becomes active during maintenance and one stack immediately enters a root-inconsistent or blocked state.NetworkAdvanced20 minProNETWORK-1188Interface flap alarms hide that one side still negotiates the wrong speed and duplex profilePacket loss and churn appear during intermittent link events because one interface reverted to a different negotiation profile after maintenance.NetworkAdvanced21 minProNETWORK-073QinQ outer VLAN mismatch isolates one tenant even though the provider handoff is upThe carrier circuit is healthy, but one tenant stays dark because the outer service tag expected by the handoff does not match on both edges.NetworkAdvanced21 minProNETWORK-1208Stateful firewall drops only the return pathA service opens outbound sessions successfully but return packets come back through another path and get dropped.NetworkAdvanced21 minProNETWORK-1191Trunk link stays up but one VLAN is black-holedA trunk link is rebuilt after maintenance. Community threads suggest checking tagging expectations, and it turns out one side still treats a management VLAN as native.NetworkIntermediate21 minProNETWORK-067VRRP advertisements hit control-plane policing and the backup never sees master lossBoth routers are online, but failover stalls because the protection policy drops the very control traffic that should signal the state change.NetworkAdvanced21 minProNETWORK-690A static summary route is valid (Rollout Stuck)A static summary route is valid (Rollout Stuck) focuses on Routing And Failover Paths and asks the reader to isolate Rollout Stuck in Cisco. 실무에서는 rollout-stuck 이슈를 볼 때 DNS, 라우팅, ACL/방화벽, 목적지 응답을 계층별로 잘라서 확인하면 장애 구간을 훨씬 빠르게 좁힐 수 있습니다.NetworkIntermediate22 minProNETWORK-1202Asymmetric routing keeps stateful firewall sessions failing after one return path changed quietlyForward traffic reaches the service, but responses traverse another path and hit a stateful filter that never saw the original session setup.NetworkAdvanced22 minProNETWORK-066ECMP asymmetric return traffic breaks the stateful firewall even though both routers look healthyEvery routing table looks correct, yet sessions reset because the forward and return directions traverse different firewall state holders.NetworkAdvanced22 minProNETWORK-1186Health checks fail from the load balancer subnet while user traffic still worksUsers can still reach the app, but the load balancer drains targets because health checks originate from a path the firewall policy never allowed.NetworkAdvanced22 minProNETWORK-1210HTTPS health checks pass on one hostname while the real route failsAn edge service returns healthy responses to probes on one host name, while customers still see TLS errors on another.NetworkAdvanced22 minProNETWORK-083MPLS L3VPN route is present in the core but import RT mismatch keeps the customer VRF emptyThe transport side looks correct, but the service remains dark because the destination VRF never imports the route target the provider is exporting.NetworkAdvanced22 minProNETWORK-1196Source NAT hides the real client so ACL troubleshooting keeps focusing on the wrong segmentConnectivity appears blocked by an ACL on the destination side, but source NAT has already rewritten the path and the policy is evaluating a different source than operators expect.NetworkAdvanced22 minProNETWORK-058Controller telemetry fails although the management VRF can still ping the destinationBasic reachability tests look fine, but telemetry and API registration fail because the source interface or VRF binding used by the application differs from the test command path.NetworkAdvanced23 minPro