Certification795 problems· 7 reviewed

CCNP Enterprise

795 incident response problems that help with CCNP Enterprise prep.

All problems (795)

NETWORK-1370A reverse proxy real-IP fix works for the app and automated bans still hit...A reverse proxy real-IP fix works for the app and automated bans still hit... focuses on incident-response and asks the reader to isolate the key signal in NGINX. Real-IP fixes are incomplete until every security parser reads the same trusted...NetworkIntermediate12 minProNETWORK-1380A WAF bypass rule appears correct and never matchesA CDN logging format is updated and later allowlists, bypass rules, or enrichment behave as though every request came from the wrong IP.NetworkIntermediate12 minProNETWORK-1426An auth gateway protects a path and an encoded traversal still reaches the...An auth gateway protects a path and an encoded traversal still reaches the... focuses on proxy-headers and asks the reader to isolate the key signal in NGINX. Path protection bugs often come from normalization order differences rather than fr...NetworkIntermediate12 minProNETWORK-1436An auth gateway protects an admin path and an encoded traversal still reaches itAn encoded admin route variant bypasses the expected auth gateway after a normalization refactor.NetworkIntermediate12 minProNETWORK-1446An auth gateway protects the admin path and an encoded traversal still reaches itAn encoded admin URL bypasses the expected auth gateway after a normalization refactor.NetworkIntermediate12 minProNETWORK-1378Cloudflare Access works on the primary app and the internal admin path loses...Cloudflare Access works on the primary app and the internal admin path... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Identity propagation can break at internal proxy hops even when the edge...NetworkIntermediate12 minProNETWORK-1335A Cisco DHCP relay works and one subnet never gets leasesA Cisco DHCP relay works and one subnet never gets leases focuses on network-segmentation and asks the reader to isolate the key signal in Cisco. Helper addresses alone do not define what identity the DHCP server sees the relay as.NetworkIntermediate13 minProNETWORK-1368A Cloudflare Access app authenticates correctly and one admin route still...A Cloudflare Access app authenticates correctly and one admin route still... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Identity headers often disappear inside the origin proxy long after e...NetworkIntermediate13 minProNETWORK-1333A Cloudflare cache purge appears successful and one path still serves stale...A Cloudflare cache purge appears successful and one path still serves stale... focuses on Deployment Governance and asks the reader to isolate the key signal in Cloudflare. A successful purge response does not prove it targeted the same cache identity m...NetworkIntermediate13 minProNETWORK-1356A Cloudflare purge request returns success and one login page stays staleA page update is pushed urgently and later only one user segment continues to receive the stale login screen or policy page.NetworkIntermediate13 minProNETWORK-1346A Netgate HA pair fails over cleanly and one package VPN stays downAn HA firewall upgrade is validated by failover tests and later one VPN tunnel fails only on the secondary node.NetworkIntermediate13 minProNETWORK-1354A Netgate policy route sends traffic out the right WAN and health checks still failA multi-WAN firewall is tuned for one application and later probes disagree with user traffic about which path is actually in use.NetworkIntermediate13 minProNETWORK-1340A pfSense HA pair passes XMLRPC sync and still divergesAn HA firewall pair is upgraded and later one node behaves differently despite successful XMLRPC config sync.NetworkIntermediate13 minProNETWORK-1342A pfSense policy route works for clients and monitoring still reports the...A pfSense policy route works for clients and monitoring still reports the... focuses on firewall-policy-basics and asks the reader to isolate the key signal in netgate. Policy routing can look correct until reply-to pins the reverse path so...NetworkIntermediate13 minProNETWORK-1352An NGINX reverse proxy preserves client IP for the app and fail2ban still...An NGINX reverse proxy preserves client IP for the app and fail2ban still... focuses on incident-response and asks the reader to isolate the key signal in NGINX. Fixing forwarded headers is not enough if downstream security automation stil...NetworkIntermediate13 minProNETWORK-1360An OpenSearch cluster behind NGINX serves queries and bulk writes time outAn OpenSearch cluster behind NGINX serves queries and bulk writes time out focuses on protocol-interoperability and asks the reader to isolate the key signal in NGINX. Search health does not prove write paths inherited the same proxy bu...NetworkIntermediate13 minProNETWORK-1322An OSPF adjacency stays in EXSTARTA routed handoff is moved to a subinterface and later OSPF neighbors stop progressing beyond EXSTART or EXCHANGE.NetworkIntermediate13 minProNETWORK-1362An OSPF adjacency stays in EXSTART after a subinterface moveA routed handoff is migrated to a subinterface and later OSPF neighbors stop progressing beyond EXSTART or EXCHANGE.NetworkIntermediate13 minProNETWORK-1277Manual DNS testing passesA DNS incident appears solved after a manual command, but applications continue failing in production.NetworkIntermediate13 minProNETWORK-1313A BGP route map change looks harmless and one edge loses reachabilityA BGP route map change looks harmless and one edge loses reachability focuses on bgp-policy-basics and asks the reader to isolate the key signal in Cisco. Policy clauses can be individually correct and collectively wrong when order changes.NetworkIntermediate14 minPro