CCNP Enterprise
795 incident response problems that help with CCNP Enterprise prep.
먼저 읽을 가이드
추천 문제
All problems (795)
NETWORK-1338A DNS path fails only for signed domainsOperators validate DNS from a client and still see production resolvers fail selectively for signed zones.NetworkIntermediate14 minProNETWORK-1318A DNS resolver works for most records and large TXT lookups failA DNS resolver works for most records and large TXT lookups fail focuses on dns-resolution and asks the reader to isolate the key signal in Cisco. Partial DNS breakage often starts with packet-size assumptions, not name data quality.NetworkIntermediate14 minProNETWORK-1348A DNS resolver works for most zones and signed domains failA DNS resolver works for most zones and signed domains fail focuses on dns-resolution and asks the reader to isolate the key signal in Cloudflare. Stub resolver success does not prove the recursive server can complete its own fallback behavior.NetworkIntermediate14 minProNETWORK-1329A firewall path breaks oversized DNSSEC answersA security hardening change is followed by selective failures against DNSSEC-enabled domains while ordinary resolution remains fine.NetworkIntermediate14 minProNETWORK-1324A Palo Alto decryption exception covers HTTPS and the mobile client still...A Palo Alto decryption exception covers HTTPS and the mobile client still... focuses on protocol-interoperability and asks the reader to isolate the key signal in palo-alto. Protocol preference differences between clients can make one...NetworkIntermediate14 minProNETWORK-1344A Palo Alto SSL decryption bypass fixes browsers and OCSP stapling still failsA Palo Alto SSL decryption bypass fixes browsers and OCSP stapling still fails focuses on Identity And Access and asks the reader to isolate the key signal in palo-alto. TLS validation often depends on supporting service domains beyond the pri...NetworkIntermediate14 minProNETWORK-1316A Palo Alto URL override fixes one domain and another subpath still...A Palo Alto URL override fixes one domain and another subpath still... focuses on firewall-policy-basics and asks the reader to isolate the key signal in palo-alto. URL categorization can vary within a site enough to make a single broad-loo...NetworkIntermediate14 minProNETWORK-1309A QoS rollout preserves DSCP markings on access ports but still ruins voiceA QoS rollout preserves DSCP markings on access ports but still ruins voice focuses on l2-switching and asks the reader to isolate the key signal in Cisco. QoS breaks quietly when the trust boundary no longer aligns with the device that marks packets.NetworkIntermediate14 minProNETWORK-1350A reverse proxy fronting OpenSearch stays green and bulk ingest times outAn OpenSearch proxy is reorganized for route clarity and later only bulk ingest begins timing out under load.NetworkIntermediate14 minProNETWORK-1298A voice rollout fails in one buildingA standardized access template rollout degrades voice in one location even though bandwidth and VLANs look normal.NetworkIntermediate14 minProNETWORK-1327A VRF route leak seems symmetric and return traffic still diesA segmentation change appears correct during one-way tests and later breaks reply traffic or stateful sessions across VRFs.NetworkIntermediate14 minProNETWORK-1303An OSPF adjacency sticks in ExStart after a subinterface template rolloutA routing change template is applied broadly and one VLAN interface alone stops forming OSPF neighbors.NetworkIntermediate14 minProNETWORK-1275DHCP relay looks healthy but leases still failA new segment can reach the DHCP server and still never receives an address after rollout.NetworkIntermediate14 minProNETWORK-1307HSRP failover moves the VIP but users still hit the dead nodeA failover test looks good on the routers and still leaves clients blackholed for an unexpected interval.NetworkIntermediate14 minProNETWORK-1265Manual DNS tests over TCP succeed but real users still failNetwork incident scenario used for structured troubleshooting practice.NetworkIntermediate14 minProNETWORK-1270Manual DNS tests over TCP succeed but real users still failA DNS outage seems cleared after a successful test command, but applications continue failing because they never use the same transport that the operator tested.NetworkIntermediate14 minProNETWORK-1294A DHCP relay works for data VLANs but not the guest VLANA switch upgrade lands and only one VLAN stops leasing addresses while relay traffic still reaches the server.NetworkIntermediate15 minProNETWORK-1286A DHCP snooping deployment blocks one floor onlyA switch replacement introduces DHCP failures only on one access block even though the DHCP server and helper still receive the discover traffic.NetworkIntermediate15 minProNETWORK-1300A load balancer health check passes on TCP and still fails on HTTPA backend seems reachable at the port level and remains unhealthy behind a load balancer's application probe.NetworkIntermediate15 minProNETWORK-1249A manual DNS test succeeds over TCP but real clients still failAn operator proves DNS with one command and later finds the application still cannot resolve names in production.NetworkIntermediate15 minPro