Home > Share your TSHOOT Experience

Share your TSHOOT Experience

August 30th, 2010 in TSHOOT Go to comments

The TSHOOT 642-832 exam has been used to replace the old ISCW & ONT exams so this article is devoted for candidates who took this exam sharing their experience. Please tell with us what are your materials, the way you learned, your feeling and experience after taking the TSHOOT exam…

Your posts are warmly welcome!

Some information I have gathered so far:

The exam is very different from other Cisco exams. You have 135 minutes for this exam.

Exam’s Structure:

+ About 3 Multichoice questions
+ 2 Drag and Drop Questions
+ 13 lab-sim Questions with the same network topology (13 troubleshooting tickets or you can call it one “big” question). Each lab-sim is called a ticket and you can solve them in any order you like.

Topics of the lab-sims:

1- IPv6
3- OSPFv3
4- Frame Relay
5- GRE
6- EtherChannel
7- RIPng
9- Redistribution
10- NTP
11- NAT
12- BGP
13- HSRP
14- STP
15- DHCP

The problems are rather simple. For example wrong IP assignment, disable or enable a command, authentication…

In each tickets you will have to answers three types of questions:

+ Which device causes problem
+ Which technology is used
+ How to fix it

When you press Done to finish each case, you can’t go back.

A demo of the TSHOOT Exam can be found at: http://www.cisco.com/web/learning/le3/le2/le37/le10/tshoot_demo.html

Note: We have gathered many questions about TSHOOT exam and posted them at TSHOOT FAQs & Tips, surely you will find useful information about the TSHOOT exam there!

In short, unlike other Cisco exams, we can go backward in this exam. That means we can choose a Troubleshooting Ticket,  browse all the configurations and hit “Abort” to ignore that Ticket. We can come back to that Ticket any time.

Below are the topologies of the real TSHOOT exam, you are allowed to study these topologies before taking the exam. It surely saves you some invaluable time when sitting in the exam room (Thanks rrg for sharing this).

IPv4 Layer 3 Topology


IPv6 Layer 3 Topology


Layer 2-3 Topology


Luckily we have a link to download and practice this lab with Packet Tracer. Please visit this page to download it: https://www.networktut.com/practice-tshoot-tickets-with-packet-tracer.

You can download the Khattak strategy to pass the exam here:


If you have any new information about this exam, please share with us!


Below is the strategy that has been used by many candidates to pass TSHOOT. Thanks to ENA for posting this.

I just come from MY exam and i passed T-shoot 1000/1000
i want share some experience there i had Only one BUG IN exam For question access map
U need to choice Aswn1 to get correct Answer
because if u make Dwsn1 U will see not there Option to get correct answer..
all those TT are the same all

The TT’s that I got are mentioned below:
1. ASW1 – Allowed Vlan
2. ASW1 – Port Security
3. ASW1 – Access Vlan
4. DSW1 – Access Map
5. DSW1 – HSRP
6. R4 – IP DHCP – first delete ip dhcp excluded-address and then enter ip dhcp excluded-address –
9. R2 – IPv6
10. R1 – NAT ACL
11. R1 – L3 Security – ACL
12. R1 – BGP – Wrong BGP Neighbor Address
13. R1 – OSPF Authentication
I didn’t get there any IP Helper there also i checked all TT and IP helper was not configured there..
Well now I want to Describe how to find more easy the TT
first with 3 TT which be ON R1..
IN 3 TT U can Ping which tickets are Nat , BGP , Access list , remember IN 3 TT U can ping which is R1
totally are 4 TT on R1 which IN one Ticket u cannot ping but u can ping
which Ticket is Ospf authentication….
Dont lose ur time use abort abort abort and abort First I found those 3 TT where I can ping and one ticket when u cannot ping but u can ping which is
ospf authenteticaton…
4 TT Gone of R4
now Find 2 TT HSRP and IPV6 which are so clearly as question….. Now totally 6 TT GOneeeee
Next steeep
FIND 4 TT which Client 1 Get IP address 169.x.x
which are Access vlan 10 , port security issused on f0/1/0 , Trunking Interface Those 3 TT u Must must must Check ON ASW1 Remember…
One TT is ON R4 Layer 3 Topology which Client get IP 169.x.x.x
which Is DHCP ON R4 router R4 – IP DHCP – first delete ip dhcp excluded-address and then enter ip dhcp excluded-address –
Now 10 TT Goneeeeeeeeeee
now Find TT which Client get IP address 10.x.x.x but cannot ping the Gateway
Using abort
that Is Access Map but in this TT is one BUG and U need to choice ASW1 to get Correct answer because doesn’t see any option Vlan acl / Port ACL *
IF u select AWS1 U will see this One Vlan Acl POrt
now 11 TT GONeeee
now 2 TT Of R4 which Client get IP address 10..x.x.x
Route Redistribute , and Passive Interfaceee ,,
I played with those 2 TT for more 20 MIN just to play and to spend the time because i did exaaamm so fast 30 MIN
and i stayed for 1 Hour
well now are ONLY 2 TT
When select One TT of them
IN one U will see wrong redistribute I mean name of spelling of Route map…
if U use abort and JUMP another TT U will see then Correctly Route map spelling name and u will see another one new with Passive Interface Under EIGRP
Well the First I end this one with wrong spelling route map..
and for this one the last with passive interface i did in the end
and u must select
no passive interface under eigrp process in Interface f0/1 and f0/0
now 13 TT GOneeeee 100%
Well also i want tell YOU something is better to Useeee 46Q there are all all all all all the answers the same when U select just there in that DUMP
are 2 questions WRONG
Interface Trunking allow vlan 10 , correct answer is 10.200
now as that dump 10.20.200 keep this In Mind..
and another one Port security In this dump 46Q are Wrong
for this one port security need to choice with shutdown and no shutdown there on dump write somthing different right
I hope this have been Information for all OF you

Here is the strategy which I Useddddddd

Problem Device Problem Description
A – > ASW1 –> Access VLAN 10 ( Layer 2 )host 1- 169.x.x.x
P – > ASW1 –> Port-Channel not allowing VLAN 10 ( layer 2 )host 1- 169.x.x.x
S – > ASW1 –> Port Security needs to be disabled ( layer 2 )host 1- 169.x.x.x
H – > DSW1 –> HSRP Track 10 ( layer 3 ) host 10.x.x.x
V – > DSW1 –> VLAN Filter ( layer 2 ) host 1 -10.x.x.x
E – > R4 –> DHCP wrong exclude address host 1- 169.x.x.x
P – > R4 -> Passive Interface Under eigrp 10 host 1 – 10.x.x.x
R – > R4 –> Route Redistribution ( layer 3 )host 1- 10.x.x.x
6 – > R2 –> IPv6 OSPF ( Ipv6 topology ) ipv6 ip add
B – > R1 –> BGP wrong Neighbor IP ( layer 3 )host 1 – 10.x.x.x
N – > R1 –> NAT ACL miss configured ( layer 3 ) host 1- 10.x.x.x
A – > R1 –> ACL blocking traffic on int ( layer 3 )host 1- 10.x.x.x
O – > R1 –> OSPF Authentication issue ( layer 3 ) host 1 – 10.x.x.x

Try the following strategy.. if you have got time… This i have found from one of the post…. your strategy is good, but how will you find out which ticket is having that particular issues… this may help you…

If you can ping Then faulty device is definitely R1. Check this website. This is 100% correct. From client ping If successful then R1 is the faulty device. It is simple concept. Any device before that does not have faulty configuration. Because you can reach R1 it means DSW1, R4, R3, R2 is allowing you to reach R1. If any of them had wrong configuration then you would not be able to ping From client I pinged more frequently then others. Once you can ping then you definitely know the fault is with R1. No doubt about about that.
1. Can be faulty BGP neighbour. Wrong ip address of neighbour. Use show run. You know where to look. Under router bgp 65001.–> sh ip bgp sum
2. Check NAT access list. Look for permit statement. If permit is not present then it is NAT Access list.
3. Check edge_security access list. If the permit statement is missing for — permit then it is IPV4 layer 3 security.
So, you can see that if you can ping but can not ping then 3 TT for R1.
Now if you can ping to but can not ping then it is definitely R1. ip ospf authentication message-digest on serial0/0/0/0.12 interface. Check configuration on R1. You will see that — ip ospf authentication message-digest is missing. So it R1, OSPF, ip ospf authentication message digest.
In total R1 has 4 TT.
3 TT — You can ping R1 but can not ping
1 TT – You can ping but can not ping
As soon as I opened a TT –> I used ipconfig to see the ip address. If it is 169.XXX then 3 TT for ASW1. If it has valid ip address such as then i immediately pined to see if the fault is with R1. 3 TT gone.

Total 6 TT gone in the blink of an eye.

ASW1 – 3 TT – if ip address is 169.xxxx
(1.switch port security: Symptoms for this ticket:-
1- Client 1 is getting 169.x.x.x ip address
2- Client 1 is unable to ping Client 2 as well as DSW1.
3- ‘sh interfaces fa1/0/1′ will show following message in the first line
‘enFastEthernet1/0/1 is down, line protocol is down (err-disabled)’
4- ‘sh running-config’, you will see ‘switchport port-security mac-address ’0000.0000.0001′ configured under fa1/0/1.
if u did not have the port in err-disable mode but in the config there was a port security mac….. command assigned
so if u do show int fa 1/0/1 it will show it as UP so do not get confused)
(2.vlan1–> vlan10)
(3.trunk allowed: int range portchannel13,portchannel23
switchport trunk allowed vlan none
switchport trunl allowed vlan 10,200)

R1 – 3TT – if you can ping R1
R1 – 1TT if you can ping but can not ping
If HSRP mentioned then you know it is DSW1
If ipv6 or ospfV3 mentioned then you know it is R2.
9 TT very simple.
Now if you can not ping or then you come back near client. Like DSW1, R4.
DSW1 – 1 more TT — Vlan ACL – Look for VLAN Access Map
R4 – 3 TT: EIGRP Passive interface , DHCP on R4 which get IP add 169.x.x , OSPF-to-EIGRP (OSPF->EIGRP).
also now we have 2 TT new to idendify them if client now get ip add 169.x.x also check ON R4 for DHCP
this new One again ON R4 for passive Interface
now totally we have 3 TT ON R4
4 TT on R1
Dws1 2 TT
R2 1 TT
Asw1 3 TT

* Note: The bug has been fixed recently so you can select DSW1 device, next page you have to scroll down and you will find the VLAN Access List/PACL option.

Best wishes to those who are going to take this exam!

Comment pages
1 76 77 78 6
  1. Asterisk
    May 17th, 2015

    In each TT we have 3 sub questions, can we change the answer of 1st and 2nd sub questions after we attempt 3rd?

  2. Tshhot
    May 17th, 2015


    Congratulations. What strategy did you use ?

  3. Tshhot
    May 17th, 2015


    Yeah we can.

  4. faizullah
    July 1st, 2015

    I have just left the the exam room. I fail with the score 372. The test is exactly the same with this vce file (for both answer and question) ,but In real exam ,I have checked the configuration of all devices are all correct ,no need to correct.. I was very confused . Can any one explain ? why ?

  5. HelloHRU
    July 1st, 2015

    Can any confirm that we can use the traceroute command on dsw1 and routers in ccnp tshoot v2. I have told only show and ping commd can be used. Please respond . eagrly waiting to write exam

  6. BuckyRocks
    July 10th, 2015

    I passed this test over a month ago. I was freaking out because I didn’t feel confident going into the test. I found this website the night before the test and practiced the SIMs 4 hour before I took it and passed. The simulations are what gave me confidence. Ping and traceroute are your friend. It is the closest to the real test and much much better than Actualtest study.

  7. moa
    November 19th, 2015

    guys im having exam on 21-11-2015 is there drag and drop
    I cant see drag and drop but i heard so ?

  8. Katja
    December 18th, 2015

    I just want to say I am just all new to weblog and deentiifly savored your blog site. Most likely I’m want to bookmark your blog post . You surely come with exceptional article content. Appreciate it for sharing your web page.

  9. Elizabeth
    December 18th, 2015

    Hi Hilary It’s live online job coinhacg. If you have a library card, go to dallaslibrary.org, click My Account and log in with your library card. Click Databases and scroll down the alphabetical list to Job Now!. Once you get to the Job Now site you’ll need to register to receive the live help.If you don’t have a library card, then you’ll need to come in to your closest library location to use Job Now!If you need assistance, email and I’ll be happy to help.

  10. Ashmel
    December 18th, 2015

    Found you through our frdiens at Cozy Travels. They shared on my blog once a while back so I got the ping when they talked about sharing on yours too. You have a fantastic blog going here. I really enjoyed this post, mostly because it’s the same way I feel. I like a Blogger involved with their community but I get so frustrated when a Blog starts to look like a self promotion page (or a self demotion page with constant whining.) Great stuff, can’t way to keep exploring your blog, looks like it has so much to offer. Could take me a while to get caught up

  11. Anonymous
    January 8th, 2016

    Please anyone who passed recently can confirm if the tickets 2,10,13 showed in the exam

  12. Anonymous
    January 8th, 2016

    can you please tell if you got HSRP Ticket??

  13. guy
    January 31st, 2016


    Next week I will have the exam

    HELP !

  14. guy
    April 4th, 2016

    @guy dont steal my name..

    YES networktut is still valid…

  15. KAMAL
    May 2nd, 2016

    Dear All,
    I have passed the exam on with 1000/1000 with the help of Network TUT T-shoot Labs and Sims, Sunday 1st May 2016.

    exam 100% from this website.

    Thanks again

  16. KAMAL
    May 2nd, 2016

    Questions in Exam,

    -OSPF authentication
    -BGP Neighbor
    -NAT ACL
    -R1 ACL
    -VLAN Filter
    -Port security
    -switch-switch connictivity
    -VLAN access 10
    -redistribution OSPF-EIGRP ipv4
    -Redistribution ripng-OSPFV3
    -GRE Tunnel
    -EIGRP Passive interface
    -IPV6 OSPF

    SIM====OSPF and EIGRP

    MCQ all valid from this website

  17. DarioFen
    October 9th, 2019

    Добрый день! Увидела у вас на сайте внутреннюю аудио панель без трубки, высылаю вам фото вызывной панели на подъезде. Подойдёт ли нам ваша панель?

  18. DarioFen
    November 22nd, 2019

    Почему такая разница о домофонов без трубки (UKP-66) белая за полторы тысячи остальные существенно больше двух тысяч, там, что золото применяют в краске?

Comment pages
1 76 77 78 6
  1. No trackbacks yet.