Courseiva

DVA-C02 Troubleshooting and Optimization Practice Question

A developer is troubleshooting an EC2 instance that is unreachable via SSH. The instance is in a public subnet with a security group that allows inbound SSH from 0.0.0.0/0. Which THREE are possible causes? (Choose 3.)

⚠ Common exam trap

DVA-C02 often tests the difference between security groups (stateful) and NACLs (stateless), and the requirement for a public IP for internet reachability — candidates may overlook the NACL or public IP and instead blame IAM roles or key pairs, which do not affect network connectivity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The network ACL associated with the subnet is blocking inbound SSH.

Option A is correct because a network ACL is a stateless subnet-level firewall, so even if the security group allows inbound TCP port 22 from 0.0.0.0/0, an NACL rule denying inbound SSH (and the corresponding outbound ephemeral ports) will block the connection. Option C is correct because an EC2 instance in the 'stopped' state has no running OS or network stack, so SSH cannot be served regardless of subnet, security group, or IP configuration. Option E is correct because an instance in a public subnet is only reachable from the internet if it has a public IPv4 address (or an Elastic IP); without one, external SSH clients have no routable destination. Option B is not a valid cause here because an incorrect SSH key pair would cause authentication failure after the TCP connection is established, not make the instance unreachable. Option D is not a valid cause because IAM roles govern AWS API permissions, not inbound SSH access to the instance's operating system.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The network ACL associated with the subnet is blocking inbound SSH.

    Why this is correct

    Network ACLs are stateless and operate at the subnet level, so even if the security group allows inbound SSH (TCP 22) from 0.0.0.0/0, a subnet’s NACL with an explicit deny rule for inbound port 22 will block the traffic before it reaches the instance. This satisfies the stem’s constraint that the instance is unreachable despite permissive security group rules.

  • ✗

    The SSH key pair used to launch the instance is incorrect.

    Why it's wrong here

    An incorrect SSH key pair would result in an authentication failure, typically manifesting as a "Permission denied (publickey)" error *after* a successful TCP connection has been established to the instance's SSH daemon. The instance itself would still be reachable over the network, meaning the connection attempt would not time out or be refused at the network layer. Therefore, this condition does not make the instance "unreachable."

  • ✓

    The instance is in the 'stopped' state.

    Why this is correct

    When an EC2 instance is in the 'stopped' state, its virtual machine is powered off, and its operating system is not running. Consequently, the SSH daemon (sshd) service is not active, and the instance cannot respond to any network requests, including inbound SSH connection attempts. This effectively makes the instance completely unreachable over the network until it is started again.

  • ✗

    The instance does not have an IAM role with the necessary permissions.

    Why it's wrong here

    An IAM role assigned to an EC2 instance grants permissions for the *instance itself* to make API calls to other AWS services, such as S3 or DynamoDB. It does not govern or affect inbound SSH access for external users. SSH connectivity relies on network reachability, security group rules, and key-pair authentication, entirely separate from the instance's IAM role.

  • ✓

    The instance does not have a public IPv4 address.

    Why this is correct

    For an EC2 instance to be directly accessible from the public internet via SSH, it must have a public IPv4 address assigned to it. Without a public IP, the instance is only reachable from within its Virtual Private Cloud (VPC) or via a private connection like a VPN or AWS Direct Connect. Therefore, attempts to connect from the internet would fail because there is no routable public endpoint.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.