Courseiva

DOP-C02 Incident and Event Response Practice Question

Network Topology
$ aws ec2 describe-instancesinstance-ids i-0abcd1234efgh5678query 'Reservations[0].Instances[0].State'Refer to the exhibit."Code": 16,"Name": "running"

An EC2 instance is in 'running' state according to the CLI output, but the application hosted on it is unreachable. The DevOps engineer checks the security group and finds it allows inbound HTTP traffic from 0.0.0.0/0. The instance has a public IP. What is the MOST likely issue?

⚠ Common exam trap

DOP-C02 often tests the misconception that security groups are the only firewall layer, leading candidates to overlook OS-level firewalls when security groups are correctly configured.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The instance's OS firewall (e.g., iptables) is blocking the traffic.

The instance is running, has a public IP, and the security group allows inbound HTTP from 0.0.0.0/0. Since the security group is correctly configured, the most likely cause is a host-level firewall (e.g., iptables, Windows Firewall) blocking the traffic. Security groups operate at the hypervisor level and do not override OS-level firewalls; thus, even with permissive security group rules, the OS can still drop packets. This is a common misconfiguration when instances are launched with restrictive default OS firewall rules.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The network ACL is blocking inbound HTTP traffic.

    Why it's wrong here

    Network ACLs are stateless filters applied at the subnet boundary, not at the instance level. If a custom network ACL denied inbound TCP port 80, every instance in that subnet would fail HTTP, whereas the problem here is isolated to one running instance. Additionally, the default VPC network ACL permits all inbound/outbound traffic, and no CLI output indicates a NACL rule blocking HTTP, so this is not the cause.

  • ✗

    The instance does not have a public IP address assigned.

    Why it's wrong here

    An EC2 instance must have a public IP or Elastic IP to accept HTTP from the internet, but the scenario explicitly shows the instance has a public IP address from the CLI output. Without a public IP, not even the correct security group or OS firewall configuration could make port 80 reachable, so this is not a variable. Since the address exists, the absence of a public IP cannot explain the connectivity failure.

  • ✗

    The security group is attached to the instance but does not allow inbound HTTP.

    Why it's wrong here

    Security groups are stateful and default-deny, and the scenario confirms that the attached security group includes an allow rule for inbound HTTP. If the rule were missing, traffic would be silently blocked for every instance using that group, not just this one, and the eventual reachability issue would point directly to the SG. Given the rule is present and correctly attached, a security group misconfiguration is not the reason.

  • ✓

    The instance's OS firewall (e.g., iptables) is blocking the traffic.

    Why this is correct

    The instance OS runs its own packet-filtering firewall—typically iptables or firewalld on Linux—which operates independently of AWS's security groups and network ACLs. Even with a permissive security group and a correct public IP, an iptables rule (e.g., default INPUT policy DROP or a REJECT rule) will drop inbound HTTP packets before they reach the web server. This is a classic scenario where all AWS-side checks pass but the instance remains unreachable, hence the CLI 'running state' does not reflect host-level firewall state.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.