DOP-C02 Incident and Event Response Practice Question
Which THREE steps should a DevOps engineer take to troubleshoot an EC2 instance that cannot be reached via SSH? (Choose three.)
⚠ Common exam trap
The trap here is that candidates often overlook network ACLs and focus only on security groups, or they mistake a recovery action (creating an AMI) for a troubleshooting step, when the correct approach is to systematically verify the layered network controls (NACLs, security groups, and public IP assignment).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check the network ACL inbound rules for the subnet.
Network ACLs (NACLs) are stateless firewall rules applied at the subnet level. If the inbound rule for ephemeral ports or port 22 is not explicitly allowed, SSH traffic will be dropped even if the security group permits it. Checking NACL inbound rules is a fundamental step in troubleshooting connectivity issues.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Check the network ACL inbound rules for the subnet.
Why this is correct
Network ACLs are stateless, subnet-level filters that apply to all traffic crossing the subnet boundary. Even if a security group allows inbound SSH, a deny rule in the NACL inbound table for port 22 will silently drop the connection before it reaches the instance, so inspecting the subnet's inbound NACL rules is an essential first troubleshooting step.
- ✗
Verify that the corporate firewall allows SSH to the instance.
Why it's wrong here
This is outside AWS operational scope: a corporate firewall is controlled by the customer's on-premises network team, not by AWS. If the corporate firewall blocks outbound SSH, AWS-side security groups and NACLs cannot influence that, so checking it is not an AWS troubleshooting step, though it could explain a client-side connectivity failure.
- ✗
Create an AMI from the instance and launch a new one.
Why it's wrong here
This is a recovery, not a diagnostic, action. Creating an AMI and launching a new instance discards the current instance state and does not reveal whether the issue is a NACL, security group, routing, or IP assignment problem. Troubleshooting should first inspect the existing network and security configuration before considering a replacement instance.
- ✓
Check the security group inbound rules for port 22.
Why this is correct
Security groups are stateful, instance-level virtual firewalls that control inbound traffic to the resource. Because SSH over port 22 is typically denied by default, a missing or misconfigured inbound rule is one of the most common causes of SSH connection failures, so verifying allow rules for port 22 from the appropriate source CIDR is mandatory.
- ✓
Verify that the instance has a public IP address.
Why this is correct
To connect via SSH from the internet, an EC2 instance must have a public IPv4 address or an Elastic IP; without one, there is no routable destination for the SSH client. This check is independent of security group or NACL rules, which only filter traffic to an existing IP and cannot create connectivity where no public address exists.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.