ANS-C01 Network Implementation Practice Question
A company is deploying a multi-tier web application on AWS. The application consists of an Application Load Balancer (ALB), a fleet of EC2 instances in an Auto Scaling group across three Availability Zones, and an Amazon RDS for MySQL database. The ALB has a target group that routes traffic to the EC2 instances on TCP port 8080. The security group for the EC2 instances allows inbound traffic from the ALB's security group on port 8080. Users report intermittent connectivity issues to the application. A network engineer reviews the VPC Flow Logs and notices that traffic from the ALB to the EC2 instances is being recorded as 'REJECT' for some requests. What is the most likely cause of this issue?
⚠ Common exam trap
The trap here is that candidates often focus on security groups being stateful and forget that network ACLs are stateless and require explicit rules for return traffic, especially on ephemeral ports.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The network ACL associated with the EC2 instances' subnet does not have an outbound rule to allow traffic from the EC2 instances to the ALB on ephemeral ports.
The network ACL (NACL) is stateless and must have explicit outbound rules to allow return traffic from the EC2 instances back to the ALB on ephemeral ports. Since the ALB initiates connections to the EC2 instances on TCP port 8080, the return traffic from the EC2 instances uses ephemeral ports (typically 1024-65535) destined for the ALB's source port. Without an outbound rule in the subnet's NACL allowing this traffic, the NACL will reject the response packets, causing intermittent REJECT entries in VPC Flow Logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The network ACL associated with the EC2 instances' subnet does not have an outbound rule to allow traffic from the EC2 instances to the ALB on ephemeral ports.
Why this is correct
The network ACL is stateless and must allow return traffic. Missing outbound rules cause REJECT.
- ✗
The ALB's security group is blocking inbound traffic from the EC2 instances on the response path.
Why it's wrong here
The ALB does not have a security group that affects traffic to targets; target security group handles inbound.
- ✗
The ALB's target group health check is misconfigured, causing the ALB to mark instances as unhealthy and stop sending traffic.
Why it's wrong here
Health checks use the same security group rules; if instances are healthy, traffic should flow.
- ✗
The security group on the EC2 instances is stateful and automatically allows return traffic; the issue cannot be security group related.
Why it's wrong here
Security groups are stateful, but network ACLs are not; the issue is likely with the ACL, not the security group.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every ANS-C01 question from scratch — 1,621 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.