Courseiva
Network Management and OperationshardMultiple ChoiceObjective-mapped

ANS-C01 Network Management and Operations Practice Question

A network engineer is troubleshooting connectivity issues between two VPCs that are connected via VPC peering. The VPCs are in the same region and have overlapping CIDR blocks. The engineer can ping the private IP of an instance in the peered VPC from an instance in the first VPC. However, traffic on TCP port 443 (HTTPS) fails. Which is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The security group of the target instance does not allow inbound HTTPS traffic from the source

The security group of the target instance must allow inbound HTTPS traffic from the source instance's security group or CIDR. Option A is incorrect because ICMP works, indicating that network ACLs are allowing traffic; network ACLs are stateless and would block ICMP if misconfigured. Option C is incorrect because the VPC peering connection must be active for any traffic to pass, and ICMP works. Option D is incorrect because route tables must have routes to the peered VPC's CIDR for traffic to flow, and ICMP works.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The network ACL in the target subnet is blocking inbound HTTPS traffic

    Why it's wrong here

    NACLs are stateless; if they block HTTPS, they would likely block ICMP as well unless specifically allowed.

  • The security group of the target instance does not allow inbound HTTPS traffic from the source

    Why this is correct

    Security groups are stateful; ICMP may be allowed but HTTPS not.

  • The VPC peering connection is not in the 'active' state

    Why it's wrong here

    Ping works, so connection is active.

  • The route tables in both VPCs do not have routes to the peered VPC's CIDR

    Why it's wrong here

    If ping works, routing is correct.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every ANS-C01 question from scratch — 1,621 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on ANS-C01

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A network engineer is troubleshooting intermittent connectivity issues between two VPCs connected via a VPC peering connection. The engineer notices that the route tables in both VPCs have the correct routes. What should the engineer check next?

easy
  • A.Check security group and network ACL rules
  • B.Verify that DNS resolution is enabled for the VPCs
  • C.Ensure that the VPN connection is active
  • D.Check the internet gateway configuration

Why A: Security group rules and NACLs can block traffic even if routes are correct. Option B is wrong because DNS resolution is not related to basic connectivity. Option C is wrong because internet gateway is not involved in VPC peering. Option D is wrong because VPN connection is a different service.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.