SAP-C02 Continuous Improvement for Existing Solutions Practice Question
Which TWO AWS services can be used to monitor and troubleshoot network connectivity issues between EC2 instances? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VPC Reachability Analyzer.
VPC Reachability Analyzer (D) is correct because it performs static analysis of the VPC configuration and traces the path between a source and destination (such as two EC2 instances) to determine whether packets can reach the target, identifying blocking components like security groups, NACLs, route tables, and gateways. VPC Flow Logs (E) is correct because it captures IP traffic metadata (source/destination IP, ports, protocol, ACCEPT/REJECT) for ENIs, subnets, or VPCs, which is used to diagnose connectivity and traffic-filtering issues between EC2 instances. Amazon Inspector (A) is wrong because it is a vulnerability management service that scans workloads for software vulnerabilities and unintended network exposure, not a connectivity troubleshooting tool. AWS CloudTrail (B) is wrong because it records API activity and account actions for auditing, not packet-level or path-level network reachability. AWS Config (C) is wrong because it evaluates resource configuration compliance and changes over time, not live network connectivity between instances.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon Inspector.
Why it's wrong here
Amazon Inspector scans EC2 instances and container images for software vulnerabilities and unintended network exposure; it does not trace packet paths or reachability between instances. It is tempting because it reports network-related findings, and would be correct for vulnerability assessment, not for diagnosing connectivity failures.
- ✗
AWS CloudTrail.
Why it's wrong here
CloudTrail records API activity and management events in the account; it captures no packet-level or flow-level data between EC2 instances, so it cannot show where connectivity breaks. It is tempting because it is a core monitoring service, and would be correct for auditing who changed security groups or routes, not for tracing live traffic.
- ✗
AWS Config.
Why it's wrong here
AWS Config records resource configuration changes and evaluates compliance against rules; it does not capture packet-level flow logs or reachability paths between instances. It is tempting because it inventories network resources such as security groups, which is useful for auditing drift, but connectivity troubleshooting requires VPC Flow Logs and Reachability Analyzer.
- ✓
VPC Reachability Analyzer.
Why this is correct
VPC Reachability Analyzer performs static configuration analysis across ENIs, security groups, NACLs, route tables and gateways, tracing the exact hop where connectivity breaks without sending traffic. This satisfies the stem's troubleshooting requirement by pinpointing misconfigured components between EC2 instances, rather than merely reporting packet loss or flow logs.
- ✓
VPC Flow Logs.
Why this is correct
VPC Flow Logs capture IP traffic metadata for elastic network interfaces, subnets and VPCs, recording accepted and rejected packets with source and destination addresses, ports and protocol. This directly satisfies the requirement to monitor and troubleshoot connectivity between EC2 instances, revealing security group or NACL blocks.
Visual reference
Go deeper
Related to this question
About these practice questions
This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SAP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Drag and drop the steps to troubleshoot an EC2 instance that is unreachable via SSH in the correct order.
medium- ✓ A.Check security groups, then network ACLs, then public IP, then system status, then console output.
- B.Check network ACLs, then security groups, then public IP, then system status, then console output.
- C.Check public IP, then security groups, then network ACLs, then console output, then system status.
- D.Check system status, then console output, then security groups, then network ACLs, then public IP.
Why A: Start with security groups, then network ACLs, then public IP, then system status, and finally console output.
Variation 2. A DevOps engineer notices that an EC2 instance is running but is not reachable via SSH. The instance was launched with a security group that allows SSH from anywhere (0.0.0.0/0). What is the most likely cause?
easy- A.The instance does not have a public IP address.
- B.The instance is failing system status checks.
- C.The security group is not attached to the instance.
- ✓ D.The subnet's network ACL is blocking inbound SSH traffic.
Why D: The most likely cause is that the subnet's network ACL is blocking inbound SSH traffic. While the security group allows SSH from anywhere (0.0.0.0/0), network ACLs operate at the subnet level and can override security group rules. If the network ACL denies inbound traffic on port 22, SSH connections will be blocked. Option A is less likely because even without a public IP, the instance could be reached via private IP from within the VPC; the scenario implies external SSH access. Option B is incorrect because system status checks indicate underlying hardware issues, not connectivity problems. Option C is incorrect because the security group is attached by default when launching an instance, and the question confirms it allows SSH.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.