SCS-C02 Infrastructure Security Practice Question
A security engineer is troubleshooting connectivity issues between two EC2 instances in the same VPC but different subnets. Both instances have security groups that allow all traffic from each other's security group. However, traffic is still blocked. What is the most likely cause?
⚠ Common exam trap
Test-takers frequently assume security groups alone control all traffic and overlook the stateless nature of network ACLs, especially when instances are in different subnets where NACLs apply at the subnet boundary.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The network ACL for one or both subnets is blocking the traffic.
The most likely cause is that the network ACL (NACL) for one or both subnets is blocking the traffic. Security groups are stateful and allow traffic based on rules, but NACLs are stateless and require explicit inbound and outbound rules for traffic to flow. Even if security groups permit all traffic between the instances, a NACL denying the traffic (e.g., by having a default deny rule or missing ephemeral port ranges) will block it. Since the instances are in different subnets, the NACL associated with each subnet must allow the traffic in both directions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The instances are in different VPCs.
Why it's wrong here
Although inter-VPC communication requires explicit networking constructs such as VPC peering, a transit gateway, or a VPN attachment, the scenario explicitly places the instances in the same VPC. Within one VPC, all subnet CIDRs are part of the same private address space, so from a routing perspective the local route already covers them. Therefore, this option cannot explain a connectivity failure because the premise contradicts the given architecture.
- ✓
The network ACL for one or both subnets is blocking the traffic.
Why this is correct
Network ACLs are stateless filters applied at the subnet boundary and are evaluated before Security Groups. A custom network ACL with an explicit deny rule, or with an inbound allow rule that lacks a matching outbound ephemeral-port allow rule, will drop traffic even when Security Groups permit it. Since stateful Security Groups do not validate the complete bidirectional flow, a misconfigured network ACL remains a common cause of unexplained communication failures between instances.
- ✗
The route tables do not have a route between the subnets.
Why it's wrong here
Every route table in a VPC automatically contains a fixed local route with the destination set to the VPC CIDR and the target set to 'local'. This route cannot be removed or modified, and it makes traffic between subnets of the same VPC routable without any VPC peering or gateway. Thus, a missing route between subnets is impossible; the only forwarding issue would involve custom routes to external destinations, not same-VPC subnet traffic.
- ✗
VPC Flow Logs are not enabled.
Why it's wrong here
VPC Flow Logs only capture metadata about accepted and rejected traffic, such as source/destination IPs, ports, protocol, and the allow/deny action performed by security groups and network ACLs. Enabling or disabling flow logs has no influence on packet forwarding, Security Group evaluation, or network ACL behavior. Consequently, while flow logs are useful for diagnosing where the traffic was blocked, their absence cannot be the root cause of a connectivity issue.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.