SOA-C02 Networking and Content Delivery Practice Question
A company has a VPC with an IPv4 CIDR block of 10.0.0.0/16. They need to add an IPv6 CIDR block to the VPC and ensure that EC2 instances can communicate over IPv6. Which step is necessary?
⚠ Common exam trap
It's easy for candidates to think attaching an IPv6-capable internet gateway is the first step, but the VPC must first have an IPv6 CIDR block assigned before any IPv6 routing or addressing can occur.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Associate an Amazon-provided IPv6 CIDR block with the VPC.
To enable IPv6 communication in an existing VPC, you must first associate an Amazon-provided IPv6 CIDR block with the VPC. This is a prerequisite for configuring subnets, route tables, and internet gateways to support IPv6 traffic. Without an IPv6 CIDR block assigned to the VPC, no EC2 instance can obtain an IPv6 address or route IPv6 traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Attach an internet gateway that supports IPv6.
Why it's wrong here
Attaching an internet gateway that supports IPv6 is not the missing step because an internet gateway (IGW) is inherently dual-stack and will forward IPv6 traffic once IPv6 is configured on the VPC and subnets. However, the IGW itself does not assign an IPv6 CIDR to the VPC; until the VPC has an associated IPv6 CIDR block, there is no IPv6 route target for the IGW. Thus, while attaching an IGW is eventually required for outbound IPv6 connectivity, it does not enable IPv6 on the VPC.
- ✗
Create a new VPC with an IPv6 CIDR block and migrate resources.
Why it's wrong here
Creating a new VPC with an IPv6 CIDR block and migrating resources is an unnecessarily disruptive alternative because AWS supports associating an IPv6 CIDR block to the existing VPC in place. Migration would require moving or recreating subnets, route tables, security groups, NACLs, VPC endpoints, and any VPC peering or Transit Gateway attachments, introducing downtime and risk. Since the existing VPC can simply be associated with an Amazon-provided IPv6 CIDR, creating a new VPC is not a valid or recommended solution.
- ✓
Associate an Amazon-provided IPv6 CIDR block with the VPC.
Why this is correct
Associating an Amazon-provided IPv6 CIDR block with the VPC is the correct first step to enable IPv6. The VPC's IPv4 CIDR remains unchanged, and AWS automatically assigns a /56 IPv6 CIDR from Amazon's global unicast address pool. After this association, you must also assign /64 IPv6 CIDRs to subnets, attach an internet gateway, update route tables, and add IPv6 rules to security groups and NACLs to complete native IPv6 support.
- ✗
Enable DNS64 in the VPC.
Why it's wrong here
Enabling DNS64 in the VPC does not give the VPC an IPv6 address range; DNS64 is a translation mechanism that synthesizes AAAA records from A records to let IPv6-only clients reach IPv4-only services. It works alongside NAT64, which translates the actual network packets, and it requires an existing IPv6 CIDR on the VPC to be useful. Therefore, DNS64 cannot replace the need to associate an IPv6 CIDR block with the VPC and is not the correct action for native IPv6 enablement.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.