Courseiva

SOA-C02 Networking and Content Delivery Practice Question

A company has a VPC with multiple subnets. An EC2 instance in a public subnet needs to communicate with an RDS database in a private subnet. The RDS security group allows inbound traffic from the EC2 instance's security group. However, the EC2 instance cannot connect. What is the most likely cause?

⚠ Common exam trap

The trap here is that candidates focus on security group or NACL misconfigurations, overlooking that DNS resolution is a prerequisite for connecting to any service using a DNS endpoint, especially when the database is in a private subnet without a direct route to a public resolver.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The VPC does not have DNS resolution enabled, so the RDS endpoint cannot be resolved.

The RDS database is in a private subnet and its endpoint is a DNS name. If DNS resolution is disabled on the VPC, the EC2 instance cannot resolve the RDS endpoint's hostname to an IP address, preventing the TCP connection from being established even though security group rules are correctly configured.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The VPC does not have DNS resolution enabled, so the RDS endpoint cannot be resolved.

    Why this is correct

    Amazon RDS exposes its database via a fully qualified domain name, such as `dbname.xxxxx.rds.amazonaws.com`, which the EC2 instance must resolve to an IP address. In a VPC, DNS resolution is governed by the `enableDnsSupport` attribute; if this is set to false, the VPC's Route 53 Resolver does not answer DNS queries. Without DNS resolution, the RDS endpoint cannot be translated into a private IP, so the connection attempt fails at the name resolution stage. This is the direct cause of the connectivity failure described.

  • ✗

    The network ACL for the private subnet blocks inbound traffic from the public subnet.

    Why it's wrong here

    A network ACL (NACL) applies at the subnet boundary, but the default NACL that AWS creates for a VPC allows all inbound and outbound traffic. Even a custom NACL would need an explicit deny rule to block traffic between the public and private subnets, and the scenario does not indicate any such rule. Since the database's security group already permits traffic from the EC2 instance, the NACL is not the reason the connection fails—the real problem is that the RDS hostname cannot be resolved. Additionally, NACLs are stateless, meaning you would need to allow both inbound and outbound for the connection, but the default configuration already permits everything.

  • ✗

    The security group of the RDS database does not allow outbound traffic.

    Why it's wrong here

    Security groups are stateful, so if you allow inbound traffic on the RDS security group, the corresponding outbound response is automatically permitted—even if no outbound rule exists. Thus, the fact that the RDS security group lacks outbound rules would not prevent the database from sending response packets back to the EC2 instance. The failure occurs before any database traffic is exchanged: the EC2 instance cannot even resolve the RDS endpoint because DNS resolution is disabled. A missing outbound rule in a security group only matters for initiating outbound connections, which is not the case here.

  • ✗

    The EC2 instance does not have a public IP address.

    Why it's wrong here

    An EC2 instance in a public subnet does not need a public IP address to reach an RDS database inside the same VPC. All internal VPC traffic is routed over private IP addresses, and the RDS DNS endpoint resolves to a private IP in the VPC. Even if the instance had no public IP and no internet gateway route, it could still connect to RDS as long as the subnet's route table and the RDS security group allow the traffic. Therefore, the absence of a public IP address is unrelated to the DNS resolution failure that is preventing the connection.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.