SOA-C02 Deployment, Provisioning, and Automation Practice Question
A SysOps administrator is troubleshooting a failed Auto Scaling group launch. The group uses a launch template that specifies an Amazon Linux 2 AMI. The instances fail to pass the EC2 health check and are terminated. The administrator checks the system log and finds that the instance boots but the cloud-init script fails due to a missing package repository. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The AMI used by the launch template is outdated and the repositories are no longer valid.
If the AMI is outdated, the package repository URLs may be deprecated, causing cloud-init failures. The launch template version is not directly related to repository access. User data script problems could cause failures but the log points to a missing repository, which is often due to an outdated AMI. IAM role issues would affect API calls, not package repos.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The launch template is using an incorrect version.
Why it's wrong here
The launch template version controls which AMI, user data, and instance settings are applied at launch; an incorrect or old version would still honor whatever AMI/repository configuration that template points to. The failure is not caused by the version selection itself—it merely selects a configuration—so the observed cloud-init repo error would only happen if that version's AMI is itself stale. A version mismatch typically shows symptoms like mismatched instance type, security groups, or key pair, not invalid package repository URLs.
- ✗
The IAM instance profile does not have sufficient permissions.
Why it's wrong here
An IAM instance profile grants the instance permissions to make AWS API calls (e.g., to S3, SSM, or EC2 actions), but package repository access over yum/apt is an OS-level HTTPS request to public repositories and is not authenticated by IAM. Insufficient IAM permissions would cause failures when cloud-init tries to call AWS APIs for things like SSM registration or custom metadata, not when it tries to reach a repo. The error message about invalid repositories indicates the issue is the upstream repo endpoint, not the instance's AWS credentials.
- ✗
The Auto Scaling group is in a private subnet without a NAT gateway.
Why it's wrong here
A private subnet without a NAT gateway would prevent the instance from reaching the internet, so package downloads would fail with timeouts or DNS resolution errors, not with a clear 'repository no longer valid' message. The scenario states instances boot and cloud-init runs, which means the user-data script began executing; if there were no internet access, cloud-init would likely hang or report inability to connect rather than getting a definitive repo invalidity response. Therefore, the network path is probably intact, and the 'invalid repository' error points to a stale repository configuration, not to lack of outbound connectivity.
- ✓
The AMI used by the launch template is outdated and the repositories are no longer valid.
Why this is correct
An outdated AMI often contains yum or apt repository URLs that point to deprecated or retired endpoints. When cloud-init executes user data that runs package installs, the package manager tries to reach those old repositories and receives a 404 or 'repository not found' response, causing the boot-time failure. This is a common issue with Amazon Linux AMIs that have reached end-of-life, where the original repositories are no longer maintained and the instance cannot update or install software despite successfully booting.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.