Courseiva

SOA-C02 Monitoring, Logging, and Remediation Practice Question

A SysOps administrator is troubleshooting an issue where an EC2 instance running a web server is not reachable from the internet. The instance has a public IP and is in a public subnet. The security group allows HTTP and HTTPS from 0.0.0.0/0. The network ACL allows all inbound and outbound traffic. What should the administrator check NEXT?

⚠ Common exam trap

Many exam-takers assume a public IP and permissive security groups are sufficient for internet access, overlooking the critical requirement of a route table entry pointing to an internet gateway for the subnet.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify that the subnet's route table has a route to an internet gateway.

The instance is in a public subnet with a public IP and security group allowing HTTP/HTTPS, and the network ACL allows all traffic. The most likely remaining issue is that the subnet's route table lacks a route to an internet gateway (IGW), which is required for traffic to and from the internet. Without this route, the instance cannot send responses back to internet clients, making it unreachable despite having a public IP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Check that the instance is associated with an Elastic IP address.

    Why it's wrong here

    An Elastic IP (EIP) is a static public IPv4 address that can be attached to an instance, but the instance in this scenario already has a public IP, so a second public IP would not change its ability to reach the internet. The issue of missing internet connectivity after security group and NACL checks points to a routing problem, not to the public IP address being dynamic or absent. Associating an EIP would only be relevant if the instance lacked a public IP and you needed a fixed address; it does not create or modify the subnet's route table entry to an Internet Gateway.

  • ✓

    Verify that the subnet's route table has a route to an internet gateway.

    Why this is correct

    A public subnet's route table must contain a default route (0.0.0.0/0) that targets an Internet Gateway (IGW) for outbound and inbound internet traffic to flow. Even with a public IP and permissive security group and NACL rules, if this route is missing or points to a misconfigured target, the instance cannot send or receive packets to/from the internet. Verifying the route table is the correct next step because it directly addresses the network path after you've already confirmed the stateful and stateless filtering layers.

  • ✗

    Confirm that the instance's operating system firewall is disabled.

    Why it's wrong here

    Although the operating system firewall can block internet traffic, the instance cannot communicate with the internet at all, and the question states that security groups and NACLs have already been verified. Disabling the OS firewall is a broad, disruptive action that should only be taken after confirming that network-layer routing and addressing are correct, otherwise you may mask a more fundamental configuration issue. In the AWS troubleshooting hierarchy, the route table and network path are evaluated before the OS-level configuration, so this step would be premature.

  • ✗

    Review the VPC Flow Logs for the instance's network interface.

    Why it's wrong here

    VPC Flow Logs record IP traffic metadata but do not provide visibility into the routing table configuration, which is the logical next step to verify internet reachability. This option is tempting because flow logs assist in diagnosing whether packets are being accepted or rejected by security groups; however, they only confirm connectivity exists rather than identifying why a route to an Internet Gateway is missing.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.