Courseiva

SOA-C02 Networking and Content Delivery Practice Question

A SysOps administrator is troubleshooting an issue where an EC2 instance cannot be accessed via SSH from the internet. The security group allows inbound SSH (port 22) from 0.0.0.0/0. The network ACL (NACL) for the subnet has an inbound rule allowing SSH from 0.0.0.0/0. What else could be blocking access?

⚠ Common exam trap

The trap is forgetting that NACLs are stateless; candidates often focus only on inbound rules and overlook the need for outbound rules to allow return traffic, especially for ephemeral ports.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The NACL outbound rule is blocking return traffic.

Network ACLs are stateless, meaning they evaluate inbound and outbound traffic separately. Even if the inbound rule allows SSH, the outbound rule must also allow the return traffic (ephemeral ports) for the SSH session to work. If the NACL outbound rule is blocking return traffic, the SSH connection will fail.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The NACL inbound rule is blocking traffic.

    Why it's wrong here

    The inbound NACL rule is not the cause because it explicitly permits SSH (port 22) for the source IP range. NACLs are stateless, so the inbound rule only governs the initial connection request, and since it allows SSH, the request can reach the instance's network interface. The failure is more likely in the outbound path, where response traffic to the client's ephemeral port needs a permissive rule.

  • ✗

    The internet gateway is not attached to the VPC.

    Why it's wrong here

    An unattached internet gateway (IGW) would prevent any inbound or outbound internet traffic, making it impossible to initiate an SSH session at all. However, the scenario implies the connection attempt reaches the instance and then fails or times out, which suggests network connectivity exists at the gateway level. If the IGW were missing, the issue would affect all internet access, not just the SSH response path, so this is not the correct diagnosis.

  • ✗

    The security group rule is misconfigured.

    Why it's wrong here

    The security group is stateful, meaning that if an inbound SSH rule is allowed, the return traffic for that session is automatically permitted regardless of outbound security group rules. Since the security group already allows SSH on port 22, it cannot be responsible for dropping the response packets. The symptom of an SSH timeout despite an existing allow rule points to a stateless component, such as a NACL, rather than a security group misconfiguration.

  • ✓

    The NACL outbound rule is blocking return traffic.

    Why this is correct

    NACLs are stateless, so the outbound rule is evaluated independently of the inbound rule. Even if the inbound NACL rule allows SSH (port 22) from the client, the instance's response traffic goes to a random ephemeral port (typically 1024–65535) on the client. If the outbound NACL rule does not allow these ephemeral ports, the return packets are dropped, causing the SSH connection to hang or time out. This is the classic cause of asymmetric traffic failures when using stateless filtering.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.