Courseiva

SOA-C02 Networking and Content Delivery Practice Question

An organization has a VPC peering connection between VPC A and VPC B. Instances in VPC A can reach instances in VPC B, but not vice versa. What is the most likely cause?

⚠ Common exam trap

A common mix-up: candidates assume a VPC peering connection automatically enables bidirectional traffic once accepted, overlooking the requirement to manually add routes in both VPCs' route tables.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The route table in VPC B does not have a route to VPC A's CIDR.

For a VPC peering connection to allow bidirectional traffic, both VPCs must have routes in their route tables pointing to the other VPC's CIDR block. Since instances in VPC A can reach VPC B but not vice versa, the most likely cause is that VPC B's route table lacks a route to VPC A's CIDR. Without this route, VPC B's subnet does not know how to forward return traffic to VPC A, even though the peering connection itself is active.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The route table in VPC B does not have a route to VPC A's CIDR.

    Why this is correct

    For a VPC peering connection to work, both VPCs must have explicit routes in their route tables that send traffic destined for the peer's CIDR to the peering connection ID. If VPC B's route table lacks such a route to VPC A's CIDR, any return traffic from VPC B to VPC A is dropped because there is no valid next hop, even though VPC A may have a route that permits outbound traffic. This is the classic cause of one-way connectivity failures after a peering connection is accepted.

  • ✗

    DNS resolution is not enabled for the VPC peering connection.

    Why it's wrong here

    DNS resolution settings for a VPC peering connection control whether private DNS hostnames from the peer VPC are resolvable and whether the requester's DNS resolution is enabled. These are optional features that only affect name resolution, not the underlying IP packet forwarding. Instances can still communicate perfectly well using private IPv4 addresses, so the absence of DNS resolution support cannot be the root cause of a total lack of connectivity between the VPCs.

  • ✗

    Security groups in VPC B block inbound traffic from VPC A.

    Why it's wrong here

    A security group associated with an instance in VPC B could indeed block inbound traffic from VPC A, but that would only affect traffic directed to that specific instance's IP after routing has already been decided. Security groups do not influence route table lookups; they act as a stateful firewall at the instance level. If the issue were a security group block, the VPC peering connection and route tables would still be valid and you would typically see no response, whereas a missing route produces a 'network unreachable' error or a blackhole.

  • ✗

    The VPC peering connection is in a 'pending-acceptance' state.

    Why it's wrong here

    A VPC peering connection in 'pending-acceptance' state means the accepting VPC owner has not yet accepted the request, so the connection is not active and cannot be used by either side. Once accepted, the state changes to 'active'. Since the organization is experiencing a connectivity issue after presumably accepting the peering request, a pending state would be inconsistent with the scenario and is not a likely cause of the described problem; the route table misconfiguration is the more direct explanation.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.