A SysOps administrator is troubleshooting connectivity issues between an Amazon EC2 instance in a VPC and an on-premises data center connected via AWS Direct Connect. The EC2 instance can reach other instances in the same VPC but cannot reach the on-premises network. The virtual private gateway (VGW) is attached to the VPC and the Direct Connect virtual interface is up. Which configuration step should the administrator verify first?
The VPC route table must contain a route for the on-premises CIDR targeting the virtual private gateway; without it, traffic to on-premises has no path despite the Direct Connect virtual interface being up. This is the most common cause of this symptom.
Why this answer
For an EC2 instance to reach an on-premises network via Direct Connect, the VPC route table must contain a route for the on-premises CIDR block pointing to the virtual private gateway (VGW). Since the instance can reach other VPC instances, local routing works; the missing piece is the route to the on-premises destination. Without this route, traffic has no path to the VGW and is dropped.
Exam trap
SOA-C02 often tests whether candidates jump to security groups or NACLs (familiar troubleshooting steps) instead of first verifying routing—the most common cause of hybrid connectivity failures is a missing route, not a security rule.
How to eliminate wrong answers
Option A is wrong because security group rules control instance-level traffic; if they blocked traffic, the instance likely couldn't reach other VPC instances either, and the symptom is specifically on-premises reachability. Option B is wrong because the question states the Direct Connect virtual interface is up, implying VLAN association is correct; verifying it is not the first step when the VIF is already operational. Option D is wrong because network ACLs are stateless subnet-level filters; while they could block traffic, the more fundamental issue is the absence of a route, and NACLs would typically affect all traffic, not just on-premises.