Courseiva

CCNA Networking and Content Delivery Questions

75 of 193 questions · Page 2/3 · Networking and Content Delivery · Answers revealed

76
MCQeasy

A company hosts a static website on Amazon S3 with public read access enabled. The website is accessed via a custom domain name that uses Amazon Route 53. The domain name points to the S3 bucket's website endpoint. Users report that they can access the website using the S3 bucket URL but not the custom domain name. What is the most likely cause?

A.The S3 bucket policy does not allow public access.
B.The website does not support HTTPS and the browser blocks it.
C.The Route 53 alias record points to the S3 bucket's regional endpoint instead of the website endpoint.
D.The DNS TTL is too long and the changes have not propagated.
AnswerC

The S3 bucket has two distinct endpoints: the REST API endpoint (bucket-name.s3.amazonaws.com) and the static website endpoint (bucket-name.s3-website-region.amazonaws.com). For a custom domain to serve your static website, the Route 53 alias record must target the website endpoint, because that endpoint processes requests with the Host header matching the custom domain and returns the index document. If the alias record mistakenly points to the REST endpoint, the request is handled by the S3 API, which expects path-style addressing and returns a 403 Forbidden or a connection error when it receives a Host header for a custom domain. This is the classic misconfiguration that prevents the website from appearing.

Why this answer

For an S3 static website behind a custom domain, the Route 53 alias record must point to the bucket's S3 website endpoint (for example, bucket.s3-website-us-east-1.amazonaws.com), not the regional REST endpoint (bucket.s3.us-east-1.amazonaws.com). The regional endpoint does not serve index documents or support website redirects, so requests via the custom domain fail even though the bucket URL works. This mismatch is the most likely cause of the reported behavior.

Exam trap

SOA-C02 often tests the S3 REST endpoint vs. website endpoint distinction — candidates assume any S3 endpoint works for static hosting, but only the website endpoint serves index and error documents.

How to eliminate wrong answers

Option A is wrong because public read access is already enabled and the bucket URL works, so the bucket policy is not blocking access. Option B is wrong because S3 static website endpoints only support HTTP, and browsers do not block plain HTTP by default — the symptom would be a security warning, not a failure to resolve or load the site. Option D is wrong because a long TTL would delay propagation but would not cause a persistent failure once cached records expire, and the question describes a consistent failure rather than a transient one.

77
MCQeasy

A SysOps administrator is configuring Amazon CloudFront to serve content from an Amazon S3 bucket. The content is sensitive and should be encrypted at rest. Which option ensures that content is encrypted at rest in S3?

A.Enable server-side encryption (SSE-S3) on the S3 bucket
B.Enable CloudFront HTTPS-only access to the S3 bucket
C.Configure signed URLs for the distribution
D.Use CloudFront field-level encryption
AnswerA

Server-side encryption with S3-managed keys (SSE-S3) encrypts each object at rest using AES-256 before it is written to disk in the S3 bucket. When CloudFront makes a legitimate origin fetch, S3 transparently decrypts the object and serves it over the configured protocol, so the encryption does not interfere with content delivery. This directly satisfies an encryption-at-rest requirement for the origin storage.

Why this answer

Enabling server-side encryption (SSE-S3) on the S3 bucket ensures that objects are encrypted at rest using AES-256 encryption managed by Amazon S3. This directly addresses the requirement for content to be encrypted while stored in S3, independent of how CloudFront accesses the bucket.

Exam trap

The trap here is that candidates often confuse encryption in transit (HTTPS) or access control mechanisms (signed URLs) with encryption at rest, leading them to select options that only protect data during transfer or restrict access rather than securing stored data.

How to eliminate wrong answers

Option B is wrong because HTTPS-only access encrypts data in transit between CloudFront and S3, but does not encrypt the content at rest within the S3 bucket. Option C is wrong because signed URLs control access to content by requiring authentication, but they do not provide encryption of the data at rest in S3. Option D is wrong because CloudFront field-level encryption encrypts specific data fields at the edge during transit to the origin, not the entire object at rest in S3.

78
Multi-Selectmedium

Which TWO actions can be taken to improve the availability of a web application hosted on EC2 instances behind an Application Load Balancer? (Select two.)

Select 2 answers
A.Configure an Auto Scaling group with health checks to replace unhealthy instances.
B.Use larger EC2 instance types.
C.Deploy the EC2 instances across multiple Availability Zones.
D.Use a single AWS Region for all instances.
E.Place all EC2 instances in a single subnet.
AnswersA, C

An Auto Scaling group with ELB health checks detects instances failing load balancer health checks and terminates then replaces them automatically, restoring capacity without manual intervention. This directly addresses instance-level failure, one axis of the availability requirement.

Why this answer

Option A is correct because an Auto Scaling group configured with health checks (ELB or EC2 health checks) automatically detects and replaces unhealthy instances, maintaining the desired capacity and thus improving availability. Option C is correct because deploying EC2 instances across multiple Availability Zones provides fault isolation; if one AZ fails, the Application Load Balancer routes traffic to healthy instances in other AZs, maintaining availability. Option B is incorrect because larger instance types increase capacity/performance but do not address redundancy or failure recovery.

Option D is incorrect because using a single Region does not improve availability against AZ-level failures and is not a redundancy measure. Option E is incorrect because placing all instances in a single subnet concentrates them in one AZ, reducing availability and creating a single point of failure.

Exam trap

The trap is equating 'more capacity' (larger instances, more instances in one AZ) with 'higher availability,' when availability requires distributing across failure domains and automating recovery.

79
MCQmedium

A company hosts a web application behind an Application Load Balancer (ALB) in us-east-1. Users in Europe report high latency. The SysOps administrator decides to use AWS Global Accelerator to improve performance by directing traffic to the closest edge location. However, the application logs require the original client IP addresses of users. The ALB currently provides the client IP via the X-Forwarded-For header, but the development team warns that Global Accelerator may change the source IP. Which configuration should the administrator choose to meet both performance and logging requirements?

A.Configure Global Accelerator with an endpoint group that points directly to the ALB. The ALB will continue to receive the original client IP in the X-Forwarded-For header.
B.Place a Network Load Balancer (NLB) in front of the ALB, and configure Global Accelerator to point to the NLB. The NLB preserves the client IP, and the ALB can still see it in the X-Forwarded-For header.
C.Enable Proxy Protocol v2 on the ALB to ensure client IP addresses are preserved through Global Accelerator.
D.Use Amazon CloudFront instead of Global Accelerator and configure it to forward the client IP in a custom header.
AnswerB

Global Accelerator preserves the client source IP when the endpoint is an NLB. The NLB passes traffic to the ALB, which can see the original client IP in the X-Forwarded-For header. This satisfies both performance (using Global Accelerator) and logging requirements.

Why this answer

Placing a Network Load Balancer (NLB) in front of the ALB allows Global Accelerator to terminate the TCP connection at the edge, then forward traffic to the NLB. The NLB preserves the original client IP address by default (since it operates at Layer 4 and does not terminate the connection), and the ALB can still read the client IP from the X-Forwarded-For header. This setup meets both the performance requirement (via Global Accelerator's edge routing) and the logging requirement (preserving the original client IP).

Exam trap

The trap here is that candidates assume Global Accelerator preserves the client IP like a transparent proxy, but in reality it terminates the TCP connection at the edge, so the source IP changes unless an NLB is used to preserve it.

How to eliminate wrong answers

Option A is wrong because Global Accelerator terminates the TCP connection at the edge location and then creates a new connection to the ALB, so the source IP seen by the ALB becomes the Global Accelerator's internal IP, not the original client IP; the X-Forwarded-For header will contain the Global Accelerator's IP, not the user's IP. Option C is wrong because Proxy Protocol v2 is a feature of Network Load Balancers and TCP listeners, not Application Load Balancers; ALBs do not support Proxy Protocol v2, and enabling it on the ALB would not preserve client IP through Global Accelerator. Option D is wrong because CloudFront does not preserve the original client IP in the X-Forwarded-For header by default; it adds the CloudFront edge IP as the last entry, and while you can forward a custom header, this requires additional configuration and does not guarantee the original client IP is preserved in the same way as the NLB+ALB solution.

80
MCQmedium

A company has an on-premises data center connected to AWS via an AWS Direct Connect private virtual interface (VIF). The SysOps administrator needs to ensure that all traffic between the on-premises network and Amazon S3 in the same AWS Region stays within the AWS network and does not traverse the internet. Which solution should the administrator implement?

A.Use a Direct Connect gateway and a public VIF with a route to S3 prefix lists
B.Use a Direct Connect gateway and a private VIF with VPC endpoints for S3
C.Use a VPN connection over Direct Connect to access S3
D.Use a Transit Gateway with a private VIF and route S3 traffic through a NAT instance
AnswerB

A private VIF creates a dedicated private network connection between your on-premises data center and a VPC, while a VPC Gateway Endpoint for S3 privately connects the VPC to S3 without traversing the internet. Traffic from on-premises flows via the private VIF into the VPC and then through the Gateway Endpoint directly to S3 over AWS's internal network, successfully meeting the requirement for high-bandwidth, fully private S3 access. This is the recommended AWS architecture for private S3 connectivity over Direct Connect.

Why this answer

A private VIF with VPC endpoints for S3 (Gateway Endpoints) ensures that traffic from on-premises to S3 stays within the AWS network. The private VIF provides connectivity to the VPC, and the Gateway Endpoint routes S3 traffic through the AWS backbone without traversing the internet. This combination meets the requirement of keeping traffic within the AWS network.

Exam trap

The trap here is that candidates often confuse public VIF with private VIF, thinking a public VIF is required for AWS service access, but Gateway Endpoints allow private VIF to access S3 without internet exposure.

How to eliminate wrong answers

Option A is wrong because a public VIF with a route to S3 prefix lists would still route traffic over the public internet (via the Direct Connect public VIF), which does not guarantee that traffic stays within the AWS network; it also requires routing over the internet gateway. Option C is wrong because a VPN connection over Direct Connect would encrypt traffic but still uses the public VIF or internet path, and it does not inherently keep traffic within the AWS network; it adds unnecessary complexity and does not meet the requirement of staying within the AWS network. Option D is wrong because a Transit Gateway with a private VIF and routing S3 traffic through a NAT instance would force traffic through a NAT instance, which typically uses an internet gateway to reach S3, thus traversing the internet; this violates the requirement.

81
MCQeasy

A company hosts a web application on EC2 instances behind an Application Load Balancer. Users report intermittent 503 errors. Which step should the SysOps administrator take to troubleshoot the issue?

A.Verify the target group health check settings.
B.Enable cross-zone load balancing.
C.Increase the idle timeout on the load balancer.
D.Add more subnets to the load balancer.
AnswerA

The 503 Service Unavailable response from an Application Load Balancer specifically indicates that the target group contains no registered instances that are passing health checks. Health check settings, such as the configured path, expected HTTP success codes, interval, timeout, and unhealthy threshold, directly determine whether EC2 instances are marked healthy or unhealthy. If the health check path returns a non-2xx status due to an application misconfiguration, or if the health check port is blocked by a security group, all targets can be flagged unhealthy, triggering a 503. Verifying and correcting these settings is the first and most effective remediation step.

Why this answer

Intermittent 503 errors from an Application Load Balancer typically indicate that the target instances are failing health checks or are unable to handle the request load. Verifying the target group health check settings (e.g., path, interval, threshold, and protocol) is the first troubleshooting step because if the health checks are misconfigured or the targets are unhealthy, the ALB will stop routing traffic to them, resulting in 503 responses.

Exam trap

The trap here is that candidates often confuse 503 errors with timeout or capacity issues and jump to increasing idle timeout or adding subnets, rather than recognizing that 503 errors from an ALB almost always point to target health check failures.

How to eliminate wrong answers

Option B is wrong because cross-zone load balancing is enabled by default on Application Load Balancers and does not cause intermittent 503 errors; it distributes traffic evenly across all targets in all enabled Availability Zones. Option C is wrong because increasing the idle timeout on the load balancer affects how long the ALB keeps idle connections open, not the availability or health of targets; 503 errors are not related to idle timeout settings. Option D is wrong because adding more subnets to the load balancer increases its availability and capacity but does not directly resolve intermittent 503 errors caused by unhealthy targets or misconfigured health checks.

82
MCQmedium

A company has two Amazon VPCs: VPC-A (10.0.0.0/16) and VPC-B (10.1.0.0/16) in the same AWS Region. The SysOps administrator needs to enable private IP connectivity between the two VPCs without using the public internet. The solution must be simple, low-cost, and provide high throughput. Which AWS service should the administrator use?

A.VPC peering
B.AWS Site-to-Site VPN
C.AWS Direct Connect
D.AWS Transit Gateway
AnswerA

VPC peering establishes a direct, private network connection between two VPCs using the AWS backbone. It is simple to set up, has low cost (no hourly fees, only data transfer charges), and provides high throughput with no bandwidth constraints.

Why this answer

VPC peering is the correct choice because it enables direct private IP connectivity between two VPCs using the AWS global network, without requiring internet gateways, VPNs, or physical connections. It is simple to set up (no additional hardware or software), low-cost (no per-hour charges, only data transfer costs), and provides high throughput (bandwidth is limited only by the instance types, not by the peering connection itself).

Exam trap

The trap here is that candidates often over-engineer the solution by choosing AWS Transit Gateway (Option D) for its advanced features, forgetting that for a simple two-VPC connection, VPC peering is the most cost-effective and straightforward option without unnecessary complexity.

How to eliminate wrong answers

Option B (AWS Site-to-Site VPN) is wrong because it requires a virtual private gateway on each VPC and an on-premises VPN endpoint, adding complexity and cost (per-hour charges) while throughput is limited by the VPN tunnel (typically up to 1.25 Gbps per tunnel). Option C (AWS Direct Connect) is wrong because it is designed for dedicated on-premises to AWS connectivity, not for VPC-to-VPC peering, and involves high cost, long provisioning times, and physical infrastructure. Option D (AWS Transit Gateway) is wrong because while it can connect multiple VPCs, it introduces additional cost (per-hour and per-GB charges) and complexity (requires transit gateway attachments and route table management) that is unnecessary for a simple two-VPC scenario.

83
Multi-Selecteasy

A company wants to use Amazon CloudFront to distribute content globally with low latency. Which TWO features of CloudFront help achieve this?

Select 2 answers
A.Regional edge caches that provide additional caching layers
B.Edge locations that cache content near users
C.Use of S3 Transfer Acceleration
D.VPC peering to connect to origins
E.Integration with AWS Global Accelerator
AnswersA, B

Regional edge caches are a middle-tier layer between CloudFront edge locations and the origin server. They have larger storage capacity than edge locations and retain content longer, which improves cache hit ratios for content that is requested less frequently. When an edge location misses, it can fetch from the regional edge cache instead of hitting the origin directly, reducing origin load and latency. This is a native CloudFront architecture component, not a separate service.

Why this answer

Option B is correct because CloudFront's global network of edge locations caches content at sites physically close to end users, so requests are served from the nearest point of presence and round-trip latency is minimized. Option A is correct because regional edge caches sit between the edge locations and the origin, providing an additional, larger caching layer that keeps less-popular content cached longer and reduces the number of origin fetches, which further lowers latency and improves hit ratios. Option C is not correct because S3 Transfer Acceleration speeds up uploads to S3 buckets over the AWS backbone and is not a CloudFront content-delivery feature.

Option D is not correct because VPC peering connects VPCs privately and does not provide global edge caching or low-latency content distribution. Option E is not correct because AWS Global Accelerator is a separate service that routes traffic over the AWS global network using static anycast IPs; it is not a CloudFront feature used to achieve edge caching.

Exam trap

SOA-C02 often tests the distinction between CloudFront's built-in caching features (edge locations and regional edge caches) and other AWS services like S3 Transfer Acceleration or Global Accelerator that also aim to reduce latency but are not part of CloudFront.

84
MCQmedium

A company uses Amazon CloudFront to deliver its static website hosted on Amazon S3. The security team notices that users are able to access the S3 bucket directly via the S3 endpoint, bypassing CloudFront. What should be done to ensure that content is only accessible through CloudFront?

A.Create an origin access identity (OAI) and update the S3 bucket policy to grant access only to the OAI
B.Use AWS WAF to block requests that do not include the CloudFront distribution's domain name
C.Create an AWS Lambda@Edge function to validate headers
D.Use S3 Block Public Access to prevent all public access
AnswerA

An origin access identity (OAI) is a CloudFront user that serves as the only AWS principal allowed to read objects from your S3 bucket. After you associate the OAI with the CloudFront distribution, update the bucket policy so it grants the s3:GetObject action strictly to that OAI's principal ARN or canonical user ID. Any request that goes directly to the S3 bucket's HTTPS endpoint is then denied with AccessDenied, because the requester is not the OAI. This ensures the only way to fetch content is through CloudFront, which is exactly the intended behavior.

Why this answer

An Origin Access Identity (OAI) is a special CloudFront user that can be associated with a CloudFront distribution. By updating the S3 bucket policy to grant read access only to that OAI's canonical user ID, the bucket becomes inaccessible via direct S3 endpoints, while CloudFront can still fetch and serve the content. This enforces that all traffic must go through CloudFront.

Exam trap

The trap here is that candidates often confuse OAI with S3 Block Public Access, thinking that blocking all public access will still allow CloudFront access, but Block Public Access applies to all principals including CloudFront unless the bucket policy explicitly grants access to the OAI.

How to eliminate wrong answers

Option B is wrong because AWS WAF can inspect HTTP headers, but the CloudFront distribution's domain name is not a reliable header that can be enforced; users can spoof headers, and WAF cannot prevent direct S3 endpoint access since S3 does not integrate with WAF. Option C is wrong because a Lambda@Edge function can validate or modify headers, but it runs within CloudFront's processing, not on the S3 bucket itself; it cannot block direct S3 endpoint access. Option D is wrong because S3 Block Public Access prevents all public access to the bucket, which would also block CloudFront from accessing the bucket, breaking the intended architecture.

85
MCQmedium

A web application is deployed in us-east-1 (primary) and eu-west-1 (standby). Under normal conditions, all traffic should go to us-east-1. If the us-east-1 health check fails, traffic must automatically redirect to eu-west-1 within 30 to 60 seconds. What Route 53 configuration implements this?

A.Create failover routing records for the domain: a Primary record pointing to us-east-1 with a Route 53 health check, and a Secondary record pointing to eu-west-1 with no health check
B.Use weighted routing with 100 weight for us-east-1 and 0 weight for eu-west-1; update the weights via Lambda when a CloudWatch alarm fires
C.Enable Route 53 latency routing with records for both regions; Route 53 will automatically switch to eu-west-1 when us-east-1 becomes unavailable
D.Configure Route 53 geolocation routing to send all US traffic to us-east-1 and all European traffic to eu-west-1
AnswerA

When the health check on the Primary record fails for the configured number of consecutive intervals, Route 53 removes the Primary from DNS responses and serves the Secondary. DNS TTL on the records should be set low (60 seconds or less) to minimize client-side caching delay. The failover is automatic, with no manual intervention or Lambda functions required.

Why this answer

Route 53 failover routing records, combined with a health check on the primary record, automatically redirect traffic to the secondary (standby) record when the primary health check fails. The health check interval and failure threshold can be configured to detect failure within 30–60 seconds, meeting the requirement without manual intervention.

Exam trap

The trap here is that candidates often confuse failover routing with latency or geolocation routing, assuming that Route 53 automatically considers health in those routing policies, but only failover routing explicitly supports active-passive failover with health checks.

How to eliminate wrong answers

Option B is wrong because weighted routing with 0 weight for eu-west-1 would never send traffic there, even if us-east-1 fails, unless the weights are updated externally; this approach cannot achieve automatic failover within 30–60 seconds without additional automation and introduces latency. Option C is wrong because latency routing selects the region with the lowest latency for each user, not based on health; if us-east-1 is unhealthy but still has low latency, traffic would continue to be sent there, failing the failover requirement. Option D is wrong because geolocation routing directs traffic based on the user's geographic location, not health; it would not redirect traffic from us-east-1 to eu-west-1 if us-east-1 fails, as users outside Europe would still be routed to the unhealthy primary region.

86
MCQeasy

A company has multiple on-premises branch offices, each with a site-to-site VPN connection to a single VPC in AWS. The SysOps administrator needs to enable communication between the branch offices using the AWS cloud as a hub. Which configuration should be implemented to achieve this with the least operational overhead?

A.Configure static routes in the VPC route table pointing to each VPN connection.
B.Use dynamic routing (BGP) on all VPN connections and enable route propagation on the virtual private gateway (VGW).
C.Create a separate Transit VPC with EC2-based VPN appliances to route traffic between branch offices.
D.Place all branch offices in the same IPsec tunnel by configuring identical pre-shared keys.
AnswerB

Configuring BGP on every Site-to-Site VPN connection and enabling route propagation on the VPC route table for the virtual private gateway (VGW) allows the VGW to automatically exchange route information between all attached VPN connections. Each branch's BGP session advertises its local CIDRs, and those routes are installed into the VPC route table via route propagation, so traffic from one branch to another is forwarded through the VGW without manual entries. This is the native AWS mechanism for a hub-and-spoke setup where the VPC is the hub and branch offices are spokes, enabling dynamic, self-updating inter-branch communication.

Why this answer

Enabling dynamic routing (BGP) on all VPN connections and propagating routes from the virtual private gateway (VGW) into the VPC route table allows each branch office to learn the CIDR blocks of all other branch offices automatically. This eliminates the need for manual static route entries and ensures that traffic between branch offices is routed through the VPC hub with minimal operational overhead, as BGP handles failover and route updates dynamically.

Exam trap

The trap here is that candidates often assume static routes are simpler and sufficient for hub-and-spoke communication, overlooking that BGP route propagation on the VGW provides automated, scalable route exchange with minimal ongoing management, which is the key to reducing operational overhead.

How to eliminate wrong answers

Option A is wrong because configuring static routes in the VPC route table pointing to each VPN connection would require manual updates whenever a branch office subnet changes or a VPN connection is added/removed, increasing operational overhead and not scaling well. Option C is wrong because creating a separate Transit VPC with EC2-based VPN appliances introduces significant complexity, cost, and maintenance overhead compared to using the native VGW with BGP route propagation. Option D is wrong because placing all branch offices in the same IPsec tunnel by configuring identical pre-shared keys is not a valid configuration; each site-to-site VPN connection must have unique tunnel settings, and this approach would cause routing conflicts and security issues, not enable inter-branch communication.

87
MCQmedium

An organization uses Amazon CloudFront to serve static content from an S3 bucket. The content is updated frequently, but users are seeing stale files. What is the most efficient way to invalidate the cache for updated objects?

A.Create a CloudFront invalidation for the updated files.
B.Use the S3 console to set a new cache-control header.
C.Change the origin path in the CloudFront distribution.
D.Delete and recreate the CloudFront distribution.
AnswerA

CloudFront invalidation is the designed mechanism to force edge locations to discard the cached copies of specified files immediately. When you submit an invalidation for the updated objects, CloudFront stops serving the stale versions and fetches the current ones from the S3 origin on the next request. This is a targeted, low-overhead operation that does not disrupt the distribution or require any configuration changes, making it the correct approach.

Why this answer

CloudFront caches objects at edge locations based on the cache key (path, headers, query strings). When origin content changes, the edge cache still serves the old object until TTL expires. Creating an invalidation explicitly purges the specified paths from all edge locations, forcing CloudFront to fetch fresh content from the S3 origin on the next request.

This is the fastest, most targeted way to serve updated files without waiting for TTL expiry.

Exam trap

SOA-C02 often tests the misconception that changing cache headers or S3 metadata retroactively purges already-cached objects — candidates must remember that only an explicit invalidation (or a new cache key) removes content already stored at edge locations.

How to eliminate wrong answers

Option B is wrong because setting a new Cache-Control header on the S3 object only affects future cache decisions after the object is re-fetched — it does not purge objects already cached at edge locations, so users still see stale content until TTL expires. Option C is wrong because changing the origin path alters where CloudFront fetches content from, which would break the distribution's mapping to the S3 bucket rather than invalidate cached objects. Option D is wrong because deleting and recreating the distribution is disruptive, changes the distribution's domain name, requires DNS updates, and takes significant time to redeploy — far less efficient than a simple invalidation.

88
MCQmedium

An organization has a VPC peering connection between VPC A and VPC B. Instances in VPC A can reach instances in VPC B, but not vice versa. What is the most likely cause?

A.The route table in VPC B does not have a route to VPC A's CIDR.
B.DNS resolution is not enabled for the VPC peering connection.
C.Security groups in VPC B block inbound traffic from VPC A.
D.The VPC peering connection is in a 'pending-acceptance' state.
AnswerA

For a VPC peering connection to work, both VPCs must have explicit routes in their route tables that send traffic destined for the peer's CIDR to the peering connection ID. If VPC B's route table lacks such a route to VPC A's CIDR, any return traffic from VPC B to VPC A is dropped because there is no valid next hop, even though VPC A may have a route that permits outbound traffic. This is the classic cause of one-way connectivity failures after a peering connection is accepted.

Why this answer

For a VPC peering connection to allow bidirectional traffic, both VPCs must have routes in their route tables pointing to the other VPC's CIDR block. Since instances in VPC A can reach VPC B but not vice versa, the most likely cause is that VPC B's route table lacks a route to VPC A's CIDR. Without this route, VPC B's subnet does not know how to forward return traffic to VPC A, even though the peering connection itself is active.

Exam trap

The trap here is that candidates often assume a VPC peering connection automatically enables bidirectional traffic once accepted, overlooking the requirement to manually add routes in both VPCs' route tables.

How to eliminate wrong answers

Option B is wrong because DNS resolution (enabling 'DNS resolution' or 'DNS hostnames' for the peering connection) affects whether instances can resolve private DNS names across VPCs, but it does not control basic IP-level reachability; the issue here is unidirectional connectivity, not DNS resolution. Option C is wrong because security groups in VPC B blocking inbound traffic from VPC A would prevent all traffic from VPC A to VPC B, but the question states that instances in VPC A can reach VPC B, so security groups are not the cause of the reverse failure. Option D is wrong because if the VPC peering connection were in a 'pending-acceptance' state, no traffic would flow in either direction; the fact that VPC A can reach VPC B confirms the connection is active and accepted.

89
MCQmedium

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB) in a VPC. Users report slow load times. The SysOps team notices that all traffic goes to a single availability zone. Which action should be taken to improve performance and reliability?

A.Configure the ALB to use subnets in at least two Availability Zones
B.Add more EC2 instances in the same Availability Zone
C.Replace the ALB with a Network Load Balancer (NLB)
D.Enable cross-zone load balancing on the ALB
AnswerA

To provide high availability, the Application Load Balancer (ALB) must be enabled in multiple Availability Zones by associating it with at least one subnet in each AZ. The ALB service creates a load balancer node in each enabled AZ, allowing it to route traffic to targets in those AZs and to continue serving requests if one AZ fails. Without multi-AZ subnet configuration, the ALB and its single node become a single point of failure, negating the resilience of having multiple EC2 instances across AZs. This is the foundational action required to meet fault-tolerance requirements.

Why this answer

The correct action is to configure the ALB to use subnets in at least two Availability Zones. An ALB is a regional service that requires subnets in multiple AZs to distribute incoming traffic across healthy targets in those zones. When all traffic goes to a single AZ, it indicates the ALB is only attached to one subnet, creating a single point of failure and limiting the pool of EC2 instances that can serve traffic, which directly causes slow load times and reduced reliability.

Exam trap

The trap here is that candidates often confuse cross-zone load balancing (which distributes traffic across instances within an AZ) with multi-AZ subnet configuration (which enables the ALB to route traffic to instances in different AZs), leading them to incorrectly select option D.

How to eliminate wrong answers

Option B is wrong because adding more EC2 instances in the same Availability Zone does not address the root cause—the ALB is only routing traffic to one AZ, so all new instances would still be in that same AZ, failing to distribute load or improve fault tolerance. Option C is wrong because replacing the ALB with a Network Load Balancer (NLB) does not solve the single-AZ issue; an NLB also requires subnets in multiple AZs for high availability, and the problem is about AZ configuration, not load balancer type. Option D is wrong because cross-zone load balancing on an ALB is enabled by default and controls distribution of traffic across instances within the same AZ, not across AZs; it does not fix the issue of the ALB only having subnets in one AZ.

90
MCQeasy

A company needs to resolve DNS names for on-premises servers from AWS. They have set up a DHCP options set with the on-premises DNS server IP. Which additional step is required?

A.Create a VPC peering connection and use the on-premises DNS IP as the DHCP option set.
B.Configure Route 53 Resolver outbound endpoint to forward queries to on-premises DNS.
C.Create a VPC peering connection to the on-premises network.
D.Configure Route 53 Resolver inbound endpoint to forward DNS queries from on-premises to AWS.
AnswerB

A Route 53 Resolver outbound endpoint is the correct answer because it allows DNS queries initiated from within the VPC to be forwarded to an on-premises DNS server via a forwarding rule. The endpoint consists of elastic network interfaces (ENIs) in your subnets that receive queries from instances, evaluate the forwarding rules (e.g., by domain name), and forward matching queries over your VPN or Direct Connect to the on-premises resolver. This enables AWS resources to resolve hostnames for on-premises servers, fulfilling the requirement directly.

Why this answer

The DHCP options set configures VPC resources to use the on-premises DNS server IP. However, to actually forward DNS queries from the VPC to the on-premises DNS server for resolution of on-premises hostnames, you need a Route 53 Resolver outbound endpoint. This endpoint provides a forwarding path from the VPC to the on-premises network (over VPN or Direct Connect).

Option D (inbound endpoint) is used for the reverse direction—allowing on-premises DNS to forward queries to AWS for resolving private hosted zones—and is not required here. Options A and C are incorrect because VPC peering does not enable DNS resolution to on-premises networks; dedicated connectivity and DNS forwarding via Route 53 Resolver are needed.

Exam trap

The trap is confusing the direction of DNS forwarding. Candidates often select the inbound endpoint (Option D) thinking it forwards queries from AWS to on-premises, but in reality, the inbound endpoint handles queries coming from on-premises into AWS. The correct direction for AWS-to-on-premises forwarding is the outbound endpoint (Option B).

How to eliminate wrong answers

Option A is wrong because a VPC peering connection does not inherently forward DNS queries; it only enables network connectivity between VPCs, and using the on-premises DNS IP as a DHCP option set is already done. Option B is wrong because a Route 53 Resolver outbound endpoint forwards queries from AWS to on-premises, which is the opposite direction needed; the requirement is to resolve on-premises DNS names from AWS, not the other way. Option C is wrong because a VPC peering connection cannot be established to an on-premises network; VPC peering is only between VPCs, not between a VPC and an on-premises data center.

91
Multi-Selecthard

A company has a VPC with public and private subnets in two Availability Zones. The private subnets need outbound internet access for EC2 instances to download updates. Which THREE components are required to achieve this? (Choose three.)

Select 3 answers
A.Route table in the private subnets with a default route pointing to the NAT Gateway
B.Internet Gateway attached to the VPC
C.Egress-only Internet Gateway
D.NAT Gateway in a public subnet
E.AWS Site-to-Site VPN connection
AnswersA, B, D

The route table associated with the private subnets must contain a default route (0.0.0.0/0) pointing to the NAT Gateway's network interface. This ensures that any outbound IPv4 traffic from instances in those subnets is forwarded to the NAT Gateway for translation. Without this route, private instances would have no path to the internet, even though the NAT Gateway exists.

Why this answer

A route table associated with private subnets must have a default route (0.0.0.0/0) pointing to a NAT Gateway to direct outbound internet traffic from EC2 instances through the NAT device. This allows instances in private subnets to initiate outbound connections to the internet (e.g., for software updates) while preventing unsolicited inbound connections from the internet.

Exam trap

The trap here is that candidates often confuse the Egress-Only Internet Gateway (IPv6 only) with the NAT Gateway (IPv4) or think a VPN connection can provide internet access, when in fact a NAT Gateway in a public subnet plus an Internet Gateway are required for IPv4 outbound connectivity from private subnets.

92
MCQhard

A company is using Amazon CloudFront with an S3 bucket as the origin. The S3 bucket contains sensitive data that should only be accessible via CloudFront. The SysOps administrator has configured an Origin Access Identity (OAI) and updated the bucket policy to allow access only to the OAI. However, users are still able to access the S3 bucket directly via the S3 URL. What is the most likely reason?

A.The bucket policy does not include a condition to require the OAI.
B.The bucket policy allows public read access in addition to the OAI access.
C.The OAI is not properly associated with the CloudFront distribution.
D.The S3 bucket is configured as a static website.
AnswerB

If the bucket policy includes an allow statement for s3:GetObject with Principal: "*", every internet user who knows the object's direct S3 URL can read it without using CloudFront. This is a common misconfiguration when administrators add the OAI allow rule but forget to remove the public read rule, leaving two paths to the content. The correct policy must only permit the OAI principal and, if needed, explicitly deny all other principals to prevent bypass.

Why this answer

The most likely reason users can still access the S3 bucket directly is that the bucket policy contains a statement granting public read access (e.g., 'Principal': '*') in addition to the OAI allow statement. Even with OAI configured, an explicit public allow overrides the restriction. The bucket policy must be reviewed to remove any public access grants.

Exam trap

SOA-C02 often tests the misconception that configuring OAI alone secures the bucket, when in fact an existing public bucket policy statement can still allow direct access, and candidates must identify that as the root cause.

How to eliminate wrong answers

Option A is wrong because the OAI condition is typically included in the bucket policy as a 'Condition' with 'aws:SourceArn' or 'aws:UserAgent', but the absence of a condition is not the primary reason for direct access if the policy already allows the OAI; the issue is an additional public allow. Option C is wrong because if the OAI were not properly associated, CloudFront would not be able to access the bucket, but users accessing directly would still be blocked if the bucket policy only allowed the OAI. Option D is wrong because configuring the bucket as a static website does not inherently make it public; public access depends on the bucket policy and ACLs, and static website hosting requires public read, but the question states the bucket policy was updated to allow only OAI, so the static website setting alone would not override that.

93
MCQhard

A company uses AWS Global Accelerator to improve performance of a TCP application. Users in Asia report higher latency than users in Europe. The endpoints are all in us-east-1. What is the BEST solution?

A.Create a VPC peering connection between us-east-1 and an Asia region.
B.Add more endpoints in us-east-1 to distribute load.
C.Switch to Amazon CloudFront for the TCP application.
D.Deploy additional endpoints in an Asia region and configure Global Accelerator to route traffic to the closest endpoint.
AnswerD

Global Accelerator routes users to the nearest healthy endpoint, so adding endpoints in an Asia region places compute closer to those users, cutting round-trip latency. With endpoints only in us-east-1, Asian traffic must still cross the Pacific, which no accelerator tuning can remove.

Why this answer

VPC peering does not affect Global Accelerator routing; Global Accelerator uses Anycast IPs and routes to endpoints based on location, not VPC peering. Option B is incorrect because adding more endpoints in us-east-1 does not reduce latency for users in Asia; they still have to travel across the Atlantic and Pacific. Option C is incorrect because CloudFront is designed for HTTP/HTTPS (and WebSockets), not general TCP applications.

Global Accelerator supports TCP/UDP. Option D is correct because deploying endpoints in an Asia region and configuring Global Accelerator to route traffic to the closest endpoint reduces latency for Asian users.

94
MCQmedium

A company is deploying a web application on EC2 instances behind an Application Load Balancer (ALB). The application needs to maintain user session state. Which configuration ensures session stickiness with minimal performance impact?

A.Use Amazon CloudFront with origin stickiness enabled.
B.Use a Network Load Balancer (NLB) with target group stickiness.
C.Enable sticky sessions on the Application Load Balancer using a load balancer-generated cookie.
D.Store session state in Amazon DynamoDB and have each instance read from DynamoDB.
AnswerC

The Application Load Balancer supports sticky sessions by generating a durable cookie (AWSALB) that is stored in the client's browser and mapped to the specific EC2 instance that handled the initial request. On subsequent requests, the ALB reads this cookie and routes the client to the same instance for the duration of the cookie's lifetime or until the instance becomes unhealthy. This mechanism is purpose-built for session-stateful web applications, and it adds negligible overhead because the routing decision is made entirely on the ALB without requiring external database reads or application code changes.

Why this answer

Enabling sticky sessions on an Application Load Balancer (ALB) using a load balancer-generated cookie (AWSALB) binds a user's session to a specific target instance with minimal overhead. The ALB inserts the cookie in the response, and subsequent requests from the same client are routed to the same instance without requiring application-level session replication or external storage, thus preserving performance.

Exam trap

The trap here is that candidates often confuse session stickiness with session persistence via external storage (DynamoDB) or assume a Network Load Balancer can provide cookie-based stickiness, but the exam tests the specific AWS service capabilities: only ALB supports cookie-based sticky sessions at Layer 7 with minimal performance impact.

How to eliminate wrong answers

Option A is wrong because CloudFront origin stickiness is not a native feature; CloudFront can forward cookies but does not itself maintain session stickiness to EC2 instances behind an ALB, and adding CloudFront introduces unnecessary latency and complexity for this use case. Option B is wrong because a Network Load Balancer (NLB) operates at Layer 4 and does not support cookie-based stickiness; its target group stickiness uses source IP hashing, which can cause uneven load distribution and does not work well with clients behind NAT or proxies. Option D is wrong because storing session state in DynamoDB and having each instance read from it adds network latency and increases cost per request, degrading performance compared to the lightweight cookie-based stickiness provided by the ALB.

95
MCQhard

A SysOps administrator receives an alert that a VPN connection between a VPC and an on-premises network is down. The VPN uses static routing. After verifying the on-premises side is functioning, what should the administrator check in AWS?

A.Check the BGP session status.
B.Reboot the virtual private gateway.
C.Ensure the route table has a route to the virtual private gateway.
D.Verify that the customer gateway device is configured with the correct IP address.
AnswerD

The customer gateway device represents the on-premises endpoint of the VPN tunnel, and its public IP address is a required parameter. If the IP address configured in AWS for the customer gateway does not match the actual public IP of the on-premises device—for example if it changed or NATed—the IPsec negotiation cannot succeed. Verifying this critical endpoint configuration is the first step in troubleshooting a downed tunnel because it prevents the security associations from ever being established. This directly addresses the root cause of a failed VPN connection.

Why this answer

Since the VPN uses static routing, BGP is not in use, so checking BGP session status (Option A) is irrelevant. Rebooting the virtual private gateway (Option B) is a disruptive action that should not be a first step without identifying the root cause. Ensuring the route table has a route to the virtual private gateway (Option C) is important for traffic flow but does not address the VPN tunnel being down.

The correct first step is to verify that the customer gateway device is configured with the correct IP address (Option D), because a mismatch in the public IP address of the on-premises VPN endpoint will prevent the IPsec tunnel from establishing, even if the on-premises side is functioning internally.

Exam trap

The trap here is that candidates assume a VPN tunnel failure must be a routing or BGP issue, but with static routing, the most common cause is a mismatch in the customer gateway IP address, which is a simple configuration check that should be performed first.

How to eliminate wrong answers

Option A is wrong because static routing does not use BGP; BGP is only used with dynamic routing, so checking BGP session status would not apply. Option B is wrong because rebooting the virtual private gateway is a drastic, last-resort action that could cause unnecessary downtime and does not diagnose the specific cause of the tunnel failure. Option C is wrong because while a missing route to the virtual private gateway could affect traffic flow, the VPN tunnel itself can be up even without a route; the immediate issue is the tunnel being down, not routing.

96
Multi-Selectmedium

Which TWO actions can a SysOps administrator take to improve the availability of a web application using an Application Load Balancer (ALB) and EC2 instances? (Choose two.)

Select 2 answers
A.Place all instances in a single subnet to reduce latency
B.Configure health checks on the target group
C.Deploy EC2 instances in multiple Availability Zones
D.Use larger instance types to handle more traffic
E.Increase the deregistration delay (connection draining) timeout
AnswersB, C

Health checks are the mechanism an Application Load Balancer uses to continuously verify that an instance is able to receive traffic. Without them, the ALB keeps sending requests to instances that may be failing, causing connection errors and degraded user experience. Once a health check fails a configured number of times, the ALB automatically marks the instance as unhealthy and stops routing new traffic to it, while still allowing it to recover. This is a direct, operational improvement to availability because it proactively isolates failures at the instance level.

Why this answer

Health checks allow the ALB to automatically detect unhealthy EC2 instances and stop routing traffic to them, which prevents failed requests from reaching users. By configuring health checks on the target group, the ALB can mark instances as unhealthy based on criteria like HTTP response codes or timeout thresholds, and then route traffic only to healthy instances. This directly improves availability by ensuring that requests are not sent to failed or degraded instances.

Exam trap

The trap here is that candidates often confuse scaling (larger instances or more instances) with high availability, or they think that increasing timeouts like deregistration delay improves availability, when in fact only redundancy across AZs and proper health checking provide true fault tolerance.

97
MCQeasy

A company wants to host a static website on AWS with high availability and low latency for global users. Which service should be used to serve the static content?

A.AWS Lambda with API Gateway.
B.Amazon Route 53 with a simple routing policy.
C.EC2 instances behind an Application Load Balancer.
D.Amazon S3 bucket configured for static website hosting, with Amazon CloudFront.
AnswerD

An S3 bucket configured for static website hosting provides durable, highly available object storage with built-in features like index and error documents, and it scales automatically to handle any traffic level. Adding Amazon CloudFront in front of S3 gives you a global CDN that caches content at edge locations, reducing latency for users worldwide and offloading repeated requests from the bucket. CloudFront also adds HTTPS for custom domains, DDoS protection via AWS Shield, and allows you to keep the S3 bucket private using Origin Access Control (OAC), making this pairing the recommended serverless, cost-effective architecture for a high-availability static website.

Why this answer

Amazon S3 static website hosting serves the HTML/CSS/JS objects directly from the bucket, and fronting it with Amazon CloudFront caches content at global edge locations, delivering low latency and high availability. This combination is the canonical AWS pattern for globally distributed static sites because it removes server management and scales automatically.

Exam trap

SOA-C02 often tests whether candidates recognize that 'high availability and low latency for global users' implies edge caching (CloudFront) plus object storage (S3), not compute or DNS-only solutions — the trap is picking Route 53 or EC2/ALB as if DNS or a regional load balancer could deliver global edge performance.

How to eliminate wrong answers

Option A is wrong because Lambda with API Gateway is a serverless compute/API pattern for dynamic request handling, not for serving static assets, and it adds unnecessary cost and cold-start latency. Option B is wrong because Route 53 with a simple routing policy only resolves DNS to a single endpoint — it provides no caching, no edge delivery, and no high-availability failover for global users. Option C is wrong because EC2 instances behind an ALB require managing servers, patching, and scaling, and an ALB is region-scoped, so it cannot deliver the global low-latency edge caching that static content demands.

98
MCQeasy

A company wants to allow its employees to access internal applications using a custom domain name (app.example.com) that resolves to an internal ALB. Which AWS service should be used?

A.AWS Global Accelerator
B.Application Load Balancer
C.Amazon Route 53
D.Amazon CloudFront
AnswerC

Amazon Route 53 is a scalable and authoritative DNS service designed specifically to resolve custom domain names. It lets you create hosted zones, manage records (A, AAAA, CNAME, MX, etc.), and route traffic to AWS resources such as load balancers, CloudFront distributions, or IP addresses. Route 53 also supports alias records that integrate natively with other AWS services, making it the standard choice for mapping internal or external domains to application endpoints.

Why this answer

Amazon Route 53 is the correct choice because it is a DNS service that can resolve a custom domain name (app.example.com) to an internal Application Load Balancer's DNS name. By creating a private hosted zone associated with the company's VPC, Route 53 can provide internal DNS resolution without exposing the ALB to the internet, which meets the requirement for internal application access.

Exam trap

The trap here is that candidates often confuse DNS resolution with load balancing or content delivery, mistakenly choosing the ALB (which handles traffic distribution but not name resolution) or CloudFront (which is for public content delivery), instead of recognizing that Route 53 is the DNS service required to map a custom domain to an internal resource.

How to eliminate wrong answers

Option A is wrong because AWS Global Accelerator is a network layer service that improves availability and performance by directing traffic to optimal endpoints over the AWS global network, but it does not provide DNS resolution for custom domain names. Option B is wrong because an Application Load Balancer is a load balancer that distributes incoming traffic to targets, but it does not resolve domain names; it requires a DNS service like Route 53 to map a custom domain to its DNS name. Option D is wrong because Amazon CloudFront is a content delivery network (CDN) that caches content at edge locations and is typically used for public-facing applications; it does not provide internal DNS resolution within a VPC and would require public exposure.

99
MCQeasy

A company wants to distribute content with low latency to users globally. The content is static and stored in an S3 bucket. Which AWS service should be used?

A.Application Load Balancer
B.AWS Global Accelerator
C.Amazon CloudFront
D.S3 Transfer Acceleration
AnswerC

Amazon CloudFront is a content delivery network that caches static and dynamic content at edge locations worldwide, ensuring users receive data from the nearest edge to minimize latency. It works with origins like S3, EC2, or on-premises servers, and offloads repeated requests from the origin by serving cached copies. This directly satisfies the requirement to distribute content with low latency to users.

Why this answer

Amazon CloudFront is a global content delivery network (CDN) that caches static content at edge locations worldwide, reducing latency for users by serving data from the nearest edge. It integrates directly with S3 buckets as an origin, providing low-latency distribution of static content without requiring any changes to the S3 bucket configuration.

Exam trap

The trap here is confusing AWS Global Accelerator (which optimizes network path for dynamic traffic) with CloudFront (which caches static content at the edge), leading candidates to pick Global Accelerator for static content distribution.

How to eliminate wrong answers

Option A is wrong because an Application Load Balancer distributes traffic across targets within a single region and does not cache content or provide global edge distribution. Option B is wrong because AWS Global Accelerator improves performance for TCP/UDP traffic by routing users to the nearest edge via the AWS global network, but it does not cache static content; it is designed for dynamic traffic and non-HTTP protocols. Option D is wrong because S3 Transfer Acceleration speeds up uploads to S3 over long distances using AWS edge locations, but it is not designed for low-latency content distribution to end users; it accelerates uploads, not downloads.

100
MCQmedium

A company has multiple VPCs in the same account that need to communicate with each other. The VPCs are in the same region. Which solution provides the simplest and most scalable connectivity?

A.Set up AWS Direct Connect and route through a single VPC.
B.Use AWS PrivateLink to connect the VPCs.
C.Create a Transit Gateway and attach all VPCs.
D.Create VPC Peering connections between each pair of VPCs.
AnswerC

AWS Transit Gateway (TGW) is a regional hub-and-spoke router that centrally manages connectivity between multiple VPCs and on-premises networks via a single attachment per VPC. After attaching all VPCs to the transit gateway, you configure route tables and propagate routes so that traffic can flow transitively between any attached VPC, eliminating the need for a full mesh of peering connections. This approach scales to hundreds of VPCs, simplifies route management, and supports additional connections such as VPNs and Direct Connect, making it the correct choice.

Why this answer

AWS Transit Gateway acts as a central hub that allows you to attach multiple VPCs and manage inter-VPC routing through a single gateway, simplifying connectivity and scaling easily as you add more VPCs. It eliminates the need for complex mesh or star configurations and supports transitive routing, making it the simplest and most scalable solution for multi-VPC communication within the same region.

Exam trap

The trap here is that candidates often confuse VPC Peering as the simplest solution for a few VPCs, but the question emphasizes scalability, and Transit Gateway is the only option that provides transitive routing without a full mesh of connections.

How to eliminate wrong answers

Option A is wrong because AWS Direct Connect is a dedicated network connection from on-premises to AWS, not designed for inter-VPC connectivity, and routing through a single VPC creates a single point of failure and bandwidth bottleneck. Option B is wrong because AWS PrivateLink is used to expose services privately from one VPC to another, not for general inter-VPC routing; it requires service-specific configurations and does not provide transitive routing between all VPCs. Option D is wrong because VPC Peering requires creating and managing a full mesh of individual peering connections (n*(n-1)/2), which becomes complex and unscalable as the number of VPCs increases, and it does not support transitive routing.

101
MCQmedium

A company has an Application Load Balancer (ALB) that routes traffic to Amazon EC2 instances in private subnets of a VPC. The SysOps administrator needs to ensure that the EC2 instances can download software updates from the internet, but they must not be directly accessible from the internet. The solution should minimize operational overhead. Which solution should the administrator implement?

A.Place the EC2 instances in a public subnet and configure security group inbound rules to block all traffic.
B.Attach a NAT Gateway to a public subnet and configure the private subnet route table to send 0.0.0.0/0 traffic to the NAT Gateway.
C.Launch a NAT instance in a public subnet with an Elastic IP address and configure route tables accordingly.
D.Attach an Internet Gateway to the VPC and add a route to the private subnet route table pointing 0.0.0.0/0 to the Internet Gateway.
AnswerB

A NAT Gateway deployed in a public subnet with an Elastic IP provides secure outbound-only internet connectivity for private-instance traffic. The private subnet route table's 0.0.0.0/0 entry points to the NAT gateway, which translates source IPs and discards unsolicited inbound connections. Because AWS fully manages the gateway, it auto-scales and requires no patching, minimizing operational overhead. This satisfies both security and administrative efficiency.

Why this answer

A NAT Gateway (option B) allows EC2 instances in private subnets to initiate outbound connections to the internet (e.g., for software updates) while preventing any unsolicited inbound connections from the internet. It is a fully managed AWS service that automatically scales and requires no patching, minimizing operational overhead compared to a NAT instance. The private subnet route table directs 0.0.0.0/0 traffic to the NAT Gateway, which is placed in a public subnet with an Elastic IP address to enable internet access.

Exam trap

The trap here is that candidates may confuse a NAT Gateway with a NAT instance, thinking the latter is acceptable, but the question explicitly requires minimizing operational overhead, which disqualifies the self-managed NAT instance in favor of the fully managed NAT Gateway.

How to eliminate wrong answers

Option A is wrong because placing EC2 instances in a public subnet with security group rules blocking all inbound traffic still leaves them with public IP addresses, making them theoretically reachable from the internet (security groups are stateful and can be misconfigured), and it violates the requirement that instances must not be directly accessible from the internet. Option C is wrong because launching a NAT instance requires manual management (patching, scaling, high availability setup), increasing operational overhead, which contradicts the 'minimize operational overhead' requirement. Option D is wrong because adding a route to the private subnet route table pointing 0.0.0.0/0 to an Internet Gateway would make the private subnet effectively public, allowing direct inbound internet access to the EC2 instances, which violates the requirement that they must not be directly accessible from the internet.

102
MCQmedium

A SysOps administrator needs to ensure that all traffic between an on-premises data center and the AWS VPC is encrypted and goes over the internet. Which AWS service should be used?

A.AWS Site-to-Site VPN
B.VPC Peering
C.AWS Transit Gateway
D.AWS Direct Connect
AnswerA

AWS Site-to-Site VPN creates encrypted IPsec tunnels between the customer's on-premises network and AWS virtual private gateways or transit gateways. These tunnels, which leverage the public internet, provide secure and confidential transmission of data by encrypting traffic in transit. The service also automatically provisions two tunnels for high availability, ensuring redundant connectivity.

Why this answer

AWS Site-to-Site VPN creates an encrypted tunnel between an on-premises data center and an AWS VPC using IPsec (IKEv1/IKEv2) over the public internet. This meets the requirement for encryption and internet-based connectivity, as the VPN traffic traverses the internet but is secured by IPsec tunnels.

Exam trap

The trap here is that candidates often confuse AWS Site-to-Site VPN with AWS Direct Connect, assuming Direct Connect provides encryption by default, but Direct Connect is a private connection that does not include encryption unless a VPN is layered on top.

How to eliminate wrong answers

Option B (VPC Peering) is wrong because it connects VPCs within AWS using private AWS infrastructure, not over the internet, and does not support encryption by default. Option C (AWS Transit Gateway) is wrong because it is a network transit hub that connects VPCs and on-premises networks, but it does not itself provide encryption; it requires a Site-to-Site VPN or Direct Connect for on-premises connectivity. Option D (AWS Direct Connect) is wrong because it uses a dedicated private network connection, not the internet, and does not inherently encrypt traffic unless combined with a VPN.

103
MCQhard

A company uses Amazon Route 53 as its DNS service. They have a domain example.com with an alias record pointing to an Application Load Balancer (ALB). Recently, they updated the ALB's DNS name, but the Route 53 record was not updated. Users are still being directed to the old ALB, which has been decommissioned. The SysOps administrator updates the alias record to point to the new ALB DNS name. However, users still experience errors for several hours. What is the most likely reason?

A.Route 53 requires time to propagate changes globally
B.The alias record was not saved correctly
C.The TTL on the DNS record is set too high, causing client-side caching
D.The domain is using DNSSEC, which delays updates
AnswerC

DNS records include a Time-to-Live field that tells clients and recursive resolvers how long to cache the answer. Setting a high TTL, for example 86400 seconds, causes clients that resolved before the change to retain the old IP address for up to 24 hours, even though Route 53 already serves the new record. Lowering the TTL in advance or waiting for the old TTL to expire is the correct fix, making this the accurate explanation.

Why this answer

Alias records in Route 53 are not subject to TTL-based caching for the alias target resolution itself, but the DNS query response from the resolver to the client still includes a TTL value. When the TTL is set too high, clients and intermediate resolvers cache the old DNS response (pointing to the decommissioned ALB) for the duration of that TTL, causing continued errors even after the Route 53 record is updated. The alias record update propagates instantly within Route 53's authoritative infrastructure, but cached records at clients and recursive resolvers must expire before users reach the new ALB.

Exam trap

The trap here is that candidates assume alias records update instantly for all users, forgetting that the TTL in the DNS response controls client-side and resolver caching, which can cause delays even after the authoritative record is changed.

How to eliminate wrong answers

Option A is wrong because Route 53 alias records do not require global propagation time; updates to alias records are effective immediately within Route 53's authoritative DNS servers due to its anycast network and single authoritative source. Option B is wrong because the scenario states the SysOps administrator updated the alias record, and if it were not saved correctly, the record would not change at all, not cause a delay of several hours; the issue is client-side caching, not a save error. Option D is wrong because DNSSEC does not delay updates; it adds cryptographic signing but does not introduce additional propagation delays—DNSSEC validation happens at the resolver, not by introducing a waiting period for record changes.

104
MCQmedium

A company has a CloudFront distribution with an S3 bucket as the origin. The S3 bucket contains sensitive data that should only be accessible through CloudFront. Which configuration is required to ensure that direct access to the S3 bucket is blocked?

A.Attach an IAM role to CloudFront that allows S3 access
B.Set the S3 bucket policy to deny all access except from CloudFront's IP ranges
C.Create an Origin Access Identity (OAI) and add a bucket policy that grants access only to the OAI
D.Use signed URLs for all requests
AnswerC

An Origin Access Identity (OAI) is a special virtual identity that CloudFront uses to fetch objects from your S3 bucket. After creating an OAI and associating it with the distribution, you update the bucket policy to allow s3:GetObject for that OAI principal and deny all other direct S3 access. This ensures viewers can only access content through CloudFront, while the S3 bucket remains private. This is the AWS-recommended mechanism for securing S3 origins and avoids the pitfalls of IP-based or public-bucket policies.

Why this answer

The correct configuration is to create an Origin Access Identity (OAI) and grant it access via the S3 bucket policy. An OAI is a special CloudFront user that can be associated with a distribution. By updating the S3 bucket policy to allow only the OAI to perform s3:GetObject, you ensure that objects are only accessible through CloudFront.

This effectively blocks direct public access to the bucket while allowing CloudFront to serve the content.

Exam trap

SOA-C02 often tests the misconception that CloudFront IP ranges or IAM roles are sufficient to secure S3 origins, when in fact an OAI (or OAC) with a bucket policy is required to block direct access.

How to eliminate wrong answers

Option A is wrong because attaching an IAM role to CloudFront does not automatically restrict direct access to the S3 bucket; CloudFront would still need explicit permissions, and the bucket would remain publicly accessible unless its policy is changed. Option B is wrong because CloudFront's IP ranges are not static and can change, making IP-based restrictions unreliable and difficult to maintain; also, this does not prevent direct access from other AWS services or within the same region. Option D is wrong because signed URLs control access to CloudFront-distributed content but do not block direct access to the S3 bucket itself; users could still bypass CloudFront and access the S3 object URL directly if the bucket is public.

105
MCQeasy

A company wants to use Amazon CloudFront to serve content from an Application Load Balancer (ALB) that is internet-facing. Which type of origin should be configured in CloudFront?

A.S3 origin with the ALB's DNS name as the bucket name.
B.Custom origin with Origin Access Identity (OAI) to restrict access.
C.Custom origin (HTTP/HTTPS) pointing to the ALB DNS name.
D.Custom origin pointing to the ALB's private IP address.
AnswerC

An Application Load Balancer is an HTTP/HTTPS endpoint, so the correct way to attach it to CloudFront is as a custom origin, entering the ALB's DNS name (e.g., my-alb-1234567890.us-east-1.elb.amazonaws.com) rather than a bucket name or IP address. CloudFront then sends requests to that public DNS name and can resolve it from edge locations, forwarding the original request or the configured cache behavior. This is the standard pattern for accelerating dynamic or mixed content served through an ALB, and it also works with any load balancer that exposes a public DNS endpoint.

Why this answer

CloudFront requires a custom origin (HTTP/HTTPS) when the origin is an Application Load Balancer (ALB) because ALBs are not S3 buckets and do not support S3 origin configurations. The custom origin type allows CloudFront to forward requests to the ALB's public DNS name, which resolves to the ALB's IP addresses, enabling proper load balancing and content delivery.

Exam trap

The trap here is that candidates may mistakenly think an ALB can be configured as an S3 origin or that OAI applies to non-S3 origins, but CloudFront strictly requires a custom origin for ALBs and OAI is only valid for S3 bucket origins.

How to eliminate wrong answers

Option A is wrong because an S3 origin expects an S3 bucket endpoint, not an ALB DNS name; using an ALB DNS name as a bucket name would cause a configuration error. Option B is wrong because Origin Access Identity (OAI) is used exclusively with S3 origins to restrict access to S3 content, not with ALB origins; for ALBs, you would use custom headers or AWS WAF to restrict access. Option D is wrong because CloudFront cannot use private IP addresses as origins; the ALB must be internet-facing with a public DNS name for CloudFront to reach it over the internet.

106
Matchingmedium

Match each AWS database service to its type.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Relational database

NoSQL key-value and document

In-memory caching

Data warehousing

Graph database

Why these pairings

The correct matches are: Amazon RDS with relational database, Amazon DynamoDB with NoSQL key-value and document database, Amazon Redshift with data warehouse, and Amazon ElastiCache with in-memory cache. Common confusions include mistaking RDS for NoSQL or Redshift for caching.

107
MCQeasy

A company has an EC2 instance that needs to have a static public IP address that does not change even if the instance is stopped and started. Which AWS resource should be attached to the instance?

A.An Elastic IP address
B.An automatically assigned public IP address
C.A secondary private IP address
D.A static private IP address
AnswerA

An Elastic IP address is a static public IPv4 address allocated to your AWS account that persists until you explicitly release it. Unlike an automatically assigned public IP, an EIP can be associated with an instance and remains fixed across instance stops, starts, and replacements. You can also remap it to another instance in the same region, making it the correct way to give an EC2 instance a permanent public endpoint.

Why this answer

An Elastic IP address is a static, public IPv4 address designed for dynamic cloud computing. When associated with an EC2 instance, it remains fixed even if the instance is stopped and started, unlike automatically assigned public IPs which change on stop/start. This meets the requirement for a static public IP.

Exam trap

The trap is confusing private and public IPs — candidates might think a static private IP (Option D) provides public accessibility, but only Elastic IPs offer static public addressing.

How to eliminate wrong answers

Option B is wrong because an automatically assigned public IP is dynamic and is released when the instance is stopped, then a new one is assigned on start. Option C is wrong because a secondary private IP is internal to the VPC and not publicly routable; it does not provide a static public IP. Option D is wrong because a static private IP is also internal and does not provide public internet accessibility.

108
MCQmedium

A company has an Application Load Balancer (ALB) in the us-east-1 region. Users in Asia report high latency. The SysOps administrator wants to use AWS Global Accelerator to improve performance by directing traffic to the closest edge location. Which step is required to integrate Global Accelerator with the ALB?

A.Create a CloudFront distribution and point it to the ALB as an origin.
B.Configure the ALB as an endpoint group in a Global Accelerator accelerator.
C.Set up a Route 53 geoproximity routing policy for the ALB.
D.Use AWS WAF to allow traffic from Global Accelerator edge locations.
AnswerB

Global Accelerator is a networking service that provides two static anycast IP addresses at AWS edge locations and routes traffic over the AWS global network to the ALB endpoint. By adding the ALB as an endpoint in an endpoint group for the us-east-1 region, user traffic from Asia enters the AWS backbone at the nearest edge and traverses the private, low-latency AWS network instead of the congested public internet. This also brings health checking, automatic failover, and consistent performance even during internet disruptions.

Why this answer

AWS Global Accelerator uses the AWS global network to route traffic to the closest edge location, then forwards it over the AWS backbone to the ALB endpoint. To integrate, you must configure the ALB as an endpoint in an endpoint group within the accelerator, which allows Global Accelerator to direct traffic to the ALB based on proximity and health. This reduces latency for users in Asia by minimizing internet hops.

Exam trap

The trap here is that candidates often confuse Global Accelerator with CloudFront or Route 53 routing policies, assuming any CDN or DNS-based solution can achieve the same latency reduction, but Global Accelerator uniquely provides static IP addresses and optimized network pathing without caching or DNS caching delays.

How to eliminate wrong answers

Option A is wrong because CloudFront is a content delivery network (CDN) optimized for caching static and dynamic content, not for TCP/UDP traffic acceleration to an ALB; it adds unnecessary complexity and does not provide the anycast IP-based global acceleration that Global Accelerator offers. Option C is wrong because Route 53 geoproximity routing is a DNS-based routing policy that can direct users to different endpoints based on geographic location, but it does not provide the static anycast IP addresses or the optimized network path that Global Accelerator uses to reduce latency; DNS-based routing is also subject to client-side caching and does not offer the same performance improvements. Option D is wrong because AWS WAF is a web application firewall that filters HTTP/S traffic based on rules, not a mechanism to integrate or allow traffic from Global Accelerator edge locations; Global Accelerator automatically handles traffic routing without requiring WAF configuration for integration.

109
MCQhard

A company has a web application behind an Application Load Balancer (ALB) in a VPC. The application needs to authenticate users using an external identity provider (IdP). The SysOps Administrator recommends using Amazon Cognito as an identity broker. Which ALB action should be configured to authenticate users before forwarding requests to the target group?

A.An authenticate action using Amazon Cognito as the user pool.
B.A fixed-response action to return a 401 status code.
C.A redirect action to the IdP login page.
D.A forward action to the target group.
AnswerA

The ALB authenticate action with Amazon Cognito as the user pool is purpose-built for this use case. When a rule has this action, ALB redirects the user to Cognito's hosted UI, performs the OAuth 2.0 authorization code flow, validates the returned tokens, and then forwards the request to the target with user claims embedded in X-AMZN-OIDC headers and a session cookie. This is the only option that both verifies the user's identity and creates an authenticated session at the load balancer layer.

Why this answer

Amazon Cognito integrates directly with Application Load Balancers via an authenticate action. When you configure an ALB rule with an authenticate action using a Cognito user pool, the ALB handles the OAuth 2.0 / OpenID Connect flow with the external IdP, obtains tokens, and only forwards authenticated requests to the target group. This eliminates the need for custom authentication logic in the application.

Exam trap

The trap here is that candidates may think a simple redirect action (Option C) is sufficient, but they miss that the ALB must actively participate in the token exchange and validation, which only the authenticate action provides.

How to eliminate wrong answers

Option B is wrong because a fixed-response action returning a 401 status code would simply reject all requests without any authentication flow, failing to integrate with the external IdP. Option C is wrong because a redirect action to the IdP login page would send users to the IdP but the ALB would not handle the callback or validate tokens, leaving authentication incomplete and unmanaged. Option D is wrong because a forward action to the target group would bypass authentication entirely, allowing unauthenticated requests to reach the application.

110
MCQmedium

A SysOps administrator notices that traffic to an Application Load Balancer (ALB) is being rejected. The ALB has a security group that allows inbound HTTP (80) and HTTPS (443) from 0.0.0.0/0. The target group health checks are failing. What could be the issue?

A.The target instances' security group does not allow inbound traffic from the ALB security group.
B.The ALB security group does not allow outbound traffic to the targets.
C.The ALB’s security group is blocking health check traffic from the targets.
D.The target instances' security group does not allow inbound HTTP/HTTPS from the internet.
AnswerA

For an ALB health check to succeed, the target instance's security group must explicitly allow inbound traffic on the health check port from the ALB's security group as the source. This rule permits the ALB to establish the health check connection and receive the response. Without it, the target rejects the health check packets, causing the instance to be marked unhealthy even though the application itself may be running.

Why this answer

For an ALB to route traffic to targets, the targets' security group must allow inbound traffic from the ALB's security group on the target port. Even if the ALB's security group allows inbound HTTP/HTTPS from the internet, the targets will reject traffic if their security group does not permit it. This is a common misconfiguration that causes health checks to fail.

Exam trap

The trap is assuming that if the ALB's security group allows inbound traffic, the targets will automatically accept it; candidates forget that the targets have their own security groups that must also allow traffic from the ALB.

How to eliminate wrong answers

Option B is wrong because ALB security groups are stateful and allow outbound traffic by default; outbound rules are not the issue. Option C is wrong because health check traffic originates from the ALB to the targets, not the other way around, so the ALB's security group does not need to allow inbound from targets. Option D is wrong because targets do not need to allow inbound from the internet; they only need to allow traffic from the ALB.

111
Multi-Selecthard

Which THREE components are required to establish a site-to-site VPN connection between an AWS VPC and an on-premises network? (Choose three.)

Select 3 answers
A.Customer gateway (CGW)
B.Transit gateway
C.VPN connection
D.Virtual private gateway (VGW)
E.AWS Direct Connect
AnswersA, C, D

The Customer Gateway (CGW) is a logical object in AWS that represents the on-premises VPN device or software application. It stores the public IP address of the customer-side router and, if BGP is used, the Border Gateway Protocol Autonomous System Number (ASN). It is mandatory because the AWS-side virtual private gateway needs a defined peer endpoint to establish the IPsec tunnels, and route propagation depends on this object. Without the CGW, there is no specified remote device to encrypt traffic to.

Why this answer

A customer gateway (CGW) is required because it represents the on-premises side of the site-to-site VPN connection. It provides the public IP address and BGP ASN (if dynamic routing is used) of the on-premises VPN device, allowing AWS to establish IPsec tunnels with the correct endpoint.

Exam trap

The trap here is that candidates often think a transit gateway is required for site-to-site VPN, but it is only needed when you want to centralize routing across multiple VPCs or use advanced features like route propagation; a single VPC-to-on-premises VPN works with just a VGW, CGW, and VPN connection.

112
Multi-Selecthard

A SysOps Administrator is configuring VPC Flow Logs to monitor network traffic. Which THREE pieces of information are included in VPC Flow Log records?

Select 3 answers
A.HTTP status code
B.Protocol number
C.Source IP address
D.DNS query name
E.Destination IP address
AnswersB, C, E

The protocol number field in a VPC Flow Log record identifies the IP protocol used for the traffic, using IANA-assigned numbers (e.g., 6 for TCP, 17 for UDP, 1 for ICMP). This numeric value is captured directly from the IP header, independent of the application layer. Flow log records include this field regardless of whether the traffic is TCP, UDP, or another protocol, making it a reliable attribute for filtering and analyzing traffic types.

Why this answer

VPC Flow Logs capture metadata about network traffic, including source IP address (C), destination IP address (E), and protocol number (B). They do not include HTTP status codes (A) or DNS query names (D), as those are application-layer details beyond the scope of network flows.

113
MCQeasy

A company needs a dedicated private network connection from its on-premises data center to AWS that provides consistent network performance and high bandwidth. The connection must bypass the public internet. Which AWS service should the SysOps administrator use?

A.AWS Site-to-Site VPN
B.AWS Client VPN
C.AWS Direct Connect
D.AWS Transit Gateway
AnswerC

AWS Direct Connect is the correct answer because it provides a dedicated private network connection from an on-premises data center to AWS using a physical cross-connect at a Direct Connect location. This connection bypasses the public internet, delivering consistent network performance, lower latency, and higher bandwidth options (e.g., 1 Gbps or 10 Gbps, and up to 100 Gbps with aggregated links). It also reduces bandwidth costs and provides a more predictable networking experience for hybrid architectures. Direct Connect is the dedicated private circuit required by the company.

Why this answer

AWS Direct Connect is the correct choice because it provides a dedicated, private network connection from an on-premises data center to AWS, bypassing the public internet entirely. This ensures consistent network performance, low latency, and high bandwidth, which are critical for workloads requiring predictable throughput and a private link.

Exam trap

The trap here is that candidates often confuse AWS Site-to-Site VPN with a private connection, overlooking that it still traverses the public internet and cannot guarantee consistent performance or bypass it, whereas Direct Connect provides a dedicated physical link.

How to eliminate wrong answers

Option A is wrong because AWS Site-to-Site VPN uses the public internet to establish an encrypted tunnel (IPsec) between the on-premises network and AWS, which cannot guarantee consistent performance or bypass the public internet. Option B is wrong because AWS Client VPN is a managed remote access VPN service for individual clients (e.g., laptops) connecting over the internet, not for dedicated private network connections between data centers and AWS. Option D is wrong because AWS Transit Gateway is a network transit hub that connects VPCs and on-premises networks via VPN or Direct Connect, but it is not a connection service itself; it requires a separate underlying connection like Direct Connect or VPN to provide the private link.

114
MCQeasy

A company hosts a static website on Amazon S3. Users access the website from around the world. The SysOps administrator needs to deliver content with low latency and support HTTPS with a custom domain. Which AWS service should be used?

A.AWS Global Accelerator
B.Amazon CloudFront
C.Amazon Route 53 latency-based routing
D.S3 Transfer Acceleration
AnswerB

CloudFront caches static content at global edge locations, cutting latency for worldwide users, and provides HTTPS with a custom domain via ACM certificates. This satisfies both the low-latency and secure custom-domain constraints that S3 static website hosting alone cannot meet.

Why this answer

Amazon CloudFront is a content delivery network (CDN) that caches static content at edge locations worldwide, reducing latency for global users. It natively supports HTTPS with custom domains via SSL/TLS certificates from AWS Certificate Manager (ACM) and integrates with S3 as an origin. This combination of low-latency delivery and HTTPS termination makes CloudFront the correct choice for this scenario.

Exam trap

The trap here is that candidates often confuse AWS Global Accelerator with CloudFront because both improve performance, but Global Accelerator does not cache content or terminate HTTPS for static websites, making it unsuitable for this use case.

How to eliminate wrong answers

Option A is wrong because AWS Global Accelerator improves TCP/UDP traffic performance using the AWS global network but does not cache content or terminate HTTPS for static website delivery; it is designed for dynamic applications, not static content caching. Option C is wrong because Amazon Route 53 latency-based routing only directs DNS queries to the region with the lowest latency, but it does not cache content or provide HTTPS termination; the origin S3 bucket would still serve content directly without edge caching. Option D is wrong because S3 Transfer Acceleration speeds up uploads to S3 using edge locations, but it does not cache content for downloads, does not support custom domain HTTPS, and is intended for large object uploads, not global static website delivery.

115
MCQmedium

Refer to the exhibit. The output shows the health status of two targets in a target group. One target is unhealthy with a 502 error. What is the most likely cause?

A.The target instance’s security group is blocking the health check traffic.
B.The target instance is not allowing outbound traffic to the ALB.
C.The web server on the target instance is returning HTTP 502 status codes.
D.The ALB health check is misconfigured with an incorrect path.
AnswerC

An HTTP 502 Bad Gateway response is produced by a web server acting as a reverse proxy or gateway when it receives an invalid response from an upstream server, such as an application server or backend service that the target depends on. In the context of an ALB health check, the load balancer considers any non-2xx HTTP response (including 502) as a health check failure, and the target is marked unhealthy. The fact that the ALB received a 502 proves that the target was reachable and successfully responded at the HTTP layer, so the issue is not network-level but application-layer, specifically that the target's own upstream dependencies are failing.

Why this answer

A 502 Bad Gateway error from the target indicates that the web server on the instance is returning an invalid response, often due to an application error or misconfiguration. Option A is incorrect because a security group blocking health check traffic would result in a connection timeout or refusal, not a 502. Option B is incorrect because the health check is initiated by the ALB to the target instance, so outbound traffic from the instance is not relevant.

Option D is incorrect because a misconfigured health check path would typically result in a 404 or other error, but not necessarily a 502. The 502 error is directly caused by the target's web server returning an HTTP 502 status code.

116
MCQmedium

A company is using Amazon Route 53 as its DNS service. The company has a web application running on an Auto Scaling group of EC2 instances behind an Application Load Balancer (ALB). The company wants to ensure that if the ALB fails, traffic is automatically redirected to a static error page hosted on an Amazon S3 bucket. Which Route 53 routing policy should be used to achieve this?

A.Geolocation routing policy
B.Failover routing policy
C.Latency routing policy
D.Weighted routing policy
AnswerB

Failover routing policy in Amazon Route 53 implements active-passive failover by associating a primary record with a health check that continuously monitors the resource. When the primary endpoint fails its health check, Route 53 automatically responds to DNS queries with the secondary record, such as an S3 bucket configured for static website hosting. You can pair a primary resource like an EC2 instance or load balancer with a secondary static S3 bucket, ensuring traffic shifts to the passive site during an outage. This is the direct mechanism for the requirement described.

Why this answer

The Failover routing policy in Amazon Route 53 is designed to route traffic to a primary resource (the ALB) and automatically redirect to a secondary resource (the S3 bucket static error page) when the primary health check fails. This ensures high availability by failing over to the static error page if the ALB becomes unhealthy, meeting the requirement precisely.

Exam trap

The trap here is that candidates often confuse Weighted routing policy with failover behavior, assuming weights can handle health-based redirection, but Weighted routing policy does not automatically remove unhealthy targets from DNS responses without additional health check integration.

How to eliminate wrong answers

Option A is wrong because Geolocation routing policy routes traffic based on the geographic location of the user, not on health or failover conditions, so it cannot redirect traffic to a static error page upon ALB failure. Option C is wrong because Latency routing policy routes traffic to the region with the lowest latency for the user, ignoring health checks and failover logic, thus it cannot automatically switch to a backup resource. Option D is wrong because Weighted routing policy distributes traffic across multiple resources based on assigned weights, but it does not support automatic failover based on health checks; it would continue sending traffic to the ALB even if it fails.

117
MCQmedium

A company has an on-premises data center connected to AWS via an AWS Direct Connect connection. The SysOps administrator needs to ensure high availability for the connectivity. Which configuration provides the highest availability for the Direct Connect connection?

A.Establish a single Direct Connect connection with a VPN backup.
B.Establish two Direct Connect connections to the same AWS Direct Connect location.
C.Establish two Direct Connect connections to different AWS Direct Connect locations.
D.Use multiple virtual interfaces on a single Direct Connect connection.
AnswerC

By connecting to two separate Direct Connect locations, you eliminate the facility as a single point of failure. If one location goes down, BGP routing automatically directs traffic over the surviving connection, assuming appropriate routing policies. This configuration meets AWS's recommendation for redundant connections with diverse paths, achieving high availability for hybrid networking.

Why this answer

Establishing two Direct Connect connections to different AWS Direct Connect locations provides geographic redundancy. If one AWS Direct Connect location experiences an outage, the other connection remains operational, ensuring high availability. This configuration eliminates single points of failure at the facility level, which is the most resilient design for hybrid connectivity.

Exam trap

The trap here is that candidates assume multiple connections to the same location provide redundancy, but AWS Direct Connect locations are single points of failure; true high availability requires geographic diversity across different locations.

How to eliminate wrong answers

Option A is wrong because a single Direct Connect connection with a VPN backup does not provide true high availability; the VPN backup relies on the public internet, which introduces variable latency, lower bandwidth, and potential security concerns, and the failover is not seamless. Option B is wrong because two Direct Connect connections to the same AWS Direct Connect location share the same physical facility and power infrastructure, meaning a location-level outage (e.g., fiber cut or power failure) will take down both connections simultaneously. Option D is wrong because multiple virtual interfaces on a single Direct Connect connection still depend on a single physical connection; if that connection fails, all virtual interfaces are lost, providing no redundancy.

118
Multi-Selecthard

A company is using Amazon Route 53 as its DNS service. The SysOps team needs to route traffic to multiple resources based on the geographic location of the users. Which TWO routing policies can achieve this? (Select TWO.)

Select 2 answers
A.Geoproximity routing
B.Simple routing
C.Failover routing
D.Latency-based routing
E.Geolocation routing
AnswersA, E

Geoproximity routing uses the geographic location of both the user and the AWS resource to route traffic, and it supports an optional bias value that expands or shrinks the route-to-resource region. For example, you can set a positive bias to direct more traffic to a specific AWS Region, or a negative bias to move traffic away from it. This makes it ideal for gradually shifting traffic between regions while still basing routing on physical proximity.

Why this answer

The question asks for two routing policies that route traffic based on geographic location. Geoproximity routing (Option A) and Geolocation routing (Option E) are the correct choices. Geoproximity routing considers both geographic location and optional bias, while Geolocation routing uses strict geographic boundaries.

Latency-based routing (Option D) routes based on network latency, not geography, even if latency often correlates with distance. Simple routing (Option B) and Failover routing (Option C) do not use geographic information at all.

Exam trap

The question asks for two geographic routing policies, but only Geoproximity routing and Geolocation routing are based on geographic location. Candidates might mistakenly think there is a third correct option, such as latency-based routing, but that uses network latency, not geography. This can cause confusion.

119
MCQhard

A company is using Amazon Route 53 for DNS and wants to route traffic to multiple endpoints based on the geographic location of the user. Which routing policy should the SysOps Administrator use?

A.Geolocation routing
B.Weighted routing
C.Failover routing
D.Latency routing
AnswerA

Geolocation routing is the correct choice because Route 53 uses the geographic location of the user's DNS resolver to determine which record to return. You can create records for continents, countries, or US states and even specify a default record for users in unmatched locations. This enables location-based routing, such as directing users to regional endpoints or enforcing regional restrictions. However, the location is inferred from the resolver's IP address, so it is approximate rather than exact.

Why this answer

Geolocation routing (Option A) is correct because it allows Route 53 to route traffic based on the geographic location of the DNS query's source IP address. This is ideal for scenarios where you need to direct users to specific endpoints based on their country, continent, or even US state, such as complying with data sovereignty laws or delivering localized content.

Exam trap

The trap here is that candidates often confuse geolocation routing with latency routing, assuming that lower latency correlates with geographic proximity, but latency routing uses actual network performance data, not geographic boundaries.

How to eliminate wrong answers

Option B (Weighted routing) is wrong because it distributes traffic across multiple endpoints based on assigned weights (e.g., 80% to one, 20% to another), not based on the user's geographic location. Option C (Failover routing) is wrong because it is designed for active-passive failover scenarios where traffic is routed to a primary endpoint unless it is unhealthy, then it fails over to a secondary endpoint; it does not consider user location. Option D (Latency routing) is wrong because it routes traffic to the endpoint with the lowest latency for the user, which is determined by network performance measurements, not by the user's geographic location.

120
MCQeasy

A SysOps administrator needs to route traffic to multiple AWS regions for a global application with low latency. Which AWS service should be used?

A.Amazon CloudFront
B.Amazon Route 53 with latency routing policy
C.Application Load Balancer
D.AWS Global Accelerator
AnswerB

Amazon Route 53's latency routing policy evaluates the measured latency between the user's DNS resolver and each AWS region where you have a resource, then returns the IP address for the region with the lowest latency. This enables multi-region active-active architectures by using DNS to direct each user request to the most responsive endpoint. For a sysops administrator needing to route traffic to multiple AWS regions, this is the correct service because it explicitly performs latency-based regional routing.

Why this answer

Amazon Route 53 with a latency routing policy directs traffic to the AWS region that provides the lowest latency for each user, based on measurements of network round-trip time. This is the correct choice for routing traffic to multiple regions to minimize latency for a global application.

Exam trap

The trap here is that candidates often confuse AWS Global Accelerator with latency-based routing, but Global Accelerator optimizes traffic over the AWS backbone from the edge, not by selecting the lowest-latency region based on DNS queries.

How to eliminate wrong answers

Option A is wrong because Amazon CloudFront is a content delivery network (CDN) that caches content at edge locations, not a service that routes traffic to multiple AWS regions based on latency. Option C is wrong because an Application Load Balancer distributes traffic within a single AWS region and cannot route traffic across multiple regions. Option D is wrong because AWS Global Accelerator uses Anycast IPs to route traffic to the nearest edge location, but it does not use latency-based routing to select the optimal AWS region; it relies on static IP addresses and the AWS global network.

121
MCQmedium

A company has deployed a web application across multiple AWS regions and wants to use Amazon Route 53 to direct users to the region with the lowest latency. Which routing policy should the SysOps administrator use?

A.Latency routing policy
B.Geolocation routing policy
C.Geoproximity routing policy
D.Weighted routing policy
AnswerA

The latency routing policy selects the AWS region that gives the requesting user the lowest network latency by comparing real-time latency measurements from the client's DNS resolver to each configured regional endpoint. It is the only policy among these that makes a routing decision based on actual network path performance rather than a static geographic or weighting rule, so it matches the requirement to route users to the fastest-performing region for the web application.

Why this answer

Latency routing policy is correct because it directs user traffic to the AWS region that provides the lowest network latency for the end user. Route 53 measures latency between the user's DNS resolver and each region's edge location, then responds with the IP of the region that has the lowest latency. This is ideal for multi-region deployments where the goal is to minimize response time.

Exam trap

The trap here is that candidates confuse 'geolocation' (based on user's physical location) with 'latency' (based on actual network performance), assuming that the closest geographic region always has the lowest latency, which is not true due to network routing and peering differences.

How to eliminate wrong answers

Option B is wrong because geolocation routing policy routes traffic based on the geographic location of the user (e.g., country or continent), not on real-time network latency, so it cannot guarantee the lowest latency. Option C is wrong because geoproximity routing policy routes traffic based on the physical distance between the user and the resource, optionally using a bias value, but it does not measure actual network latency. Option D is wrong because weighted routing policy distributes traffic across resources based on assigned weights (e.g., 80% to one region, 20% to another), which is used for load balancing or testing, not for latency optimization.

122
MCQhard

A company has a VPC with a public subnet and a private subnet. An EC2 instance in the private subnet needs to download patches from the internet. The company has a NAT gateway in the public subnet. Which of the following route table configurations is required for the private subnet to enable internet access through the NAT gateway?

A.Add a route to 0.0.0.0/0 pointing to the internet gateway in the private subnet route table
B.Add a route to 0.0.0.0/0 pointing to the NAT gateway in the private subnet route table
C.Add a route to 0.0.0.0/0 pointing to the NAT gateway in the public subnet route table
D.Add a route to the NAT gateway's private IP in the private subnet route table
AnswerB

By associating the private subnet's route table with a default route targeted at the NAT gateway, all outbound IPv4 traffic is forwarded to the NAT gateway in the public subnet, which then translates the source address and forwards the traffic to the internet gateway. This lets private instances initiate outbound connections while keeping them unaddressable from the internet, and unsolicited inbound traffic is blocked because the NAT gateway only allows responses to established outbound flows.

Why this answer

A private subnet route table must have a default route (0.0.0.0/0) pointing to the NAT gateway's elastic network interface (ENI) to forward outbound internet traffic from private instances through the NAT gateway. The NAT gateway, residing in the public subnet, then uses its own route table with a route to the internet gateway (IGW) to reach the internet. Without this route, traffic from the private subnet would have no path to the internet.

Exam trap

The trap here is that candidates often confuse the route table that needs modification, thinking the public subnet route table must be updated, when in fact it is the private subnet route table that requires the default route pointing to the NAT gateway.

How to eliminate wrong answers

Option A is wrong because adding a route to 0.0.0.0/0 pointing to the internet gateway in the private subnet route table would attempt to send traffic directly to the IGW, but the IGW requires a public IP or Elastic IP on the source instance; private instances lack public IPs, so traffic would be dropped. Option C is wrong because the public subnet route table already has a route to the IGW for 0.0.0.0/0; adding a route to the NAT gateway there would not help private instances, as the private subnet route table is the one that controls outbound traffic from the private subnet. Option D is wrong because adding a route to the NAT gateway's private IP in the private subnet route table would only allow traffic destined specifically to that IP, not general internet traffic; a default route (0.0.0.0/0) is required to forward all outbound traffic to the NAT gateway.

123
Multi-Selectmedium

A SysOps administrator is designing a highly available web application across multiple AWS regions. The application uses an Application Load Balancer in each region. Which TWO services can be used to route traffic to the closest regional load balancer based on latency?

Select 2 answers
A.AWS Global Accelerator
B.Amazon Route 53 geoproximity routing
C.Amazon Route 53 weighted routing
D.Amazon Route 53 latency-based routing
E.Amazon CloudFront with origin groups
AnswersA, D

AWS Global Accelerator routes traffic over the AWS global network to the endpoint with the lowest latency, using anycast IP addresses that direct users to the nearest edge location. This satisfies the requirement to reach the closest regional Application Load Balancer, unlike DNS-based routing which depends on resolver caching and TTL behaviour.

Why this answer

Option A (AWS Global Accelerator) is correct because it uses the AWS global network and anycast IP addresses to route user traffic to the optimal regional endpoint based on latency and health, and it can front Application Load Balancers in multiple regions. Option D (Amazon Route 53 latency-based routing) is correct because it returns the regional record whose AWS Region has the lowest measured latency to the requesting resolver, directing users to the closest regional ALB. Option B (geoproximity routing) routes based on geographic location and optional bias, not measured network latency, so it does not meet the stated requirement.

Option C (weighted routing) distributes traffic by assigned proportions regardless of latency, so it is not latency-based. Option E (CloudFront with origin groups) is for origin failover within a distribution and does not route to the closest regional load balancer by latency.

Exam trap

SOA-C02 often tests the distinction between latency-based routing and geoproximity routing — candidates may pick geoproximity thinking it means 'closest,' but it is geographic, not latency-based, and does not measure actual network performance.

124
MCQeasy

A company wants to distribute content globally with low latency and high transfer speeds. The content is stored in S3 buckets in multiple regions. Which AWS service should be used to accelerate content delivery?

A.Amazon Route 53
B.Amazon CloudFront
C.AWS Global Accelerator
D.S3 Transfer Acceleration
AnswerB

Amazon CloudFront is a content delivery network (CDN) that caches copies of content at edge locations worldwide, so users receive data from a nearby point of presence instead of the origin server. This reduces round-trip latency and offloads the origin, providing fast, consistent distribution. It integrates with S3, EC2, and custom origins, and supports features like SSL termination, geo-restriction, and Lambda@Edge for edge processing.

Why this answer

Amazon CloudFront is AWS's content delivery network (CDN), designed to cache and serve content from edge locations worldwide with low latency and high transfer speeds. It integrates natively with S3 origins across regions and can use origin groups or multiple origins for failover. This directly matches the requirement to accelerate global content delivery.

Exam trap

SOA-C02 often tests the confusion between CloudFront (CDN for caching HTTP content) and Global Accelerator (network-layer acceleration for TCP/UDP), and candidates frequently pick Global Accelerator because both claim to improve global performance.

How to eliminate wrong answers

Option A is wrong because Route 53 is a DNS service that routes users to endpoints based on latency, geolocation, or failover, but it does not cache content or accelerate transfer speeds at the edge. Option C is wrong because AWS Global Accelerator improves performance for TCP/UDP traffic using the AWS global network and anycast IPs, but it is not a content caching CDN and is better suited to non-HTTP workloads or dynamic applications. Option D is wrong because S3 Transfer Acceleration speeds up uploads and downloads to a single S3 bucket using edge locations, but it does not distribute cached content globally or serve as a CDN.

125
MCQmedium

Refer to the exhibit. A SysOps administrator is troubleshooting a CloudFront distribution that serves content from an S3 bucket. Users are receiving 'Access Denied' errors when trying to access objects. The exhibit shows the distribution configuration. What is the most likely cause?

A.The S3 bucket policy does not grant read access to CloudFront.
B.The distribution is not enabled.
C.The CloudFront distribution is not using an Origin Access Identity (OAI) to authenticate with the S3 bucket.
D.The viewer protocol policy is set to 'redirect-to-https', but users are using HTTP.
AnswerC

This is the correct diagnosis: for a private S3 bucket, CloudFront must use an Origin Access Identity to authenticate its requests. Without an OAI, CloudFront does not sign the origin request with a recognized AWS identity, so S3 treats it as anonymous and denies access. The fix involves creating an OAI, associating it with the distribution's S3 origin, and updating the bucket policy to allow that OAI the `s3:GetObject` permission.

Why this answer

The exhibit shows that the Origin Access Identity (OAI) field is empty, meaning CloudFront is not using an OAI to authenticate with the S3 bucket. Without an OAI, CloudFront relies on the bucket being publicly accessible, but by default S3 buckets are private. Therefore, CloudFront cannot access the objects, resulting in 'Access Denied' errors.

Option A is not evident from the exhibit; the bucket policy is not shown. Option B is incorrect because the distribution status is 'Enabled' in the exhibit. Option D is incorrect because the viewer protocol policy 'Redirect HTTP to HTTPS' would redirect users, not cause Access Denied.

126
MCQhard

A company has a VPC with public and private subnets across three Availability Zones. The public subnets host NAT Gateways, and the private subnets host EC2 instances that need to access the internet. The SysOps administrator notices that EC2 instances in one private subnet cannot reach the internet, while others can. What is the MOST likely cause?

A.The EC2 instances have a secondary private IP address that is not registered.
B.The NAT Gateway is not in a public subnet.
C.The network ACL for the private subnet blocks outbound traffic.
D.The route table for the private subnet does not have a default route to the NAT Gateway.
AnswerD

The private subnet's route table must contain a default route (0.0.0.0/0) that targets the NAT Gateway for all outbound internet traffic. Without this route, packets destined for the internet have no next hop and are dropped, even though the NAT Gateway itself is correctly placed and functional. This configuration is per-subnet, which explains why only the affected private subnet lacks internet access while other subnets work normally.

Why this answer

The most likely cause is that the route table associated with the private subnet does not have a default route (0.0.0.0/0) pointing to the NAT Gateway. Without this route, traffic destined for the internet has no path and fails. Option A is incorrect because secondary private IP addresses do not affect internet access.

Option B is incorrect because NAT Gateways must be in a public subnet (not private) to have internet access. Option C is incorrect because network ACLs are stateless and would affect all instances equally, not just those in one subnet.

127
MCQmedium

A company uses Amazon CloudFront to deliver content from an Application Load Balancer (ALB) origin. The SysOps administrator needs to restrict access to the content so that only users from a specific geographic location can view it. Which CloudFront feature should be used?

A.Geographic restrictions (geo-blocking) in CloudFront
B.Origin Access Identity (OAI)
C.Signed URLs
D.AWS WAF web ACL associated with the CloudFront distribution
AnswerA

CloudFront's native geo-restriction feature allows you to configure an allowlist or blocklist of two-letter ISO country codes directly in the distribution's settings. When a viewer in a denied country requests content, CloudFront's edge locations reject the request with an HTTP error before it ever reaches the origin. This works at the edge, requires no code or additional AWS services, and precisely matches the requirement of restricting access by geographic location. Because this feature is built into CloudFront itself, it is the correct choice among the options.

Why this answer

CloudFront's geographic restrictions (geo-blocking) feature allows you to restrict access to content based on the geographic location of the viewer's IP address. This is the simplest and most direct method to ensure only users from a specific country or region can access the content delivered through CloudFront, without requiring any changes to the origin or additional authentication mechanisms.

Exam trap

The trap here is that candidates often confuse AWS WAF's geo-match rules with CloudFront's built-in geographic restrictions, but the question asks for a CloudFront feature, and the native geo-blocking feature is the correct, simpler answer without requiring an additional service.

How to eliminate wrong answers

Option B is wrong because Origin Access Identity (OAI) is used to restrict access to an S3 bucket origin, not to an ALB origin, and it controls access based on identity rather than geography. Option C is wrong because Signed URLs provide time-limited access to individual files for specific users, but they do not restrict access based on geographic location; they are used for authorization, not geo-blocking. Option D is wrong because while AWS WAF can be used with CloudFront to create geo-match conditions, it is an additional service that incurs extra cost and complexity; CloudFront's built-in geographic restrictions are the native, simpler solution for this requirement.

128
Multi-Selectmedium

Which TWO of the following are benefits of using Amazon CloudFront in front of an Application Load Balancer? (Select TWO.)

Select 2 answers
A.Simplify VPC endpoint configuration
B.Protect the application against DDoS attacks
C.Offload SSL/TLS termination from the ALB
D.Reduced latency for users by caching content at edge locations
E.Provide a static IP address for the application
AnswersB, D

CloudFront is a global content delivery network that automatically integrates with AWS Shield Standard, providing always-on detection and inline mitigation for L3 and L4 DDoS attacks such as UDP floods and SYN floods. Its large edge footprint and anycast routing absorb and dissipate attack traffic close to the source, preventing it from reaching the origin. For additional protection, you can enable AWS Shield Advanced and combine it with AWS WAF for L7 attack mitigation.

Why this answer

Amazon CloudFront provides AWS Shield Standard automatically, which mitigates common Layer 3/4 DDoS attacks at the edge before traffic reaches the ALB. By absorbing volumetric attacks at CloudFront's globally distributed edge locations, the ALB is shielded from malicious traffic, ensuring application availability. This is a key benefit because ALBs alone do not have built-in DDoS protection beyond basic security group rules.

Exam trap

The trap here is that candidates often select 'Offload SSL/TLS termination from the ALB' (Option C) thinking it is a benefit of using CloudFront in front of an ALB, but this is a general CloudFront feature that applies to any origin, not a specific advantage of the ALB combination, and the ALB can already handle SSL/TLS termination efficiently.

129
MCQeasy

A SysOps administrator needs to route traffic for a domain name 'example.com' to an Application Load Balancer. Which AWS service should be used to create the DNS record?

A.Amazon EC2
B.Application Load Balancer
C.Amazon Route 53
D.Amazon CloudFront
AnswerC

Amazon Route 53 is the highly available and scalable Domain Name System (DNS) web service in AWS, designed specifically for domain registration, health checking, and authoritative DNS record management. It supports A, AAAA, CNAME, MX, and AWS-specific ALIAS records, and offers distinct routing policies such as latency-based, geolocation, weighted, and failover routing. With its global network of DNS servers, Route 53 can answer queries to route users to the appropriate application endpoints, fulfilling the exact need of a SysOps administrator who must route traffic for a domain.

Why this answer

Amazon Route 53 is AWS's DNS service and is used to create DNS records such as A or alias records that point a domain like example.com to an Application Load Balancer's DNS name. It supports alias records that map directly to ALB endpoints, enabling health checks and failover.

Exam trap

SOA-C02 often tests service boundaries — candidates may pick the ALB itself or CloudFront, but DNS record creation always belongs to Route 53.

How to eliminate wrong answers

Option A is wrong because Amazon EC2 provides compute instances, not DNS resolution. Option B is wrong because the Application Load Balancer distributes traffic but does not create or host DNS records for a domain. Option D is wrong because CloudFront is a CDN that can front an ALB, but it does not create the DNS record for example.com; Route 53 is still required for DNS.

130
Multi-Selectmedium

Which TWO AWS services can be used to provide a static IP address for an Application Load Balancer? (Choose two.)

Select 2 answers
A.Amazon Route 53 with static DNS name
B.Elastic IP address assigned to the ALB
C.Network Load Balancer (with Elastic IP)
D.AWS Global Accelerator
E.Application Load Balancer (with Elastic IP)
AnswersC, D

A Network Load Balancer (NLB) is a Layer 4 load balancer that supports Elastic IP address association per Availability Zone. Each Elastic IP assigned to an NLB subnet provides a static public IP that remains constant, giving clients a fixed address for whitelisting or legacy applications. The NLB can then forward traffic to targets such as an Application Load Balancer, EC2 instances, or other services, making it a valid way to expose a static IP.

Why this answer

Option C is correct because an Application Load Balancer cannot have an Elastic IP directly, but you can place a Network Load Balancer in front of it; the NLB supports Elastic IP addresses (one per subnet/AZ), giving the ALB a static IP entry point. Option D is correct because AWS Global Accelerator provides two static anycast IPv4 addresses (and optionally IPv6) that route traffic to the ALB, effectively giving it fixed IP addresses. Option A is incorrect because a Route 53 static DNS name is still a DNS name, not a static IP address.

Option B is incorrect because Elastic IP addresses cannot be assigned directly to an Application Load Balancer. Option E is incorrect because Application Load Balancers do not support Elastic IP addresses; their IPs are dynamic and can change.

Exam trap

SOA-C02 often tests the misconception that an ALB can be assigned an Elastic IP like an EC2 instance — candidates must remember that only NLB (and Global Accelerator) provide static IPs for ALB-fronted workloads.

131
MCQeasy

A company wants to reduce latency for global users accessing static content stored in Amazon S3. Which AWS service should be used?

A.Amazon Route 53
B.Amazon CloudFront
C.S3 Transfer Acceleration
D.AWS Global Accelerator
AnswerB

Amazon CloudFront is a content delivery network that caches static assets such as images, CSS, and JavaScript at edge locations in AWS's global point-of-presence network. When a user requests content, CloudFront serves it from the nearest edge location instead of the origin S3 bucket, which cuts network round-trip time and reduces load on the origin. This behavior directly minimizes latency for global downloads, making it the correct choice for this scenario.

Why this answer

Amazon CloudFront is a global content delivery network that caches static content at edge locations close to users, dramatically reducing latency for S3-hosted objects. It integrates natively with S3 as an origin and is the standard AWS answer for global static content acceleration.

Exam trap

The trap is confusing S3 Transfer Acceleration (upload acceleration) with CloudFront (download/content delivery) — candidates see 'S3' and 'latency' and pick Transfer Acceleration without noting the direction of traffic.

How to eliminate wrong answers

Option A is wrong because Route 53 is a DNS service — it can route users to the nearest endpoint but does not cache or serve content, so it cannot reduce latency for static objects stored in S3. Option C is wrong because S3 Transfer Acceleration speeds up uploads to S3 buckets using AWS edge locations, not downloads of static content to global users. Option D is wrong because AWS Global Accelerator optimizes TCP/UDP traffic to regional endpoints using the AWS backbone, but it does not cache content and is aimed at dynamic or non-HTTP workloads rather than static S3 objects.

132
MCQeasy

A company has an Application Load Balancer (ALB) that routes traffic to an Auto Scaling group of EC2 instances. The security group for the ALB allows inbound HTTP traffic from 0.0.0.0/0. The EC2 instances have a security group that allows inbound traffic from the ALB's security group. Users report intermittent 503 errors. What is the most likely cause?

A.The EC2 instances are not passing the ALB health checks.
B.The ALB is deployed in a private subnet without a NAT gateway.
C.The target group is configured with an incorrect protocol or port.
D.The security group on the ALB does not allow inbound traffic from the internet.
AnswerA

When an EC2 instance fails to respond to the ALB's health check requests — for example, because the application is overloaded, the health check path returns an error, or the instance's security group blocks the health check — the ALB marks the target unhealthy and stops sending traffic to it. If all registered instances are unhealthy, the ALB has no valid target to forward the request to and returns an HTTP 503 Service Unavailable. Since health checks are sent only at a fixed interval, a temporary application slowdown or resource exhaustion can cause intermittent failures, matching the symptom in the question.

Why this answer

The 503 Service Unavailable error from an Application Load Balancer typically indicates that the target instances are not healthy and are not passing the configured health checks. When the ALB's health checks fail, it stops routing traffic to those instances, resulting in 503 errors for users. Since the security group configurations appear correct (ALB allows inbound HTTP from 0.0.0.0/0 and EC2 allows traffic from the ALB's security group), the most likely cause is that the EC2 instances are failing health checks due to application-level issues, such as the web server not responding on the health check path or port.

Exam trap

The trap here is that candidates often focus on security group misconfigurations (like option D) or network connectivity issues (like option B), but the intermittent nature of the 503 error is a key clue pointing to health check failures rather than a permanent configuration mistake.

How to eliminate wrong answers

Option B is wrong because the ALB is an internet-facing load balancer, which requires public subnets with a route to an internet gateway, not a NAT gateway; deploying it in a private subnet without a NAT gateway would cause it to fail to receive traffic from the internet, but the users are already reporting intermittent 503 errors, not a complete lack of connectivity. Option C is wrong because if the target group were configured with an incorrect protocol or port, the health checks would consistently fail and the ALB would not route any traffic to the instances, leading to persistent 503 errors rather than intermittent ones; the intermittent nature suggests the instances are sometimes healthy. Option D is wrong because the security group on the ALB already allows inbound HTTP traffic from 0.0.0.0/0, so inbound traffic from the internet is permitted; this is explicitly stated in the question scenario.

133
MCQeasy

A security team applied Network ACL rules to a subnet to allow inbound TCP traffic on port 443 (HTTPS). Users connecting from the internet can initiate connections, but they never receive responses. The NACL is applied to the subnet containing the web servers. What is missing?

A.Add an outbound NACL rule allowing TCP on destination ports 1024–65535 to permit response traffic to clients' ephemeral ports
B.Enable stateful packet inspection on the NACL by toggling the 'track connections' setting in the VPC console
C.Add a security group outbound rule allowing all traffic because NACL rules only apply to inbound traffic
D.Change port 443 to allow both TCP and UDP protocols in the inbound NACL rule
AnswerA

Ephemeral ports are the temporary high-numbered ports clients open for receiving responses. Because NACLs are stateless, return traffic must be explicitly allowed by an outbound rule. The rule 'Allow TCP outbound to 0.0.0.0/0 on ports 1024–65535' covers all client ephemeral port ranges and allows the web server's responses to flow back to the client.

Why this answer

Network ACLs are stateless, meaning they evaluate each packet independently without tracking connection state. While the inbound rule allows HTTPS traffic (TCP 443) to reach the web servers, the outbound response traffic from the servers to the clients' ephemeral ports (typically 1024–65535) is blocked by the default deny-all outbound rule. Adding an outbound NACL rule allowing TCP traffic on destination ports 1024–65535 permits the response traffic to flow back to the clients, resolving the issue.

Exam trap

The trap here is that candidates often confuse stateless NACLs with stateful security groups, assuming that allowing inbound traffic automatically permits outbound responses, when in fact NACLs require explicit outbound rules for return traffic.

How to eliminate wrong answers

Option B is wrong because NACLs are inherently stateless and do not support a 'track connections' setting; stateful packet inspection is a feature of security groups, not NACLs. Option C is wrong because NACL rules apply to both inbound and outbound traffic; adding a security group outbound rule would not affect NACL behavior, and the statement that NACL rules only apply to inbound traffic is factually incorrect. Option D is wrong because HTTPS uses TCP only (port 443), and adding UDP would not fix the missing outbound response rule; the issue is statelessness, not protocol mismatch.

134
MCQhard

Refer to the exhibit. A VPC Gateway Endpoint for S3 is created and associated with route table rtb-11111111. However, an EC2 instance in a subnet that uses route table rtb-22222222 cannot access S3. What is the most likely cause?

A.The VPC endpoint is not in the 'available' state.
B.The subnet's route table (rtb-22222222) does not have a route to the VPC endpoint.
C.The endpoint policy does not allow the s3:GetObject action.
D.The VPC endpoint is in a different region from the S3 bucket.
AnswerB

For a gateway endpoint to carry S3 traffic from a subnet, that subnet's route table must have a route whose destination is the S3 prefix list (e.g., pl-63a5400a) and whose target is the gateway endpoint ID. The exhibit shows the endpoint is associated exclusively with rtb-11111111, whereas the subnet in question uses rtb-22222222, which has no such route. Without that route, traffic from the subnet destined to S3 follows the default route out to the internet, bypassing the endpoint entirely and therefore failing to use its private connectivity.

Why this answer

A VPC Gateway Endpoint for S3 is associated with specific route tables, and only subnets using those route tables can reach S3 through the endpoint. Since the endpoint is associated with rtb-11111111 but the EC2 instance's subnet uses rtb-22222222, that subnet has no route to the endpoint and traffic cannot reach S3 via the gateway endpoint. The fix is to associate the endpoint with rtb-22222222 as well.

Exam trap

The trap is assuming that creating a VPC endpoint makes it available to the entire VPC — in reality, Gateway Endpoints must be explicitly associated with each route table, and subnets using other route tables are excluded.

How to eliminate wrong answers

Option A is wrong because if the endpoint were not available, no subnet could use it — the question states the endpoint works for one route table, implying it is available. Option C is wrong because an endpoint policy denial would produce an access-denied error, not a connectivity failure, and the question does not mention permissions. Option D is wrong because VPC Gateway Endpoints are regional and S3 bucket region does not affect endpoint reachability from the VPC.

135
MCQhard

A company uses Amazon CloudFront with an Application Load Balancer (ALB) as the origin. Users report intermittent 502 errors. What is the most likely cause?

A.The CloudFront distribution does not have Cache-Control headers configured.
B.AWS WAF is blocking requests from CloudFront.
C.The ALB is experiencing health check failures or scaling issues.
D.The SSL/TLS certificate on the ALB is expired.
AnswerC

When CloudFront uses an ALB as a custom origin, it relies on the ALB to have healthy targets in its target groups. If the ALB's targets are unhealthy, the ALB cannot route requests and may return 503 or terminate connections, which CloudFront reports as 502 Bad Gateway. Scaling events, such as rapidly changing instance counts or insufficient capacity, can cause intermittent connection timeouts or reset errors. These conditions are the leading cause of transient 502 errors in a CloudFront-to-ALB architecture.

Why this answer

CloudFront returns HTTP 502 (Bad Gateway) when the origin — here an ALB — cannot successfully serve the request, most commonly because the ALB has no healthy targets registered. Health check failures or scaling events that leave the ALB without healthy backend instances cause CloudFront to receive an error response or no response, resulting in intermittent 502s.

Exam trap

The trap is focusing on edge-layer causes (WAF, cache headers, certificates) when the 502 specifically indicates an origin-side failure — candidates must map 502 to unhealthy ALB targets rather than client-facing misconfigurations.

How to eliminate wrong answers

Option A is wrong because missing Cache-Control headers affect caching behavior and TTL, not origin reachability; they would cause cache misses or stale content, not 502 errors. Option B is wrong because AWS WAF blocking requests typically returns 403 Forbidden, not 502 Bad Gateway, and WAF operates at the edge before the origin. Option D is wrong because an expired ALB certificate would cause TLS handshake failures and 5xx errors at the ALB itself, but CloudFront-to-ALB communication would fail consistently, not intermittently, and the error would more likely be 502 only if the ALB listener rejects the connection — however, the most common and classic cause of intermittent 502 from an ALB origin is unhealthy targets.

136
MCQeasy

A company hosts a web application on Amazon EC2 instances in two AWS regions: us-east-1 and eu-west-1. The application is behind an Application Load Balancer (ALB) in each region. The SysOps administrator wants to direct users to the region that provides the lowest latency, automatically routing traffic away from a region if it becomes unhealthy. Which Amazon Route 53 routing policy should be used?

A.Geolocation routing
B.Latency routing
C.Weighted routing
D.Failover routing
AnswerB

Latency routing uses measurements of latency between AWS regions and the user to direct traffic to the region with the lowest latency. When health checks are attached to the ALBs, latency routing automatically avoids unhealthy endpoints by excluding them from responses.

Why this answer

Latency routing (B) is correct because it directs users to the region with the lowest network latency based on real-time measurements between the user and the AWS endpoints. When a region becomes unhealthy, Route 53 automatically stops routing traffic to that region's ALB, ensuring failover to the next lowest-latency healthy region. This meets the requirement of both low-latency and automatic health-based rerouting.

Exam trap

The trap here is that candidates often confuse Geolocation routing with Latency routing, assuming geographic proximity equals low latency, but Geolocation routing does not measure actual network performance and lacks automatic health-based rerouting without additional failover records.

How to eliminate wrong answers

Option A (Geolocation routing) is wrong because it routes traffic based on the user's geographic location (e.g., country or continent), not on actual network latency, and it does not automatically reroute traffic away from an unhealthy region unless a failover record is explicitly configured. Option C (Weighted routing) is wrong because it distributes traffic based on assigned weights to multiple records, not on latency or health status; it does not automatically shift traffic away from an unhealthy region. Option D (Failover routing) is wrong because it uses an active-passive model with a primary and secondary record, but it does not consider latency; it only fails over to the secondary when the primary is unhealthy, which does not satisfy the requirement to direct users to the lowest-latency region.

137
Multi-Selecteasy

A SysOps administrator is troubleshooting an issue where an EC2 instance in a private subnet cannot connect to the internet via a NAT Gateway. Which TWO components must be correctly configured for this to work? (Select TWO.)

Select 2 answers
A.The network ACL for the private subnet must have a rule allowing inbound traffic from the NAT Gateway.
B.The NAT Gateway must be placed in a public subnet with a route to an Internet Gateway.
C.The route table for the private subnet must have a default route (0.0.0.0/0) pointing to the NAT Gateway.
D.The EC2 instance must have a public IP address.
E.The security group for the EC2 instance must allow inbound traffic on port 80.
AnswersB, C

The NAT Gateway must indeed be placed in a public subnet, meaning that the subnet's route table contains a 0.0.0.0/0 route pointing to an Internet Gateway. This placement is essential because the NAT Gateway needs its own internet reachability to forward traffic from private instances to the internet. Without this route, the NAT Gateway cannot communicate with the internet, and all outbound traffic it receives from private subnets will silently fail, making the NAT Gateway itself unreachable.

Why this answer

The NAT Gateway must reside in a public subnet because it needs a direct route to an Internet Gateway (IGW) to translate private IP addresses to the NAT Gateway's Elastic IP for outbound internet traffic. Without this placement and route, the NAT Gateway cannot forward traffic to the internet, breaking connectivity for instances in private subnets.

Exam trap

The trap here is that candidates often confuse the placement requirement for a NAT Gateway with that of a NAT Instance, thinking a NAT Gateway can be in a private subnet, or they incorrectly assume the private subnet's NACL needs an inbound rule from the NAT Gateway instead of focusing on outbound rules and route tables.

138
MCQeasy

A company has an on-premises data center connected to an AWS VPC via an AWS Direct Connect connection. The company's SysOps administrator wants to ensure that traffic from the VPC destined for the on-premises network uses the Direct Connect connection instead of the internet. Which configuration should be used?

A.Add a route in the VPC route table pointing to the on-premises network via a virtual private gateway (VGW)
B.Add a route in the VPC route table pointing to the on-premises network via a NAT gateway
C.Add a route in the VPC route table pointing to the on-premises network via an internet gateway
D.Add a route in the VPC route table pointing to the on-premises network via a VPC peering connection
AnswerA

The VGW is attached to the VPC and is the entry/exit point for Direct Connect. By adding a route with the on-premises destination and the VGW as the target, traffic is forced through the Direct Connect connection.

Why this answer

A virtual private gateway (VGW) is the AWS-side endpoint for an AWS Direct Connect connection when using a private virtual interface. By adding a route in the VPC route table that points the on-premises network CIDR to the VGW, all traffic destined for the on-premises network is forced over the Direct Connect link, bypassing the internet. This ensures private, low-latency, and consistent connectivity as required.

Exam trap

The trap here is that candidates often confuse the VGW with a NAT gateway or internet gateway, mistakenly thinking any gateway can route to on-premises, when only the VGW is designed for private connectivity via Direct Connect or VPN.

How to eliminate wrong answers

Option B is wrong because a NAT gateway is used to enable outbound internet traffic from private subnets, not to route traffic to an on-premises network over Direct Connect; it would send traffic to the internet, not the on-premises network. Option C is wrong because an internet gateway is designed for internet-bound traffic; routing on-premises traffic via an IGW would send it over the public internet, defeating the purpose of using Direct Connect. Option D is wrong because a VPC peering connection allows routing between two VPCs, not between a VPC and an on-premises network; it cannot be used to reach on-premises resources.

139
MCQmedium

A company uses an Application Load Balancer (ALB) to distribute traffic to an Auto Scaling group of EC2 instances. Users report intermittent 503 errors. The SysOps Administrator checks the ALB metrics and sees that the Sum of HTTP 503s correlates with spikes in CPU utilization on the EC2 instances. What is the MOST likely cause and solution?

A.Disable cross-zone load balancing on the ALB.
B.Configure the Auto Scaling group to scale out based on average CPU utilization and ensure sufficient capacity.
C.Increase the deregistration delay on the ALB target group to allow in-flight requests to complete.
D.Decrease the health check interval to detect unhealthy instances faster.
AnswerB

Configure the Auto Scaling group with a target tracking policy based on average CPU utilization, for example a 50% threshold. As CPU approaches the threshold, the ASG launches additional instances in a horizontal scale-out, distributing incoming requests across more targets and reducing CPU load per instance. You must also ensure the minimum, maximum, and desired capacity values are set high enough to absorb peak traffic. This directly eliminates the health check failures caused by CPU saturation, allowing the ALB to register healthy targets and serve requests successfully.

Why this answer

The most likely cause is that the EC2 instances are overwhelmed due to insufficient capacity, leading to 503 errors from the ALB. Configuring the Auto Scaling group to scale out based on average CPU utilization (B) ensures that additional instances are added when CPU spikes, providing sufficient capacity to handle the load and reducing 503 errors.

Exam trap

SOA-C02 often tests the misconception that 503 errors are always due to health check misconfigurations or deregistration delays, rather than insufficient capacity.

How to eliminate wrong answers

Option A is wrong because disabling cross-zone load balancing would likely worsen the situation by reducing the pool of available instances. Option C is wrong because increasing the deregistration delay helps with graceful shutdown but does not address 503 errors caused by high CPU. Option D is wrong because decreasing the health check interval might detect unhealthy instances faster but does not solve the root cause of high CPU leading to 503s.

140
MCQeasy

A sysadmin needs to block specific IP addresses from accessing an Application Load Balancer. Which approach is MOST efficient?

A.Modify the security group for the ALB to deny traffic from those IPs.
B.Add a route in the VPC route table to drop traffic from those IPs.
C.Create an AWS WAF web ACL with IP set rules and associate it with the ALB.
D.Update the network ACL for the ALB subnets.
AnswerC

AWS WAF is the recommended service for blocking specific IP addresses at an Application Load Balancer. You create a web ACL, define an IP set with the offending addresses, and attach a rule that blocks requests matching that set, then associate the web ACL with the ALB. This provides layer-7 protection, allowing granular control over source IPs while leaving other traffic unaffected, and integrates with features like rate-based rules and managed rule groups.

Why this answer

AWS WAF is the most efficient and appropriate service for blocking specific IP addresses from accessing an Application Load Balancer. You can create an IP set with the addresses to block and associate a web ACL with the ALB. WAF operates at Layer 7 and is designed for this purpose, providing granular control and scalability.

Exam trap

SOA-C02 often tests the misconception that security groups can deny traffic; candidates must remember security groups are allow-only, and WAF is the correct service for Layer 7 IP blocking on ALB.

How to eliminate wrong answers

Option A is wrong because security groups only support allow rules; you cannot create explicit deny rules. To block specific IPs, you would have to allow all other IPs, which is not scalable or efficient. Option B is wrong because VPC route tables control routing, not security; you cannot drop traffic based on source IP in a route table.

Option D is wrong because network ACLs are stateless and operate at the subnet level; while they can deny traffic, they are less efficient for ALB-specific blocking and require managing subnet-level rules, which may affect other resources.

141
MCQmedium

A company has two VPCs in the same AWS account and Region: VPC-A (10.0.0.0/16) and VPC-B (10.1.0.0/16). The SysOps administrator needs to establish connectivity between these VPCs so that resources in VPC-A can reach resources in VPC-B using private IP addresses. The solution must be highly available and not involve a third-party appliance. Which solution should the administrator implement?

A.Create an AWS Transit Gateway and attach both VPCs to it. Configure route tables to allow communication.
B.Create a VPC Peering connection between VPC-A and VPC-B. Update the route tables in each VPC to add routes to the other VPC's CIDR.
C.Attach an internet gateway to each VPC and use Amazon Route 53 to resolve private DNS names over the internet.
D.Set up a site-to-site VPN connection between the two VPCs using AWS Virtual Private Gateway.
AnswerB

VPC Peering is a one-to-one networking connection between two VPCs that enables direct traffic using private IPv4 or IPv6 addresses. Because the peering connection uses AWS's existing global network, traffic never traverses the public internet, and there are no additional hourly costs for the peering itself, aside from data transfer. After the peering request is accepted, you must add explicit routes in each VPC's route table pointing to the other VPC's CIDR block, and update the security group and network ACL rules to allow the traffic. For a simple two-VPC scenario in the same account and region, this is the most straightforward and cost-effective solution.

Why this answer

VPC Peering provides direct, private IP connectivity between two VPCs using the AWS global network, with no bandwidth bottleneck or single point of failure. By creating a peering connection and adding routes to the other VPC's CIDR in each VPC's route table, resources can communicate privately and the solution is highly available as the peering connection itself is redundant within AWS's infrastructure. No third-party appliance is required, and the setup is fully managed by AWS.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing Transit Gateway (Option A) for high availability, forgetting that VPC Peering is inherently highly available within a region and is the simplest, most cost-effective option for connecting just two VPCs.

How to eliminate wrong answers

Option A is wrong because AWS Transit Gateway, while capable of connecting multiple VPCs, introduces an additional cost and complexity that is unnecessary for a simple two-VPC scenario, and it is not the simplest highly available solution without a third-party appliance. Option C is wrong because attaching internet gateways and using Route 53 to resolve private DNS names over the internet would expose traffic to the public internet, violating the requirement to use private IP addresses and introducing security risks and potential availability issues. Option D is wrong because a site-to-site VPN connection requires a Virtual Private Gateway and a Customer Gateway, which adds complexity and potential single points of failure, and it is not the most straightforward highly available solution for VPC-to-VPC connectivity within the same region and account.

142
MCQeasy

An organization wants to allow an on-premises data center to access an Amazon RDS database in a VPC. Which AWS service should be used to establish a dedicated, private, and high-bandwidth connection?

A.AWS Direct Connect
B.AWS Transit Gateway
C.AWS Site-to-Site VPN
D.VPC Peering
AnswerA

AWS Direct Connect is the correct choice because it provides a dedicated, private, physical network connection from the on-premises data center directly to AWS, bypassing the public internet. This delivers consistent, low-latency, high-bandwidth connectivity and is ideal for hybrid workloads that require reliable, secure, and predictable network performance, meeting the organization's requirement for a dedicated connection.

Why this answer

AWS Direct Connect provides a dedicated, private network connection from an on-premises data center to AWS, bypassing the public internet. It offers consistent high bandwidth (1 Gbps, 10 Gbps, or 100 Gbps dedicated ports) and lower latency than internet-based connections. This makes it the correct choice for a dedicated, private, high-bandwidth link to an RDS database inside a VPC.

Exam trap

SOA-C02 often tests the distinction between 'dedicated private connection' (Direct Connect) and 'encrypted tunnel over the internet' (Site-to-Site VPN), causing candidates to pick VPN when the question emphasizes dedicated bandwidth or private connectivity.

How to eliminate wrong answers

Option B is wrong because AWS Transit Gateway is a regional network hub for connecting VPCs and on-premises networks to each other, but it does not itself provide the physical dedicated connection from on-premises to AWS — it requires Direct Connect or VPN as the underlying transport. Option C is wrong because AWS Site-to-Site VPN runs over the public internet (encrypted IPsec tunnels), so it is not a dedicated private circuit and its bandwidth is variable and limited by internet conditions. Option D is wrong because VPC Peering only connects two VPCs within AWS (or across regions/accounts) and cannot extend to an on-premises data center.

143
MCQeasy

A company has two Amazon VPCs in the same AWS Region with non-overlapping CIDR blocks. The SysOps administrator needs to establish private connectivity between the two VPCs with high throughput and minimal cost. Which solution should the administrator implement?

A.AWS Transit Gateway
B.VPC peering
C.AWS Direct Connect
D.AWS VPN CloudHub
AnswerB

VPC peering is the natural choice for connecting two VPCs in the same region because it creates a private, point-to-point connection using the AWS global network, with no gateways, VPNs, or physical devices. Since the CIDR blocks do not overlap, route tables are straightforward—just add routes pointing to the peering connection ID. It is highly available, incurs no per-hour fee (only data transfer costs), and is specifically designed for this exact scenario.

Why this answer

VPC peering is the correct solution because it establishes private connectivity between two VPCs in the same AWS Region using the AWS backbone network, with no bandwidth limits and no single point of failure. It incurs no additional cost beyond data transfer charges, making it the most cost-effective option for high-throughput connectivity between two VPCs with non-overlapping CIDR blocks.

Exam trap

The trap here is that candidates often choose AWS Transit Gateway because they assume it is required for any multi-VPC connectivity, but VPC peering is simpler and cheaper for connecting exactly two VPCs with non-overlapping CIDRs.

How to eliminate wrong answers

Option A is wrong because AWS Transit Gateway is a network transit hub that connects multiple VPCs and on-premises networks, which introduces additional hourly charges and is overkill for connecting only two VPCs. Option C is wrong because AWS Direct Connect is a dedicated physical connection from on-premises to AWS, not designed for VPC-to-VPC connectivity, and it incurs significant monthly port fees. Option D is wrong because AWS VPN CloudHub connects multiple VPN sites to a single virtual private gateway, but it requires VPN tunnels and is not optimized for high-throughput VPC-to-VPC connectivity within the same Region.

144
Multi-Selecthard

A company is using Amazon CloudFront with an Application Load Balancer (ALB) as the origin. The ALB is configured with HTTPS listeners. Users report that some requests are failing with a 502 error. Which THREE steps should the SysOps administrator take to troubleshoot the issue? (Choose three.)

Select 3 answers
A.Check that the ALB's security group allows inbound traffic from the CloudFront IP ranges.
B.Verify that the ALB's health check is configured correctly and that the targets are healthy.
C.Configure the CloudFront distribution to use a custom error response for 502 errors.
D.Ensure that the SSL certificate on the ALB is valid and trusted by CloudFront.
E.Verify that the ALB is configured to use the X-Forwarded-For header to route requests.
AnswersA, B, D

CloudFront reaches your ALB from AWS's CloudFront edge and regional IP ranges, which are published in ip-ranges.json and are not the same as the source IPs of your viewers. If the ALB security group does not contain an inbound HTTPS/HTTP allow rule for those CIDR blocks (or an AWS-managed prefix list), the SYN packets from CloudFront are dropped, the origin never responds, and CloudFront returns a 502 Bad Gateway to users. This is the most direct cause of the failure and must be validated first.

Why this answer

The ALB's security group must allow inbound traffic from CloudFront's IP ranges, because CloudFront forwards requests to the ALB using its own IP addresses. Without this rule, the ALB will reject the connection, resulting in a 502 error (Bad Gateway) as CloudFront cannot reach the origin. You can obtain the current CloudFront IP ranges from the AWS IP Address Ranges list and update the security group accordingly.

Exam trap

The trap here is that candidates may think a custom error response (Option C) resolves the root cause, when in fact it only masks the symptom, or they may confuse the X-Forwarded-For header (Option E) with routing logic, which is unrelated to 502 errors.

145
Drag & Dropmedium

Drag and drop the steps to enable AWS CloudTrail logging for a specific S3 bucket into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First create a log bucket with proper policy, then create the trail and configure it to log events for the target bucket.

146
MCQmedium

A company runs a three-tier application in a VPC. The web tier is in public subnets behind a Network Load Balancer (NLB). The application tier runs on EC2 instances in private subnets. The database tier is in isolated subnets with no route to a NAT gateway or internet gateway. A SysOps administrator must allow the application tier to initiate connections to the database tier while ensuring the database tier cannot initiate connections to the application tier. Which combination of security group and network ACL configuration should be used?

A.Configure the application security group to allow inbound traffic from the database security group on the database port, and configure the database security group to allow outbound traffic to the application security group on the application port.
B.Configure the database security group to allow inbound traffic from the application security group on the database port, and configure the application security group to allow outbound traffic to the database security group on the database port. Leave the database security group's outbound rules empty.
C.Configure the database security group to allow inbound traffic from the application subnet CIDR on the database port, and configure the database security group to allow outbound traffic to the application subnet CIDR on the application port.
D.Configure a network ACL on the database subnet to allow inbound traffic from the application subnet CIDR on the database port, and configure the application subnet's network ACL to allow outbound traffic to the database subnet CIDR on the database port. Leave the database subnet's network ACL outbound rules empty.
AnswerB

Security groups are stateful, so return traffic for an allowed inbound connection is automatically permitted regardless of outbound rules. Referencing the application security group as the source restricts access to only those instances. An empty outbound rule set on the database security group prevents the database from initiating outbound connections, satisfying the requirement that the database tier cannot initiate connections to the application tier.

Why this answer

Security groups are stateful and support referencing other security groups as sources or destinations. To allow the application tier to initiate connections to the database tier while preventing the reverse, the database security group should allow inbound traffic from the application security group on the database port. The application security group should allow outbound traffic to the database security group.

Because security groups are stateful, return traffic is automatically allowed, and an empty outbound rule set on the database security group prevents the database from initiating connections.

Exam trap

The trap here is assuming that security groups require symmetric inbound and outbound rules for return traffic, when in fact stateful filtering automatically permits return traffic for allowed inbound connections.

147
MCQmedium

A SysOps administrator is troubleshooting connectivity issues between two VPCs that are peered using a VPC Peering connection. The instances in VPC A can ping the private IP of instances in VPC B, but not the DNS names. What is the most likely cause?

A.The route tables in VPC A do not have a route to VPC B's CIDR.
B.The security groups in VPC B block DNS traffic (port 53).
C.The VPC Peering connection does not have 'Enable DNS Resolution' enabled.
D.The VPCs have overlapping CIDR blocks.
AnswerC

The correct issue is that the VPC peering connection does not have the 'Enable DNS Resolution' option enabled. AWS VPC peering does not automatically allow private DNS hostnames from the peer VPC to be resolved; you must explicitly enable this option on the peering connection. Specifically, the VPC owner must set 'Allow DNS resolution from peer VPC' (or 'Enable DNS Resolution') for the requester VPC to query names from the accepter VPC, and a corresponding option is needed for the reverse direction. Without this setting, the VPC DNS resolver ignores the peering connection when resolving private hostnames, causing DNS resolution to fail even though raw IP connectivity (like ping) works perfectly. This is a common, nuanced misconfiguration that is invisible to basic connectivity tests.

Why this answer

The 'Enable DNS Resolution' setting on a VPC Peering connection allows instances in one VPC to resolve the private DNS hostnames of instances in the peered VPC. Without this setting enabled, the DNS resolver in the requester VPC will not return the private IP of the peered instance, causing DNS name resolution to fail even though direct ICMP (ping) to the private IP works. This setting must be enabled on both sides of the peering connection for cross-VPC DNS resolution to function.

Exam trap

The trap here is that candidates often confuse successful ICMP connectivity with full network functionality, overlooking that DNS resolution is a separate service that requires explicit configuration on the VPC peering connection.

How to eliminate wrong answers

Option A is wrong because if the route tables in VPC A lacked a route to VPC B's CIDR, ping to the private IP would also fail, but the question states ping succeeds. Option B is wrong because security groups block traffic based on IP addresses, not DNS names; DNS traffic (port 53) would only be relevant if the issue were with DNS resolution itself, but here ping to IP works, indicating the problem is with DNS name resolution, not packet filtering. Option D is wrong because overlapping CIDR blocks would prevent the VPC peering connection from being established in the first place, and ping to private IP would also fail due to routing ambiguity.

148
Multi-Selecteasy

Which TWO features are provided by Amazon CloudFront to secure content delivery? (Choose two.)

Select 2 answers
A.Default support for custom SSL certificates without additional configuration
B.AWS WAF integration to filter requests based on rules
C.AWS Shield Advanced for DDoS protection
D.Signed URLs and signed cookies to restrict access to content
E.VPN connection between CloudFront and the origin
AnswersB, D

CloudFront integrates natively with AWS WAF, allowing you to associate a Web ACL with a distribution and filter HTTP(S) requests based on IP addresses, headers, body contents, URI patterns, SQL injection, XSS, and rate-based rules. This lets you block malicious traffic at the edge before it reaches your origin, and you can also use AWS-managed rule sets for common threats. This is a core CloudFront security feature.

Why this answer

AWS WAF can be associated with a CloudFront distribution to filter incoming HTTP(S) requests based on rules such as IP addresses, HTTP headers, URI strings, or SQL injection patterns. This allows you to block malicious traffic at the edge before it reaches your origin, providing a layer of security for content delivery.

Exam trap

The trap here is that candidates often confuse AWS Shield Standard (which is included with CloudFront) with AWS Shield Advanced (a separate paid service), leading them to incorrectly select Option C as a built-in CloudFront feature.

149
Multi-Selecthard

A company uses Amazon CloudFront to distribute content globally. They need to restrict access to premium content to only authenticated users. Which THREE methods can be used to achieve this?

Select 3 answers
A.AWS WAF IP set rules to allow only known IPs
B.AWS Shield Advanced to protect against DDoS
C.Lambda@Edge to validate JWT tokens
D.CloudFront signed cookies
E.CloudFront signed URLs
AnswersC, D, E

Lambda@Edge runs a function at CloudFront edge locations, letting you inspect the Authorization header and validate JWT tokens before the request reaches the origin, so unauthenticated viewers are rejected at the edge rather than at the origin.

Why this answer

Lambda@Edge (C) is correct because it runs custom Node.js/Python code at CloudFront edge locations, allowing the function to inspect incoming requests and validate JWT tokens (e.g., checking signature, issuer, and expiry) before serving premium content. CloudFront signed cookies (D) are correct because they grant access to multiple restricted files (such as an entire premium video library or HLS segments) using a single Set-Cookie header with a signed policy, ideal when you don't want to change URLs per object. CloudFront signed URLs (E) are correct because they provide time-limited, cryptographically signed access to individual objects, commonly used for one-off downloads or streaming a single premium file.

AWS WAF IP set rules (A) only filter by source IP address and do not authenticate users, so they cannot verify identity. AWS Shield Advanced (B) is a DDoS protection service and provides no user authentication or content access control.

150
MCQmedium

A company has an application running on EC2 instances behind an Application Load Balancer. Users report intermittent timeout errors. The ALB target group shows healthy instances, and CloudWatch metrics show no spikes in CPU or memory. Which configuration is most likely causing the timeouts?

A.Connection draining is set too low
B.The ALB idle timeout is set too low
C.The target group health check interval is too long
D.Cross-zone load balancing is disabled
AnswerB

The ALB idle timeout is the maximum time the load balancer allows between successive bytes of a client request or response before closing the connection. If an application takes longer than this interval to process a request and return data, the ALB terminates the connection, which appears to the client as a timeout error. For example, with the default 60-second idle timeout, a backend that runs a 90-second database query will consistently fail unless the timeout is increased to cover the expected processing time.

Why this answer

The ALB idle timeout is the period the load balancer waits for data on an idle connection before closing it. If it is set lower than the application's processing time (e.g., a long-running request), the ALB closes the connection and the client sees a timeout, even though targets are healthy and CPU/memory are normal. This matches the symptom of intermittent timeouts with no resource spikes.

Exam trap

SOA-C02 often tests the ALB idle timeout versus target health and connection draining — candidates blame health checks or draining, but the key clue is 'healthy targets, no CPU/memory spikes, intermittent timeouts,' which points to the idle timeout closing long-lived connections.

How to eliminate wrong answers

Option A is wrong because connection draining (deregistration delay) only affects in-flight requests during target deregistration — it does not cause timeouts on steady-state traffic. Option C is wrong because a long health check interval only delays detecting an unhealthy target; it does not cause client timeouts when targets are already healthy. Option D is wrong because disabling cross-zone load balancing affects distribution across AZs and can cause imbalance, but it does not by itself produce intermittent timeouts with healthy targets and no resource pressure.

← PreviousPage 2 of 3 · 193 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Networking and Content Delivery questions.