Courseiva

CCNA Networking and Content Delivery Questions

43 of 193 questions · Page 3/3 · Networking and Content Delivery · Answers revealed

151
MCQmedium

A company has a web application running on EC2 instances behind an Application Load Balancer (ALB) in the us-west-2 Region. Users are distributed globally and experience high latency. The SysOps administrator wants to improve latency and offload SSL termination to the edge. Which AWS service should be used with the ALB as the origin?

A.Amazon CloudFront
B.AWS Global Accelerator
C.AWS WAF (Web Application Firewall)
D.Amazon Route 53 with Latency Based Routing
AnswerA

Amazon CloudFront is a content delivery network that caches both static and dynamic content at edge locations geographically closer to users, reducing latency and offloading requests from the origin EC2 instances. It also terminates SSL/TLS at the edge, so decrypted traffic is forwarded over the AWS network to the origin, reducing the TLS handshake and encryption workload on the application servers. Additionally, CloudFront supports origin shielding, connection keep-alives, and multiple SSL/TLS protocols to further optimize delivery and reduce origin load.

Why this answer

Amazon CloudFront is a content delivery network (CDN) that caches content at edge locations worldwide, reducing latency for global users. It can offload SSL termination at the edge by accepting HTTPS requests from clients and forwarding them to the ALB over HTTP or HTTPS, thereby reducing the load on the origin. This directly addresses the requirements of improving latency and offloading SSL termination.

Exam trap

The trap here is that candidates often confuse AWS Global Accelerator with CloudFront, thinking both provide caching, but Global Accelerator only optimizes network path routing and does not cache content or terminate SSL at the edge.

How to eliminate wrong answers

Option B (AWS Global Accelerator) is wrong because it improves latency by routing traffic over the AWS global network using Anycast IPs, but it does not cache content or offload SSL termination at the edge; SSL termination still occurs at the ALB or EC2 instances. Option C (AWS WAF) is wrong because it is a web application firewall that filters malicious traffic, not a service for reducing latency or offloading SSL termination. Option D (Amazon Route 53 with Latency Based Routing) is wrong because it only directs DNS queries to the lowest-latency endpoint, but it does not cache content or terminate SSL at the edge; the actual traffic still goes directly to the ALB, and SSL termination remains at the origin.

152
Multi-Selecthard

A company is designing a multi-tier application in a VPC. The web tier must be in public subnets and the application tier in private subnets. The application tier needs to receive traffic only from the web tier. Which TWO configurations are required?

Select 2 answers
A.Configure the security group for the application tier to allow inbound traffic from the web tier's security group.
B.Ensure the web tier instances have a route to an Internet Gateway for user traffic.
C.Use a network ACL on the private subnet to deny all inbound traffic except from the public subnet CIDR.
D.Add a route to the Internet Gateway in the private subnet's route table.
E.Assign public IP addresses to the application tier instances for outbound access.
AnswersA, B

Configuring the application tier's security group to allow inbound traffic from the web tier's security group is the correct approach. This uses security group referencing, which lets you specify the web tier's security group ID as the source instead of a CIDR block. Because security groups are stateful, return traffic from the application tier is automatically permitted, and the rule dynamically tracks instance IPs, so autoscaling or instance replacements require no rule updates.

Why this answer

Security groups support stateful, rule-based traffic control using logical references to other security groups. By specifying the web tier's security group as the source in the application tier's inbound rule, traffic is allowed only from instances associated with that web tier security group, regardless of IP address changes. This provides a more secure and manageable configuration than using CIDR blocks, as it automatically adapts to scaling or instance replacements.

Exam trap

The trap here is that candidates often confuse security groups (stateful, instance-level) with network ACLs (stateless, subnet-level) and incorrectly assume that a network ACL rule denying all inbound traffic except from the public subnet CIDR is sufficient, overlooking the need for outbound rules and the dynamic, logical grouping benefits of security groups.

153
MCQmedium

A company has a VPC with public and private subnets. An Amazon EC2 instance in a private subnet needs to access an Amazon S3 bucket in the same AWS Region. The SysOps administrator wants to ensure the traffic does not traverse the internet. Which solution should be implemented?

A.Create a VPC Gateway Endpoint for S3.
B.Deploy a NAT Gateway in the public subnet and add a route to the private subnet's route table.
C.Attach an Internet Gateway to the VPC and add a default route in the private subnet's route table.
D.Set up an AWS Direct Connect connection to the S3 bucket.
AnswerA

A VPC Gateway Endpoint for S3 is the correct solution because it creates a horizontally scaled, redundant entry point that lets you route S3 traffic from your private subnet directly through the AWS backbone, not over the internet. You add a route to the subnet's route table using the S3 prefix list (e.g., pl-63a5400a for us-east-1), and no internet gateway, NAT, or public IP is required. This keeps traffic entirely within the AWS network, reducing egress costs and minimizing exposure to internet-based threats. Note that gateway endpoints are free and only support connectivity to S3 and DynamoDB within the same region.

Why this answer

A VPC Gateway Endpoint for S3 allows instances in a private subnet to access S3 without traversing the internet. It uses AWS's internal network, routing traffic through a prefix list in the route table, ensuring data stays within the AWS backbone. This meets the requirement of no internet traversal while providing secure, low-latency access to S3.

Exam trap

The trap here is that candidates often confuse Gateway Endpoints with Interface Endpoints or assume a NAT Gateway is required for private subnet outbound traffic, overlooking that S3 and DynamoDB can be accessed via Gateway Endpoints without internet connectivity.

How to eliminate wrong answers

Option B is wrong because a NAT Gateway enables outbound internet access for private instances, but traffic would still traverse the internet to reach S3, violating the requirement. Option C is wrong because attaching an Internet Gateway and adding a default route to the private subnet would route all traffic (including S3 requests) through the internet, which is not allowed. Option D is wrong because AWS Direct Connect is a dedicated network connection from on-premises to AWS, not a solution for VPC-to-S3 access within the same region; it adds unnecessary complexity and cost.

154
Multi-Selecthard

Which THREE configurations are required to enable an EC2 instance in a private subnet to access the internet for software updates while preventing inbound internet traffic?

Select 3 answers
A.Attach an Internet Gateway to the VPC.
B.Assign an Elastic IP address to the EC2 instance.
C.Add a route to the private subnet's route table with destination 0.0.0.0/0 pointing to the NAT Gateway.
D.Deploy a bastion host in the private subnet.
E.Place a NAT Gateway in a public subnet.
AnswersA, C, E

The Internet Gateway (IGW) is the VPC-wide component that enables bidirectional communication between the VPC and the internet. A NAT gateway must be provisioned inside a public subnet whose route table includes a 0.0.0.0/0 route to this IGW; without the IGW, the NAT gateway cannot resolve an external destination or forward return traffic. In short, the IGW is the essential upstream path that makes the NAT gateway's outbound translation functional.

Why this answer

An Internet Gateway (IGW) is required for any VPC to enable internet connectivity. Without an IGW, traffic cannot leave or enter the VPC from the internet. For a private subnet EC2 instance to reach the internet for software updates, the VPC must have an IGW attached, and the NAT Gateway (placed in a public subnet) uses the IGW to forward outbound traffic while blocking inbound connections.

Exam trap

The trap here is that candidates often think a NAT Gateway alone is sufficient, forgetting that an Internet Gateway must be attached to the VPC for the NAT Gateway to route traffic to the internet, or they mistakenly believe an Elastic IP on the instance itself is needed for outbound access.

155
MCQmedium

A company has an Amazon CloudFront distribution that delivers static content from an Amazon S3 bucket. The SysOps administrator needs to ensure that the content can only be accessed through CloudFront and not directly from the S3 bucket URL. The solution should use AWS managed services with minimal configuration. Which solution should the administrator implement?

A.Configure the S3 bucket policy to deny all access except from the CloudFront distribution's origin access identity (OAI).
B.Make the S3 bucket private and use pre-signed URLs for CloudFront.
C.Use AWS WAF on CloudFront to block direct access to S3 by checking the Referer header.
D.Create a VPC endpoint for S3 and restrict access to the bucket from the CloudFront IP addresses.
AnswerA

An Origin Access Identity (OAI) is a special CloudFront identity that can be assigned to a distribution, and the S3 bucket policy can explicitly grant read permission to that OAI's principal while using an explicit deny for all other principals. Since CloudFront signs requests as the OAI, only the distribution can fetch objects from the bucket; direct access to the S3 website or REST endpoint is rejected. This is the recommended AWS pattern because it relies on IAM evaluation of the caller identity rather than a client-controlled header or an IP-based allow list.

Why this answer

Configuring the S3 bucket policy to deny all access except from the CloudFront distribution's origin access identity (OAI) ensures that only CloudFront can retrieve objects from the S3 bucket. The OAI is a special CloudFront user that authenticates requests to S3, and the bucket policy explicitly grants GetObject access only to that principal, blocking any direct S3 URL access. This uses AWS managed services (CloudFront and S3) with minimal configuration—no custom code or additional infrastructure.

Exam trap

The trap here is that candidates often choose Option C (AWS WAF with Referer header) because it seems like a simple web-application-layer control, but they overlook that the Referer header is easily spoofed and does not provide cryptographic authentication, unlike the OAI-based approach which uses AWS Signature Version 4 to verify the request origin.

How to eliminate wrong answers

Option B is wrong because making the S3 bucket private and using pre-signed URLs for CloudFront adds unnecessary complexity; CloudFront does not natively generate pre-signed URLs for origin requests, and this would require custom logic to sign each request, defeating the 'minimal configuration' requirement. Option C is wrong because using AWS WAF to block direct access by checking the Referer header is unreliable—the Referer header can be spoofed or omitted by clients, and it does not prevent direct S3 URL access from scripts or tools that don't send a Referer. Option D is wrong because creating a VPC endpoint for S3 and restricting access to CloudFront IP addresses is not feasible; CloudFront uses a large, dynamic set of global IP addresses that are not static, and maintaining an allow list of those IPs would require constant updates and is not a 'minimal configuration' solution.

156
Multi-Selectmedium

A company is using Amazon Route 53 with a private hosted zone for internal DNS resolution within a VPC. The VPC is connected to an on-premises network via a VPN. On-premises resources cannot resolve DNS names in the private hosted zone. Which TWO actions should be taken to resolve this issue? (Choose two.)

Select 2 answers
A.Configure route propagation from the VPN to the VPC's route table.
B.Associate the private hosted zone with the on-premises network.
C.Enable DNS resolution and DNS hostnames for the VPC.
D.Create a public hosted zone with the same name and associate it with the VPC.
E.Create a Route 53 inbound resolver endpoint in the VPC.
AnswersC, E

This is a required VPC setting: the VPC must have both DNS resolution (the Amazon-provided DNS server at the VPC CIDR + 2) and DNS hostnames enabled. When DNS resolution is enabled, Route 53 can answer queries against private hosted zones from instances or the VPC resolver; DNS hostnames is necessary for AWS to assign and use internal DNS names for instances. Without these settings, the VPC's resolver behavior is disabled and private-hosted-zone lookups fail.

Why this answer

To allow on-premises resources to resolve DNS names in a private hosted zone, you need to create a Route 53 inbound resolver endpoint in the VPC (option E). This endpoint allows DNS queries from on-premises to be forwarded to Route 53. Additionally, you must enable DNS resolution and DNS hostnames for the VPC (option C) to ensure that the VPC's DNS settings support internal resolution.

Option A is incorrect because route propagation affects network routing, not DNS resolution. Option B is incorrect because private hosted zones cannot be associated with on-premises networks directly. Option D is incorrect because a public hosted zone is used for public DNS and does not resolve private DNS queries.

157
MCQmedium

A SysOps Administrator is configuring a Network Load Balancer (NLB) for a TCP-based application. The application requires that clients see the original source IP address of the request. Which configuration should the Administrator use?

A.Use the NLB default behavior; no additional configuration needed.
B.Use an Application Load Balancer instead, which preserves the source IP.
C.Enable cross-zone load balancing on the NLB.
D.Enable Proxy Protocol v2 on the target group.
AnswerA

A Network Load Balancer operates at Layer 4 and forwards packets as-is to the registered targets, so the client IP address is preserved in the original packet headers by default. Unlike Layer 7 load balancers, the NLB does not terminate the TCP connection or perform NAT on the source address. Therefore, no additional settings, headers, or protocols are required to make the client source IP visible to the backend.

Why this answer

Network Load Balancers (NLBs) preserve the original source IP address of clients by default when forwarding TCP traffic to targets. This is because NLBs operate at Layer 4 and do not terminate the TCP connection; instead, they pass packets directly to the backend, allowing the target to see the client's IP. No additional configuration is required for this behavior.

Exam trap

The trap here is that candidates often confuse NLB and ALB behavior, assuming that preserving source IP requires a special configuration like Proxy Protocol, when in fact NLBs do this by default for TCP traffic.

How to eliminate wrong answers

Option B is wrong because an Application Load Balancer (ALB) terminates the client connection and re-establishes a new connection to the target, which by default replaces the source IP with the ALB's private IP; ALBs require the X-Forwarded-For header to convey the original client IP, not direct preservation. Option C is wrong because cross-zone load balancing distributes traffic across targets in multiple Availability Zones but does not affect source IP preservation. Option D is wrong because Proxy Protocol v2 is an optional header that can be added to preserve client IP information when using TCP listeners, but it is not required for NLB default behavior; enabling it would add an extra header, not fix a missing IP.

158
MCQmedium

A company runs an application on Amazon EC2 instances behind an Application Load Balancer (ALB). The ALB terminates SSL/TLS and forwards traffic to the instances over HTTP. The SysOps administrator needs to capture the original client IP address in the instance logs. How should the administrator configure this?

A.Enable stickiness on the ALB target group.
B.Enable the X-Forwarded-For header on the ALB.
C.Configure the ALB to use Proxy Protocol v2.
D.Enable access logs on the ALB and store them in Amazon S3.
AnswerB

The ALB automatically adds the X-Forwarded-For header to each HTTP/HTTPS request as it passes through, containing the original client IP address in a comma-separated list. Since the ALB terminates the client's TLS connection and opens a new connection to the target, the EC2 instance must read this header to record the client IP in its logs. By default, the ALB overwrites any existing X-Forwarded-For header to prevent client spoofing, and you should configure your web server or application to log the first IP in the header, which is the true client IP.

Why this answer

When an Application Load Balancer terminates SSL/TLS and forwards traffic to EC2 instances over HTTP, the original client IP address is preserved by the ALB in the X-Forwarded-For header. By enabling this header on the ALB, the SysOps administrator ensures that the web server or application can log the true client IP, which is essential for analytics, security, and troubleshooting.

Exam trap

The trap here is that candidates confuse Proxy Protocol v2 (used for NLB TCP/UDP listeners) with the X-Forwarded-For header (used for ALB HTTP/HTTPS listeners), leading them to select option C even though it is not applicable to ALB's HTTP-based forwarding.

How to eliminate wrong answers

Option A is wrong because enabling stickiness (session affinity) on the ALB target group only ensures that requests from the same client are routed to the same target instance; it does not capture or forward the original client IP address. Option C is wrong because Proxy Protocol v2 is used with Network Load Balancers (NLB) or TCP listeners, not with Application Load Balancers (ALB) which use HTTP/HTTPS listeners and rely on the X-Forwarded-For header for client IP preservation. Option D is wrong because enabling ALB access logs and storing them in Amazon S3 captures request details including client IP, but it does not inject the original client IP into the instance logs; the instance logs still see the ALB's private IP unless the X-Forwarded-For header is used.

159
MCQmedium

A company deploys a web application on EC2 instances behind an Application Load Balancer. The SysOps administrator needs to allow inbound traffic only from the ALB to the EC2 instances. Currently, the EC2 security group allows inbound HTTP from 0.0.0.0/0. Which security group configuration should the administrator apply?

A.Keep the existing rule that allows inbound HTTP from 0.0.0.0/0, but add a network ACL to block traffic from the internet.
B.Modify the EC2 security group to allow inbound HTTP from the ALB's security group.
C.Modify the EC2 security group to allow inbound HTTP from the ALB's private IP addresses.
D.Modify the EC2 security group to allow inbound HTTP from the ALB's public IP addresses.
AnswerB

Referencing the ALB's security group as the source in the EC2 instance security group creates a highly precise trust boundary: only traffic originating from network interfaces associated with that ALB security group is permitted, so direct internet access to the instance is impossible. Because the rule references the security group ID rather than any IP address, it automatically follows the ALB's elastic network interfaces as the load balancer scales or moves between Availability Zones, requiring no manual updates. This leverages the stateful nature of security groups — return traffic is automatically allowed — and it is the documented, recommended pattern for application load balancer to target communication.

Why this answer

Security groups can reference other security groups as sources, so allowing inbound HTTP on the EC2 instances' security group from the ALB's security group automatically permits traffic from all current and future ALB nodes. This is the AWS-recommended pattern because ALB IP addresses change dynamically and cannot be reliably hardcoded. It also ensures only traffic that passed through the load balancer reaches the instances.

Exam trap

SOA-C02 often tests the misconception that you must whitelist the ALB's IP addresses; the trap is not knowing that security group referencing is the correct, dynamic-safe method.

How to eliminate wrong answers

Option A is wrong because leaving 0.0.0.0/0 open still allows direct internet access to the instances; a network ACL is stateless and subnet-level, so it does not cleanly restrict traffic to only the ALB. Option C is wrong because ALB private IP addresses are not static and change as the load balancer scales, so rules based on them will break. Option D is wrong because instances should never receive traffic from the ALB's public IPs; the ALB forwards traffic from its private nodes, and public IPs are not stable either.

160
MCQhard

A SysOps administrator needs to route traffic to multiple AWS regions for disaster recovery using Amazon Route 53. The primary region should receive all traffic unless it becomes unhealthy. Which routing policy should be used?

A.Failover routing policy
B.Geolocation routing policy
C.Latency routing policy
D.Weighted routing policy
AnswerA

Route 53 failover routing policy implements active-passive failover by using two records with the same name and type: a primary record associated with a health check and a secondary record. When the primary health check fails, Route 53 automatically returns the secondary record's value in DNS responses, directing traffic to the second resource. This policy is expressly designed to keep services available if the primary target becomes unhealthy, which matches the requirement to route traffic to multiple AWS endpoints with automatic failover.

Why this answer

Failover routing policy is correct because it allows you to configure an active-passive setup where all traffic is directed to a primary resource (e.g., an Elastic Load Balancer in the primary region) unless Route 53 health checks determine that the primary is unhealthy. When the primary fails, Route 53 automatically routes traffic to the secondary (disaster recovery) resource in another region. This directly meets the requirement of sending all traffic to the primary region unless it becomes unhealthy.

Exam trap

The trap here is that candidates often confuse failover routing with weighted or latency routing, thinking they can achieve disaster recovery by distributing traffic, but only failover routing provides the required active-passive health-based failover behavior.

How to eliminate wrong answers

Option B (Geolocation routing policy) is wrong because it routes traffic based on the geographic location of the user, not based on the health of the resource; it does not provide automatic failover to a disaster recovery region. Option C (Latency routing policy) is wrong because it routes traffic to the region with the lowest latency for the user, which does not guarantee that all traffic goes to a single primary region unless it becomes unhealthy. Option D (Weighted routing policy) is wrong because it distributes traffic across multiple resources based on assigned weights, not on health status; it cannot ensure that all traffic goes to the primary region unless it fails.

161
MCQmedium

A company runs an application on Amazon EC2 instances in private subnets of a VPC. The application needs to upload files to an Amazon S3 bucket in the same AWS Region. The SysOps administrator wants to ensure that traffic to S3 does not traverse the internet and minimizes data transfer costs. Which solution should the administrator implement?

A.Create a NAT gateway in a public subnet and route private subnet traffic to it.
B.Create an S3 Gateway Endpoint and add a route in the private subnet route table pointing to it.
C.Create an S3 Interface Endpoint and assign a security group.
D.Use AWS PrivateLink to connect to S3.
AnswerB

An S3 Gateway Endpoint is a free, highly available gateway object attached to a VPC that uses a prefix list to route S3 traffic from a private subnet without going over the internet. You must add a route in the private subnet's route table with the destination as the S3 prefix list and the target as the gateway endpoint; traffic stays entirely inside the AWS network. This is the recommended pattern for private subnets because it requires no NAT gateway, no IGW, and no data transfer charges.

Why this answer

An S3 Gateway Endpoint is the correct solution because it provides private connectivity from a VPC to S3 without traversing the internet, using AWS's internal network. By adding a route in the private subnet's route table pointing to the gateway endpoint, traffic to S3 stays within the AWS backbone, minimizing data transfer costs (no NAT gateway charges) and avoiding internet egress fees.

Exam trap

The trap here is that candidates often confuse Gateway Endpoints with Interface Endpoints, assuming Interface Endpoints are always better because they use security groups, but for S3, Gateway Endpoints are free and more cost-effective, while Interface Endpoints incur additional charges.

How to eliminate wrong answers

Option A is wrong because a NAT gateway routes traffic through the internet to reach S3, incurring data transfer costs and NAT gateway hourly charges, and it still traverses the internet, violating the requirement to avoid internet traversal. Option C is wrong because an S3 Interface Endpoint (powered by AWS PrivateLink) incurs hourly charges and per-GB data processing fees, making it more expensive than a Gateway Endpoint for S3, and it is typically used for services that don't support Gateway Endpoints (e.g., DynamoDB, API Gateway). Option D is wrong because AWS PrivateLink is the underlying technology for Interface Endpoints, not a separate solution; using PrivateLink directly would still involve Interface Endpoint costs and complexity, and it is not the optimal choice for S3 when a Gateway Endpoint is available.

162
MCQhard

A company has a VPC with public and private subnets. A NAT Gateway is deployed in the public subnet to allow instances in the private subnet to access the internet. However, private instances cannot reach an external service at 203.0.113.50:443. What should be checked first?

A.The route table for the private subnet has a route 0.0.0.0/0 pointing to the NAT Gateway.
B.The NAT Gateway has an Elastic IP assigned.
C.The security group for the NAT Gateway allows inbound traffic from the private subnet.
D.The internet gateway is attached to the VPC.
AnswerA

Private-subnet instances reach the internet only if their route table has 0.0.0.0/0 targeting the NAT Gateway. Verifying this route first confirms whether traffic can leave the subnet at all before investigating security groups, NACLs or the NAT Gateway itself.

Why this answer

The most common cause of private instances failing to reach the internet via a NAT Gateway is a missing or incorrect route in the private subnet's route table. The private subnet must have a route for 0.0.0.0/0 pointing to the NAT Gateway; otherwise, traffic has no path out. This is the first thing to verify because it is the fundamental routing requirement for NAT Gateway functionality.

Exam trap

SOA-C02 often tests the order of troubleshooting steps: candidates may jump to checking the NAT Gateway's Elastic IP or security groups, but the most common and first thing to verify is the private subnet's route table.

How to eliminate wrong answers

Option B is wrong because a NAT Gateway always requires an Elastic IP at creation, so it is not a likely misconfiguration; checking it first is less efficient. Option C is wrong because NAT Gateways do not use security groups; they are managed by AWS and do not have security group associations. Option D is wrong because if the internet gateway were not attached, the NAT Gateway itself would not function, but the question specifies the NAT Gateway is deployed, implying the IGW is likely present; also, the private subnet route is more directly related to the private instances' failure.

163
MCQhard

A company has deployed a global web application using AWS CloudFront with an Application Load Balancer (ALB) as the origin. The ALB is in a single AWS region. Users in different geographic regions report high latency, and some users are unable to access the application. The SysOps administrator verifies that the CloudFront distribution is configured correctly and that the ALB is healthy. The administrator also confirms that the ALB's security group allows traffic from the CloudFront IP ranges. What is the most likely cause of the issue?

A.The ALB is overwhelmed by the number of concurrent connections from CloudFront
B.CloudFront is not caching content, causing all requests to go to the origin
C.The CloudFront distribution is using TCP instead of HTTP, causing higher latency
D.The SSL/TLS certificate on the ALB is not trusted by CloudFront
AnswerA

CloudFront's global network of edge locations each establishes a pool of persistent (keep-alive) TCP connections to the ALB origin. In a busy distribution, the aggregate of these connections across all edges can exceed the ALB's concurrent connection capacity (MaxConnectionIdleTime, target group limits, or instance/scale limits), causing SYN queue saturation, latency, and timeouts. The fix is to scale the ALB and adjust keep-alive timeouts, not to assume caching or TLS errors.

Why this answer

The ALB in a single region can become overwhelmed by the high volume of concurrent connections from CloudFront's global edge locations, even though the security group allows traffic from CloudFront IP ranges. This can cause high latency and access failures for users in different regions. Option B is incorrect because CloudFront caching typically reduces the load on the origin by serving cached content at edge locations.

Option C is incorrect because CloudFront distributions support HTTP and HTTPS protocols, not TCP/UDP, and the protocol used does not explain the regional latency issue. Option D is incorrect because the SSL/TLS certificate on the ALB must be trusted by CloudFront for HTTPS connections, but this would not cause intermittent access issues across regions if the distribution is configured correctly.

164
MCQeasy

A company has an application running on EC2 instances in a VPC. The application needs to access an S3 bucket in the same AWS region. Which configuration provides the MOST secure and cost-effective access?

A.Make the S3 bucket publicly accessible and use the public endpoint from the EC2 instances.
B.Set up a NAT Gateway in a public subnet and route traffic from the EC2 instances through it to the S3 endpoint.
C.Create a VPC Gateway Endpoint for S3 and update the route tables for the private subnets.
D.Create an Internet Gateway and route traffic from the EC2 instances through it to a public S3 endpoint.
AnswerC

A VPC Gateway Endpoint routes S3 traffic privately over the AWS network, bypassing NAT Gateways and internet gateways entirely. This removes NAT data-processing charges and keeps traffic off the public internet, satisfying both the security and cost-effectiveness constraints for same-region S3 access.

Why this answer

A VPC Gateway Endpoint for S3 allows EC2 instances in private subnets to access S3 directly over the AWS network without traversing the internet, eliminating the need for a NAT Gateway or Internet Gateway. This provides the most secure and cost-effective access by keeping traffic within the AWS backbone and avoiding data transfer costs associated with NAT Gateways or public endpoints.

Exam trap

The trap here is that candidates often confuse VPC Gateway Endpoints with VPC Interface Endpoints (powered by AWS PrivateLink), but for S3, a Gateway Endpoint is the correct and most cost-effective choice because it does not require an Elastic Network Interface or incur hourly charges, unlike an Interface Endpoint.

How to eliminate wrong answers

Option A is wrong because making the S3 bucket publicly accessible exposes it to the entire internet, violating security best practices and potentially leading to unauthorized access or data breaches. Option B is wrong because a NAT Gateway incurs hourly charges and data processing costs, and it routes traffic through the internet unnecessarily, making it less cost-effective and less secure than a VPC Gateway Endpoint. Option D is wrong because an Internet Gateway is designed for public internet access, and routing EC2 traffic through it to a public S3 endpoint exposes the traffic to the internet, increasing latency and security risks while adding unnecessary complexity and cost.

165
MCQmedium

A company runs a gaming application that uses Amazon EC2 instances to handle real-time multiplayer sessions. The application requires low-latency communication with users around the world. The SysOps administrator needs to accelerate content delivery for non-cacheable, dynamic content (such as real-time game state updates) and also provide static asset delivery. The solution must support both TCP and UDP traffic. Which AWS service should be used?

A.AWS Global Accelerator
B.Amazon CloudFront with origins configured for both dynamic and static content
C.AWS Shield Advanced
D.AWS App Mesh
AnswerA

Global Accelerator uses the AWS global network to optimize the path from users to applications. It supports both TCP and UDP traffic, making it suitable for real-time gaming applications that require low latency for both dynamic data and static assets (if static assets are served from the same endpoint).

Why this answer

AWS Global Accelerator is the correct choice because it uses the AWS global network and Anycast IPs to route TCP and UDP traffic to the optimal endpoint, providing low-latency performance for non-cacheable dynamic content like real-time game state updates. It also supports static asset delivery by directing traffic to origins such as Application Load Balancers or EC2 instances, and it handles both TCP and UDP protocols natively, which is essential for real-time multiplayer gaming.

Exam trap

The trap here is that candidates often assume CloudFront can handle all content delivery scenarios, but it does not support UDP traffic and is designed for cacheable HTTP/HTTPS content, making it unsuitable for real-time multiplayer games that require low-latency UDP communication.

How to eliminate wrong answers

Option B is wrong because Amazon CloudFront is a content delivery network (CDN) optimized for cacheable content (HTTP/HTTPS) and does not support UDP traffic; it cannot accelerate non-cacheable dynamic content with low-latency UDP requirements. Option C is wrong because AWS Shield Advanced is a DDoS protection service that provides mitigation against volumetric attacks, but it does not accelerate content delivery or handle TCP/UDP traffic routing for performance. Option D is wrong because AWS App Mesh is a service mesh for microservices communication within a cluster (e.g., ECS/EKS) and does not provide global traffic acceleration or support for UDP traffic at the edge.

166
MCQeasy

A company is designing a highly available architecture for a web application using an Application Load Balancer (ALB) across multiple Availability Zones. Which configuration ensures that traffic is distributed evenly across all healthy targets?

A.Enable cross-zone load balancing on the ALB
B.Configure sticky sessions (session affinity) on the target group
C.Use a Network Load Balancer with path-based routing
D.Enable connection draining on the target group
AnswerA

Enabling cross-zone load balancing on the ALB allows the load balancer to distribute incoming traffic evenly across all registered targets in all enabled Availability Zones, rather than confining traffic to targets within the same AZ. This is the correct approach because it ensures optimal resource utilization and fault tolerance, especially when workloads or target capacities vary across AZs. Without this feature, each AZ would receive an equal share of traffic, but targets within a less capable AZ could become overwhelmed.

Why this answer

Cross-zone load balancing enables the ALB to distribute incoming traffic evenly across all healthy targets in all enabled Availability Zones, rather than sending traffic only to targets within the same zone as the requesting client. By default, ALBs distribute traffic equally across zones first, then round-robin within each zone, which can lead to uneven load if target counts differ per zone. Enabling cross-zone load balancing overrides this behavior, ensuring each healthy target receives an equal share of requests regardless of its zone.

Exam trap

The trap here is that candidates often confuse cross-zone load balancing with sticky sessions or connection draining, assuming that session affinity or graceful termination will improve distribution, when in fact only cross-zone load balancing ensures even traffic spread across all healthy targets.

How to eliminate wrong answers

Option B is wrong because sticky sessions (session affinity) bind a client to a specific target for the duration of its session, which can cause uneven traffic distribution and does not ensure even distribution across all healthy targets. Option C is wrong because a Network Load Balancer (NLB) does not support path-based routing; path-based routing is a feature of Application Load Balancers, and using an NLB would not address the requirement for even distribution across healthy targets. Option D is wrong because connection draining (deregistration delay) allows in-flight requests to complete before a target is removed from service, but it does not influence how traffic is distributed among healthy targets during normal operation.

167
Multi-Selecteasy

Which TWO security measures should be implemented to protect a VPC from DDoS attacks? (Choose two.)

Select 2 answers
A.Use AWS WAF with rate-based rules
B.Enable AWS Shield Advanced
C.Apply network ACLs with deny rules
D.Use restrictive security groups
E.Enable VPC Flow Logs
AnswersA, B

AWS WAF rate-based rules are specifically engineered to mitigate application-layer DDoS attacks by tracking the number of requests from a single client IP within a set time window. When the request count exceeds the configured threshold, AWS WAF blocks subsequent traffic from that IP for the rule's duration, effectively limiting the volume of requests that can reach your origin. This provides an automated, scalable defense that can be attached to Amazon CloudFront, ALB, or API Gateway, and it allows you to fine-tune thresholds based on your normal traffic baseline.

Why this answer

AWS WAF with rate-based rules (option A) is correct because it can inspect incoming HTTP/HTTPS requests at the application layer and automatically block or throttle source IPs that exceed a defined request threshold, which directly mitigates application-layer (Layer 7) DDoS floods against resources like an ALB or CloudFront. AWS Shield Advanced (option B) is correct because it provides enhanced, always-on detection and automatic inline mitigation for Layer 3/4 (and Layer 7 with WAF integration) DDoS attacks, plus access to the AWS DDoS Response Team and cost protection for scaling charges incurred during an attack. The other options are not the intended answers: network ACLs with deny rules (C) and restrictive security groups (D) are stateful/stateless traffic filters that can block known bad ports or sources but cannot detect or absorb volumetric or application-layer DDoS patterns, and VPC Flow Logs (E) only capture IP traffic metadata for monitoring and forensics—they do not block or mitigate attacks.

Exam trap

SOA-C02 often tests the confusion between preventive security controls (security groups, NACLs) and DDoS-specific services (Shield, WAF), tricking candidates into selecting generic firewall controls that cannot mitigate volumetric attacks.

168
MCQeasy

A company wants to host a static website on AWS with high availability and low latency for global users. Which combination of services should be used?

A.Amazon EC2 and Elastic Load Balancing
B.Amazon S3 and Amazon CloudFront
C.Amazon Route 53 and Amazon S3
D.Elastic Load Balancing and Amazon CloudFront
AnswerB

Amazon S3 and Amazon CloudFront is the AWS best-practice architecture for hosting a static website at global scale. S3 stores the HTML, CSS, JavaScript, and images durably and cost-effectively, while CloudFront caches those objects at edge locations around the world, dramatically reducing latency for all users. Using CloudFront with an Origin Access Control (OAC) keeps the S3 bucket private, adds HTTPS enforcement, and provides high availability because content is served from multiple edge locations even if the origin has transient issues.

Why this answer

Amazon S3 provides durable, highly available object storage ideal for hosting static website content, and Amazon CloudFront is a global CDN that caches content at edge locations worldwide, delivering low-latency access for global users. Together they form the canonical AWS static website architecture with no servers to manage.

Exam trap

SOA-C02 often tests whether candidates confuse 'high availability' (S3's multi-AZ durability) with 'low latency for global users' (which specifically requires CloudFront edge caching, not just S3 or Route 53).

How to eliminate wrong answers

Option A is wrong because EC2 requires managing servers and ELB only distributes traffic regionally, not providing global edge caching or static hosting. Option C is wrong because Route 53 alone provides DNS routing but no caching or content delivery acceleration — S3 alone cannot deliver low latency globally. Option D is wrong because ELB requires backend compute (like EC2) and does not host static content or provide global edge caching like CloudFront.

169
MCQeasy

A company wants to provide low-latency access to a web application for users in North America and Europe. The application runs on EC2 instances in us-east-1 and eu-west-1. Which AWS service should be used to route users to the nearest region?

A.Application Load Balancer with cross-region load balancing
B.Amazon CloudFront
C.AWS Global Accelerator
D.Amazon Route 53 with latency-based routing
AnswerD

Amazon Route 53 latency-based routing sends each user's DNS query to the endpoint in the AWS Region that currently has the lowest latency from the user's DNS resolver. Route 53 maintains latency data for traffic between regions and the resolver, and returns the appropriate IP address for that region, enabling low-latency access when the application is deployed in multiple Regions.

Why this answer

Amazon Route 53 with latency-based routing directs user traffic to the AWS region that provides the lowest latency for the end user. By configuring latency records for the EC2 instances in us-east-1 and eu-west-1, Route 53 responds to DNS queries with the IP address of the region that offers the best network performance, effectively routing users to the nearest region.

Exam trap

The trap here is that candidates often confuse Global Accelerator's Anycast-based routing with DNS-based latency routing, but Global Accelerator optimizes the network path from the edge to the origin, not the user's initial routing to the nearest region, which is a DNS-level decision.

How to eliminate wrong answers

Option A is wrong because an Application Load Balancer with cross-region load balancing distributes traffic across targets in multiple regions but does not route users based on their geographic proximity; it balances load regardless of user location. Option B is wrong because Amazon CloudFront is a content delivery network (CDN) that caches content at edge locations for low-latency delivery, but it does not route users to the nearest origin region; it serves cached content from the edge, not direct traffic to the closest EC2 instance. Option C is wrong because AWS Global Accelerator uses Anycast IP addresses and the AWS global network to direct traffic to the optimal endpoint based on health and latency, but it is designed for TCP/UDP traffic and requires static IP addresses, whereas the question specifically asks for routing users to the nearest region, which is a DNS-level function best handled by Route 53 latency-based routing.

170
MCQeasy

A company is using an Application Load Balancer (ALB) to distribute traffic to a fleet of EC2 instances. The company needs to ensure that the ALB sends requests to instances that are healthy and can serve traffic. Which feature should be used to monitor the health of the instances?

A.Health checks
B.Sticky sessions
C.Cross-zone load balancing
D.Connection draining
AnswerA

Health checks in an Application Load Balancer (ALB) are the mechanism that actively monitors the availability of targets by sending HTTP or HTTPS requests to a specified path, such as /health, and evaluating the response against configured success codes, e.g., 200. If a target fails a consecutive number of checks, the ALB marks it unhealthy and stops routing new traffic to it, while healthy targets continue to receive requests. This is the core feature that enables the ALB to perform automatic failover and maintain high availability.

Why this answer

Health checks allow the ALB to monitor the health of EC2 instances by sending periodic requests to a specified endpoint (e.g., /health). If an instance fails consecutive health checks, the ALB stops sending traffic to it. Option B is incorrect because sticky sessions (session affinity) ensure a client's requests are sent to the same instance, not health monitoring.

Option C is incorrect because cross-zone load balancing distributes traffic across instances in multiple Availability Zones. Option D is incorrect because connection draining (deregistration delay) allows in-flight requests to complete before an instance is removed from the target group.

171
MCQmedium

A company uses Amazon CloudFront with an Application Load Balancer (ALB) as the origin. The SysOps administrator needs to restrict access to the ALB so that it only accepts requests from CloudFront. Which solution should the administrator implement?

A.Replace the ALB with a Network Load Balancer and use a VPC endpoint
B.Create an origin access identity (OAI) and attach it to the CloudFront distribution
C.Add a security group rule to the ALB that allows traffic only from the CloudFront IP ranges
D.Configure CloudFront to add a custom HTTP header to requests, and configure the ALB to only forward requests that contain that header
AnswerD

Configure CloudFront to inject a secret custom HTTP header into every request it forwards to the ALB, and then configure the ALB listener rule to only route traffic that contains that exact header and value. CloudFront strips any client-supplied header with the same name, so the secret cannot be discovered or forged by users making direct requests to the ALB. This ensures only traffic that passed through your CloudFront distribution is accepted, securely restricting access to your origin.

Why this answer

It uses a shared secret mechanism: CloudFront is configured to add a custom HTTP header (e.g., X-Origin-Verify) to all requests, and the ALB's listener rule is configured to only forward requests that contain that specific header value. This ensures that only requests originating from your CloudFront distribution reach the ALB, as the header is not present in direct client requests. This approach is recommended by AWS for restricting ALB access to CloudFront when the origin is an ALB, because CloudFront does not support Origin Access Identity (OAI) with ALB origins.

Exam trap

The trap here is that candidates often confuse Origin Access Identity (OAI) as a universal CloudFront feature, not realizing it only works with S3 origins, and they overlook the impracticality of using CloudFront IP ranges in security groups due to their dynamic nature.

How to eliminate wrong answers

Option A is wrong because replacing the ALB with a Network Load Balancer (NLB) and using a VPC endpoint does not inherently restrict access to CloudFront; a VPC endpoint is used for private connectivity, not for authenticating the source of traffic, and NLB does not support custom header-based filtering natively. Option B is wrong because Origin Access Identity (OAI) is a feature specific to Amazon S3 origins, not Application Load Balancers; OAI cannot be attached to a CloudFront distribution with an ALB origin. Option C is wrong because CloudFront does not have a fixed set of IP ranges; its IP addresses change frequently and are published via a public list, making it impractical and insecure to maintain a security group rule that only allows CloudFront IP ranges, as the list is large and dynamic.

172
MCQeasy

A company wants to establish a dedicated, low-latency, private connection between its on-premises data center and an AWS VPC. The company does not want to use the public internet. Which AWS service should be used to meet this requirement?

A.AWS Direct Connect
B.AWS Virtual Private Gateway
C.AWS Transit Gateway
D.VPC Peering
AnswerA

AWS Direct Connect provides a dedicated private network connection from on-premises to AWS, bypassing the public internet entirely. It satisfies the low-latency and privacy constraints by using a physical cross-connect at an AWS Direct Connect location, delivering consistent network performance rather than variable internet routing.

Why this answer

AWS Direct Connect is the correct service because it provides a dedicated, private, low-latency network connection from an on-premises data center to AWS, bypassing the public internet entirely. It uses industry-standard 802.1Q VLANs to create a private virtual interface (VIF) that connects directly to a VPC, ensuring consistent network performance and reduced latency.

Exam trap

The trap here is that candidates often confuse AWS Virtual Private Gateway (a required attachment for Direct Connect) with the Direct Connect service itself, or they assume VPC Peering can extend to on-premises networks, but VPC Peering is strictly limited to inter-VPC connectivity within AWS.

How to eliminate wrong answers

Option B (AWS Virtual Private Gateway) is wrong because it is a logical component that attaches to a VPC to enable VPN or Direct Connect connections, but it is not a service that itself provides a dedicated private connection; it requires Direct Connect or a VPN to function. Option C (AWS Transit Gateway) is wrong because it is a network transit hub used to interconnect multiple VPCs and on-premises networks, but it does not provide the dedicated physical connection itself; it relies on Direct Connect or VPN for the on-premises link. Option D (VPC Peering) is wrong because it only connects two VPCs within AWS using the AWS global network, and it cannot be used to connect an on-premises data center to a VPC.

173
Multi-Selectmedium

A company has a VPC with a public subnet and a private subnet. The private subnet contains an EC2 instance that must access the internet for software updates. Which TWO actions are required to enable this? (Choose TWO.)

Select 2 answers
A.Add an Internet Gateway to the private subnet's route table.
B.Deploy a NAT Gateway in a public subnet.
C.Assign a public IP address to the EC2 instance.
D.Attach an Internet Gateway to the NAT Gateway.
E.Add a route in the private subnet's route table pointing to the NAT Gateway for 0.0.0.0/0.
AnswersB, E

Deploying a NAT Gateway in a public subnet is correct because the NAT Gateway is a managed service that must reside in a subnet that has a route to an Internet Gateway (IGW). This placement enables the NAT Gateway to translate private IP addresses from instances in private subnets into its own Elastic IP address and forward traffic to the IGW for outbound connections. Because the NAT Gateway is in a public subnet, it can reach the internet and, at the same time, it does not accept inbound connections from the internet, preserving the security boundary. Its managed nature means you do not need to patch or operate it, and it automatically scales to handle bursts of traffic.

Why this answer

A NAT Gateway in a public subnet provides outbound internet access for private instances while preventing inbound connections. The private subnet's route table must include a default route (0.0.0.0/0) pointing to the NAT Gateway, enabling traffic to be forwarded to the internet via the Internet Gateway attached to the VPC.

Exam trap

The trap here is that candidates often think a public IP on the instance or an Internet Gateway in the private subnet is needed, but the correct solution uses a NAT Gateway in a public subnet with a default route in the private subnet's route table.

174
MCQhard

A company has multiple VPCs in the same AWS account and Region, each with overlapping CIDR blocks (10.0.0.0/16). The SysOps administrator needs to establish connectivity between all VPCs and the on-premises network via AWS Transit Gateway. Additionally, certain VPCs must be isolated from each other while still reaching on-premises. How should the administrator configure the Transit Gateway to meet these requirements?

A.Create a single Transit Gateway route table and add routes for all VPCs and the on-premises network.
B.Create multiple Transit Gateway route tables: one for each group of VPCs that need to communicate, and associate each VPC attachment with the appropriate route table. Add static routes to the on-premises network in each route table.
C.Use VPC peering instead of Transit Gateway to connect VPCs, and use Direct Connect Gateway for on-premises connectivity.
D.Configure VPN connections between each VPC and the on-premises network, bypassing Transit Gateway.
AnswerB

Create separate Transit Gateway route tables, one per group of VPCs that must communicate, and associate each VPC attachment with its group's route table. Within each route table, add static routes pointing to the on-premises network (or propagate from the VPN/DX attachment) so every group retains reachability to the data center. Because route tables are independent, overlapping CIDRs across groups are never compared, avoiding routing conflicts; traffic between groups is denied by default since no routes exist. This gives you transitive routing within a group and full isolation between groups, which is exactly what the scenario demands.

Why this answer

AWS Transit Gateway supports multiple route tables, allowing you to isolate VPC attachments from each other while still providing a common route to the on-premises network. By creating separate route tables for each group of VPCs that need to communicate, and associating the appropriate VPC attachments with those tables, you can enforce isolation between groups. Adding static routes to the on-premises network in each route table ensures all VPCs can reach on-premises, even when they cannot communicate with each other.

Exam trap

The trap here is that candidates assume a single Transit Gateway route table is sufficient for all VPCs, overlooking the need for isolation between specific VPC groups when overlapping CIDRs are present.

How to eliminate wrong answers

Option A is wrong because a single Transit Gateway route table would allow all VPC attachments to communicate with each other, violating the requirement to isolate certain VPCs. Option C is wrong because VPC peering does not support transitive routing and cannot be used with overlapping CIDR blocks; additionally, Direct Connect Gateway alone does not provide the required VPC-to-VPC isolation and connectivity. Option D is wrong because configuring VPN connections between each VPC and on-premises bypasses the Transit Gateway, failing to centralize connectivity and making it impossible to manage isolation and routing efficiently across multiple VPCs.

175
MCQhard

A company uses AWS Direct Connect to connect its on-premises network to AWS. The SysOps team notices that traffic from the on-premises network to a VPC is not using the Direct Connect connection but instead is going over the internet. The VPC has a virtual private gateway attached and the on-premises router is advertising a specific route. What is the most likely cause?

A.The on-premises network does not have a route to the VPC CIDR.
B.The VPC route table has a more specific route (e.g., 0.0.0.0/0) pointing to an Internet Gateway.
C.The BGP session between the on-premises router and the Direct Connect router is down.
D.The virtual private gateway is not attached to the VPC.
AnswerC

If the BGP session is down, the on-premises router cannot exchange routes with the Direct Connect router, so it loses the Direct Connect path to the VPC and falls back to internet routing. This is the most likely cause.

Why this answer

The BGP session between the on-premises router and the Direct Connect router is down. When BGP is down, the on-premises router cannot exchange routes with the AWS side over Direct Connect. Even though the on-premises router may be advertising a specific route, without an active BGP session, that route is not received by the Direct Connect router, and the virtual private gateway does not propagate it into the VPC.

As a result, traffic from the on-premises network to the VPC falls back to using the internet route instead of Direct Connect. Option B is incorrect because the VPC route table controls outbound traffic from the VPC, not inbound traffic from on-premises; a default route to an Internet Gateway would cause asymmetric routing for return traffic but would not prevent inbound traffic from using Direct Connect if the BGP session is active.

Exam trap

The trap is that candidates often suspect VPC route misconfigurations or virtual private gateway attachment issues, but the core problem is a failed BGP session on the Direct Connect link, which stops route exchange between on-premises and AWS.

How to eliminate wrong answers

Option A is wrong because if the on-premises network lacked a route to the VPC CIDR, traffic would not reach the VPC at all, but the scenario states traffic is going over the internet, indicating a route exists but is misdirected. Option C is wrong because if the BGP session were down, the on-premises router would not advertise any routes, and the VPC would have no learned route to the on-premises network, causing traffic to fail or use the internet gateway as a default; however, the question states the on-premises router is advertising a specific route, implying BGP is up. Option D is wrong because if the virtual private gateway were not attached to the VPC, the VPC would have no connectivity to Direct Connect, and traffic would either fail or use the internet gateway, but the scenario specifically mentions a virtual private gateway is attached, making this option incorrect.

176
MCQeasy

A company has a VPC with public and private subnets. An Application Load Balancer (ALB) is in the public subnets, and Amazon EC2 instances are in the private subnets. The SysOps administrator needs to allow the EC2 instances to access an Amazon S3 bucket in the same AWS Region without traversing the internet. Which solution should the administrator implement?

A.A VPC Gateway Endpoint for S3
B.A NAT Gateway
C.An Internet Gateway
D.VPC Peering
AnswerA

A gateway endpoint attaches to the route table and provides private connectivity to S3 over the AWS network, so instances in private subnets reach the bucket without a NAT gateway, internet gateway or public addressing. This satisfies the no-internet-traversal constraint.

Why this answer

A VPC Gateway Endpoint for S3 allows EC2 instances in private subnets to access S3 buckets privately using AWS's internal network, without traversing the internet. This endpoint uses prefix lists and route table entries to direct S3 traffic through the AWS backbone, ensuring low latency and no data transfer costs.

Exam trap

The trap here is that candidates often choose a NAT Gateway or Internet Gateway because they think outbound traffic to AWS services must go through the internet, but Gateway Endpoints provide a private, cost-effective alternative for S3 and DynamoDB access within the same region.

How to eliminate wrong answers

Option B (NAT Gateway) is wrong because it routes traffic through the internet, which violates the requirement to avoid internet traversal and incurs data transfer costs. Option C (Internet Gateway) is wrong because it is used for public internet access and requires public IP addresses, not private S3 access. Option D (VPC Peering) is wrong because it connects VPCs but does not provide direct access to S3; S3 is a service outside the VPC, not a peered resource.

177
MCQhard

Refer to the exhibit. This bucket policy is attached to an S3 bucket that is used as an origin for a CloudFront distribution. Users are reporting Access Denied errors when accessing objects via the CloudFront URL. What is the MOST likely cause?

A.The condition is missing the aws:SourceVpce condition for VPC endpoints.
B.The bucket policy does not grant access to the CloudFront service principal.
C.The resource ARN is missing the bucket ARN for the bucket itself.
D.The condition restricts access to a specific IP range, but CloudFront requests come from its own IP addresses.
AnswerD

The bucket policy includes a condition that allows requests only from a specific IP address range. When CloudFront fetches the object from the S3 origin, the request originates from CloudFront's edge server IP addresses, not from the viewer's IP. These CloudFront addresses are not in the allowed range, so S3 denies the GET request. The correct fix is to either remove the IP restriction or replace it with an OAI/OAC and a condition that specifically identifies the CloudFront distribution.

Why this answer

The bucket policy condition restricts access to a specific IP range (likely the corporate CIDR), but CloudFront fetches objects from its own globally distributed edge IP addresses, not the end user's IP. CloudFront forwards the viewer's IP in the X-Forwarded-For header, but the actual TCP connection to S3 originates from CloudFront's IPs, so the IpAddress condition blocks all CloudFront requests, causing Access Denied.

Exam trap

SOA-C02 often tests whether candidates understand that CloudFront requests to S3 originate from CloudFront's IPs, not the viewer's — so IP-based bucket policy conditions break CloudFront origins.

How to eliminate wrong answers

Option A is wrong because aws:SourceVpce is only needed when restricting access to a VPC endpoint, not for CloudFront origins — CloudFront uses OAC, not VPC endpoints. Option B is wrong because CloudFront does not use a service principal in S3 bucket policies the way some other services do; access is granted via Origin Access Identity (OAI) or Origin Access Control (OAC), not a service principal. Option C is wrong because the resource ARN format shown (bucket ARN with /*) is correct for granting object access — the missing bucket ARN would only matter for bucket-level operations like ListBucket.

178
MCQeasy

A SysOps administrator needs to allow a Lambda function to access a DynamoDB table in the same AWS account. Which configuration is required?

A.Create a VPC endpoint for DynamoDB and attach it to the Lambda function.
B.Configure a network ACL to allow traffic from Lambda to DynamoDB.
C.Add the Lambda function as a principal in the DynamoDB table's resource-based policy.
D.Assign an IAM role to the Lambda function with DynamoDB permissions.
AnswerD

The correct and only supported mechanism is to attach an IAM execution role to the Lambda function. When the function runs, the Lambda service assumes this role using the service principal `lambda.amazonaws.com`, and the temporary credentials obtained from STS are used to sign all DynamoDB API requests. The role's managed or inline policies must explicitly allow the desired actions (e.g., `GetItem`, `PutItem`) on the target table, and DynamoDB evaluates these permissions for each request, making the role the sole source of access control.

Why this answer

Lambda functions assume an IAM role (the execution role) that grants permissions to AWS services. To allow a Lambda function to access a DynamoDB table in the same account, you attach an IAM policy to that execution role granting the necessary DynamoDB actions (e.g., GetItem, PutItem) on the table's ARN. This is the standard, required configuration for same-account access.

Exam trap

The trap is confusing network-level connectivity (VPC endpoints, NACLs) with authorization (IAM roles), leading candidates to pick a networking answer when the question is about granting service permissions.

How to eliminate wrong answers

Option A is wrong because a VPC endpoint for DynamoDB is only needed when the Lambda function runs inside a VPC and you want private connectivity to DynamoDB; it is not required for IAM-based access and does not grant permissions. Option B is wrong because network ACLs are stateless subnet-level firewalls that filter IP traffic; DynamoDB access is authorized via IAM, not network ACLs, and Lambda outside a VPC uses AWS-managed networking. Option C is wrong because DynamoDB resource-based policies are used for cross-account access or specific scenarios; for same-account Lambda access, the execution role's identity-based policy is the correct and sufficient mechanism.

179
MCQeasy

A company is using Amazon CloudFront to distribute content globally. The company wants to restrict access to content so that only users from specific countries can access it. Which CloudFront feature should be used?

A.AWS WAF
B.Signed URLs
C.Geo restriction
D.Origin Access Identity (OAI)
AnswerC

CloudFront geo restriction evaluates the viewer's country against an allowlist or blocklist at edge locations, denying requests before they reach the origin. This directly satisfies the requirement to limit content access to users from specific countries without modifying application code.

Why this answer

CloudFront's geo restriction feature (also known as geo-blocking) allows you to allow or block access to your content based on the geographic location of the viewer's IP address. This is the correct choice because the requirement is specifically to restrict access by country, which is exactly what geo restriction does by using a country-level allowlist or blocklist.

Exam trap

The trap here is that candidates often confuse geo restriction with AWS WAF's geo-match conditions, but the question explicitly asks for a CloudFront feature, and geo restriction is the native, simpler option that does not require WAF integration.

How to eliminate wrong answers

Option A is wrong because AWS WAF is a web application firewall that filters traffic based on rules like SQL injection or IP addresses, but it does not natively provide country-level access control without additional configuration (though it can be integrated with CloudFront for geo-matching via IP sets, the question asks for the CloudFront feature itself). Option B is wrong because Signed URLs provide temporary access to individual files by requiring a cryptographic signature, but they do not restrict access based on the viewer's geographic location. Option D is wrong because Origin Access Identity (OAI) is used to restrict access to an S3 origin so that only CloudFront can fetch content, but it does not control which end users can access the content based on their country.

180
MCQeasy

A company has multiple VPCs in the same AWS Region that need to communicate with each other. The SysOps administrator wants to avoid the complexity of a full mesh of VPC peering connections. Which AWS service should the administrator use to connect all VPCs with a central hub?

A.AWS Direct Connect
B.AWS Transit Gateway
C.VPC peering
D.AWS PrivateLink
AnswerB

AWS Transit Gateway functions as a regional hub-and-spoke router, to which you can attach VPCs, VPN connections, and Direct Connect gateways. It uses central route tables to enable transitive routing, so any attached VPC can communicate with any other without point-to-point connections. This model scales easily with thousands of VPCs and simplifies network management and security. It directly solves the requirement of multiple VPCs needing to communicate, making it the correct choice.

Why this answer

AWS Transit Gateway acts as a central hub that allows you to connect multiple VPCs and on-premises networks through a single gateway, eliminating the need for a full mesh of VPC peering connections. It uses a star topology where each VPC attaches to the Transit Gateway, and routing is managed via route tables, simplifying network management and scaling.

Exam trap

The trap here is that candidates often confuse VPC peering (which is point-to-point) with a hub-and-spoke solution, or mistakenly think AWS PrivateLink can route general traffic between VPCs, when it is actually designed for service-specific endpoints.

How to eliminate wrong answers

Option A is wrong because AWS Direct Connect is a dedicated network connection from on-premises to AWS, not a service for interconnecting multiple VPCs within the same Region. Option C is wrong because VPC peering creates a one-to-one connection between two VPCs, requiring a full mesh of N*(N-1)/2 connections for multiple VPCs, which adds complexity and does not provide a central hub. Option D is wrong because AWS PrivateLink enables private connectivity between VPCs and services (like endpoints), but it is designed for accessing specific services rather than routing traffic between multiple VPCs as a hub-and-spoke model.

181
MCQeasy

A company hosts a static website on Amazon EC2 instances behind an Application Load Balancer. They want to improve latency for users around the world by caching content at edge locations. Which AWS service should they use?

A.Amazon CloudFront
B.AWS Global Accelerator
C.AWS Direct Connect
D.Amazon Route 53
AnswerA

Amazon CloudFront is a content delivery network (CDN) that caches static assets, such as HTML, CSS, JavaScript, and images, at edge locations geographically close to users. When a user requests a file, CloudFront serves it from the cache if the TTL has not expired, drastically reducing latency and offloading repeated requests from the underlying EC2 instances. It can be configured with an Application Load Balancer or EC2 as the origin and automatically handles SSL termination, HTTP/2, and compression, making it the ideal choice for static website acceleration.

Why this answer

Amazon CloudFront is a content delivery network (CDN) that caches static content (e.g., HTML, CSS, images) at edge locations worldwide, reducing latency for global users by serving cached responses from the nearest edge rather than the origin EC2 instances behind the Application Load Balancer. It integrates directly with ALB as a custom origin, offloading traffic and improving response times for repeated requests.

Exam trap

The trap here is confusing AWS Global Accelerator (which optimizes network path but does not cache) with CloudFront (which caches at edge), leading candidates to pick Global Accelerator for latency improvement without recognizing the requirement for content caching.

How to eliminate wrong answers

Option B (AWS Global Accelerator) is wrong because it improves latency by directing traffic over the AWS global network using Anycast IPs, but it does not cache content at edge locations—it only optimizes routing to the origin. Option C (AWS Direct Connect) is wrong because it establishes a dedicated private network connection from on-premises to AWS, which does not cache content or serve edge locations; it is used for hybrid connectivity, not global content delivery. Option D (Amazon Route 53) is wrong because it is a DNS service that resolves domain names to IP addresses and can route users to the nearest endpoint via latency-based routing, but it does not cache or store content at edge locations.

182
MCQeasy

A company has a VPC with a CIDR block of 10.0.0.0/16. They have two subnets: a public subnet (10.0.1.0/24) and a private subnet (10.0.2.0/24). An EC2 instance in the private subnet needs to access an S3 bucket to store logs. The instance currently has no internet access. The SysOps administrator has created a VPC endpoint for S3 (gateway type) and attached it to the VPC. The instance still cannot reach S3. What additional step is required?

A.Attach an Internet Gateway to the VPC and add a route to it
B.Add a security group rule to allow outbound HTTPS traffic to S3
C.Modify the endpoint policy to allow all S3 actions
D.Add a route in the private subnet's route table pointing to the S3 endpoint
AnswerD

For a gateway VPC endpoint to work, the subnet's route table must include a route with the S3 prefix list (e.g., com.amazonaws.region.s3) targeting the endpoint ID. Without this route, S3-bound traffic from private instances follows the default route and fails if there's no internet path. Adding this route directs traffic through the endpoint over AWS's private network.

Why this answer

After creating a gateway VPC endpoint for S3, you must add a route in the subnet's route table that points S3 traffic (using the prefix list pl-xxxxxxxx for S3) to the endpoint. Without this route, the private subnet has no path to the endpoint, so the instance cannot reach S3. The gateway endpoint is not automatically added to route tables; it must be explicitly associated.

Exam trap

SOA-C02 often tests the extra step required after creating a gateway endpoint, tempting candidates to focus on security groups or endpoint policies when the missing piece is the route table entry.

How to eliminate wrong answers

Option A is wrong because attaching an Internet Gateway and adding a route would give the instance internet access, which defeats the purpose of using a gateway endpoint and is unnecessary for private S3 access. Option B is wrong because security groups are stateful and outbound HTTPS is allowed by default; moreover, gateway endpoints for S3 do not use security groups — they use endpoint policies and route table entries. Option C is wrong because modifying the endpoint policy to allow all S3 actions addresses authorization, not connectivity; the default endpoint policy already allows full access, and the instance still cannot reach S3 without a route.

183
Multi-Selectmedium

A company is designing a VPC with public and private subnets. The private subnets need internet access for patching, but must not be directly reachable from the internet. Which TWO components should be used together?

Select 2 answers
A.VPC Peering connection
B.Private subnet route table with a route to the Internet Gateway
C.Internet Gateway attached to the VPC
D.Private subnet route table with a route to the NAT Gateway
E.NAT Gateway in a public subnet
AnswersD, E

The private subnet's route table must direct 0.0.0.0/0 traffic to the NAT Gateway, keeping instances unaddressable from the internet while enabling outbound patching. Without this route, private instances have no path to the NAT Gateway, so the no-inbound-reachability constraint fails.

Why this answer

Option E is correct because a NAT Gateway must be deployed in a public subnet (with an Elastic IP) so it can route traffic out through the Internet Gateway on behalf of private instances. Option D is correct because the private subnet's route table must have a route (typically 0.0.0.0/0) pointing to that NAT Gateway, which allows instances in the private subnet to initiate outbound traffic for patching while remaining unreachable from the internet. Together, the NAT Gateway in the public subnet and the private route table entry provide one-way outbound internet access.

Option A is incorrect because VPC Peering connects two VPCs and does not provide internet access. Option B is incorrect because routing a private subnet directly to an Internet Gateway would make it a public subnet and expose it to inbound internet traffic. Option C is incorrect because an Internet Gateway alone, attached to the VPC, does not give private subnets outbound access without a NAT device and the corresponding route.

Exam trap

The trap is assuming that attaching an Internet Gateway to the VPC automatically gives private subnets internet access — candidates must remember that private subnets require a NAT Gateway (in a public subnet) plus a route to it, and that the IGW alone is insufficient.

184
MCQmedium

A company has a web application deployed in a VPC with both public and private subnets. The web servers are in public subnets and the database servers are in private subnets. The web servers need to access the internet for updates. Which configuration is required to provide internet access to the web servers while keeping the database servers private?

A.Place both web and database servers in private subnets and use a NAT Gateway for outbound internet access.
B.Attach an Internet Gateway to the VPC and add a route to it in the route tables for both public and private subnets.
C.Attach an Internet Gateway to the VPC and add a route to it only in the route tables for the public subnets.
D.Use a VPC Gateway Endpoint to provide internet access to the web servers.
AnswerC

This is the standard and correct VPC design for a web application: the Internet Gateway is attached to the VPC and a 0.0.0.0/0 route pointing to it is placed only in the route tables of public subnets hosting the web servers. This allows the web servers to receive inbound user traffic and respond over the internet, while the database servers in private subnets have no route to the IGW, keeping them inaccessible from the internet. The VPC's routing architecture ensures proper traffic flow and security.

Why this answer

An Internet Gateway (IGW) is required for any subnet that needs direct internet access. By attaching an IGW to the VPC and adding a default route (0.0.0.0/0) pointing to the IGW only in the public subnet route tables, web servers in those subnets can reach the internet. Database servers in private subnets remain isolated because their route tables lack the IGW route, preventing direct inbound or outbound internet traffic.

Exam trap

The trap here is that candidates often confuse the role of an Internet Gateway with a NAT Gateway, assuming that adding an IGW route to all subnets is necessary for outbound access, but this would break the isolation of private subnets by allowing direct inbound traffic.

How to eliminate wrong answers

Option A is wrong because placing both web and database servers in private subnets would require a NAT Gateway for outbound internet access, but the question specifies web servers are already in public subnets and need direct internet access, not NAT-mediated access. Option B is wrong because adding a route to the Internet Gateway in private subnet route tables would expose database servers to the internet, violating the requirement to keep them private. Option D is wrong because a VPC Gateway Endpoint provides private connectivity to AWS services (e.g., S3, DynamoDB) via the AWS network, not general internet access for web servers.

185
MCQhard

A SysOps administrator is setting up Amazon Route 53 for a domain that will be used for a web application. The application requires failover to a backup data center in another region if the primary becomes unhealthy. The administrator creates a failover routing policy with two records (primary and secondary) associated with health checks. After testing, the failover does not occur when the primary endpoint fails. What is the most likely cause?

A.The primary record is not an alias record
B.The domain registrar's nameservers are not pointing to Route 53
C.The health check is configured to monitor the secondary endpoint instead of the primary
D.The TTL on the primary record is set too high
AnswerC

In Route 53 failover routing, the primary record must be associated with a health check that monitors the primary endpoint. If the health check instead monitors the secondary endpoint, it will remain healthy even when the primary goes down, so Route 53 will never see the failure and will continue returning the primary record in responses. This configuration directly prevents failover from triggering, making it the correct explanation for why the secondary resource is never used.

Why this answer

Failover routing relies on health checks to determine the health of the primary endpoint. If the health check is mistakenly configured to monitor the secondary endpoint, it will not assess the primary's health. Consequently, Route 53 will not trigger a failover to the secondary when the primary fails.

Option A is incorrect because alias records are not required for failover; they are only needed for AWS resources. Option B is incorrect because the registrar's nameservers do not affect Route 53's failover logic once the domain is delegated. Option D is incorrect because while a high TTL can delay propagation, it does not prevent failover from occurring; failover depends on health check status, not TTL.

186
MCQmedium

A SysOps Administrator is setting up a VPC peering connection between two VPCs (VPC-A and VPC-B) in different AWS accounts. After the peering connection is accepted, instances in VPC-A cannot ping instances in VPC-B. Both VPCs have non-overlapping CIDR blocks. What is the MOST likely cause?

A.The route tables in both VPCs do not have routes to the peer VPC CIDR.
B.VPC peering does not support cross-account connections.
C.The CIDR blocks overlap, causing routing conflicts.
D.The security groups in VPC-B do not allow inbound ICMP traffic from VPC-A.
AnswerA

For a VPC peering connection to function, each VPC must have an explicit route in its route table that targets the peering connection (pcx-*) and points to the peer VPC's CIDR block. Even if the peering connection is in the 'active' state, traffic will be dropped at the source VPC if no such route exists, because the source instance has no path to the destination CIDR. Both route tables must be updated for bidirectional communication; a missing route on either side breaks connectivity for traffic originating in that direction, and ICMP ping is a common test that will fail immediately without these routes.

Why this answer

The most likely cause is that the route tables in both VPCs do not have routes to the peer VPC CIDR. Even after a VPC peering connection is accepted, traffic cannot flow between the VPCs unless explicit routes are added to each VPC's route table pointing to the CIDR block of the peer VPC, with the VPC peering connection as the target. Without these routes, instances in VPC-A have no path to reach instances in VPC-B, so ping fails.

Exam trap

The trap here is that candidates often assume security groups or NACLs are the primary cause of connectivity issues, but the foundational routing layer must be correctly configured first for any traffic to flow across a VPC peering connection.

How to eliminate wrong answers

Option B is wrong because VPC peering does support cross-account connections; you simply need to accept the peering request from the other account. Option C is wrong because the question explicitly states that the CIDR blocks are non-overlapping, so routing conflicts from overlap are not the issue. Option D is wrong because while security group rules could block ICMP, the most likely cause is the missing route tables, as routing is a prerequisite for any traffic to reach the destination before security groups are evaluated.

187
MCQeasy

A company has two VPCs in the same AWS region. VPC A hosts a web application, and VPC B hosts a database. The SysOps administrator needs to enable private IP communication between the two VPCs without using the public internet. The administrator wants a simple, low-cost solution that uses the AWS network backbone. Which AWS service should be used?

A.VPC Peering
B.AWS Transit Gateway
C.AWS Direct Connect
D.AWS Site-to-Site VPN
AnswerA

VPC Peering establishes a direct, logical connection between exactly two VPCs, using a 1:1 relationship that relies on AWS's existing routing infrastructure—no gateways, virtual appliances, or dedicated physical lines are required. Traffic between the peered VPCs uses private IPv4 or IPv6 addresses and stays entirely on the AWS global network, avoiding public-internet exposure and providing low, predictable latency. It is cost-effective for a pair of VPCs because there is no hourly fee or minimum revenue commitment; you pay only for inter-VPC data transfer, which is usually significantly cheaper than traffic traversing the internet. Although VPC peering is non-transitive, that property is irrelevant for a two-VPC architecture, making it the simplest and most operationally efficient solution for this requirement.

Why this answer

VPC Peering allows direct, private IP connectivity between two VPCs using the AWS network backbone without traversing the public internet. It is the simplest and most cost-effective solution for connecting exactly two VPCs in the same region, as there are no additional hourly charges beyond data transfer costs, and no intermediate devices or bandwidth limitations are introduced.

Exam trap

The trap here is that candidates may choose AWS Transit Gateway because it is a powerful networking hub, but the question explicitly asks for a simple, low-cost solution for only two VPCs, making VPC Peering the correct choice despite Transit Gateway's broader capabilities.

How to eliminate wrong answers

Option B (AWS Transit Gateway) is wrong because it is designed for hub-and-spoke connectivity across many VPCs and incurs an hourly attachment fee, making it unnecessarily complex and more expensive for a simple two-VPC connection. Option C (AWS Direct Connect) is wrong because it is a dedicated physical connection from an on-premises data center to AWS, not a service for connecting two VPCs within the same region, and it involves significant setup costs and lead times. Option D (AWS Site-to-Site VPN) is wrong because it establishes encrypted tunnels over the public internet between on-premises networks and AWS, not between two VPCs, and it introduces additional latency and complexity compared to VPC Peering.

188
MCQeasy

A SysOps Administrator needs to allow an EC2 instance in a private subnet to access the internet for software updates. Which AWS service should be used?

A.VPN Connection
B.NAT Gateway
C.Internet Gateway
D.VPC Peering
AnswerB

A NAT Gateway is a managed service that enables instances in a private subnet to initiate outbound IPv4 traffic to the internet while blocking unsolicited inbound connections. It performs source network address translation (SNAT), replacing the instance's private IP with the NAT Gateway's Elastic IP before forwarding traffic to an Internet Gateway. This is the correct architecture because the private subnet's route table points 0.0.0.0/0 to the NAT Gateway, and the NAT Gateway resides in a public subnet to reach the internet.

Why this answer

A NAT Gateway enables EC2 instances in a private subnet to initiate outbound traffic to the internet (e.g., for software updates) while preventing unsolicited inbound connections from the internet. It translates the private IP of the instance to the NAT Gateway's Elastic IP using Source Network Address Translation (SNAT). This is the correct service because the instance is in a private subnet and requires internet access without being directly reachable.

Exam trap

The trap here is that candidates often confuse an Internet Gateway with a NAT Gateway, not realizing that an Internet Gateway requires the instance to have a public IP and be in a public subnet, whereas a NAT Gateway is specifically designed for private subnets to access the internet outbound only.

How to eliminate wrong answers

Option A is wrong because a VPN Connection establishes a secure tunnel between an on-premises network and AWS, not for providing internet access to instances in a private subnet. Option C is wrong because an Internet Gateway is attached to a VPC and allows inbound/outbound internet access, but it requires the instance to have a public IP and be in a public subnet; it cannot be used directly from a private subnet. Option D is wrong because VPC Peering connects two VPCs privately using AWS's internal network, and it does not provide internet access; it also does not support transitive routing or a default route to the internet.

189
Multi-Selectmedium

A SysOps administrator needs to design a VPC with public and private subnets for a web application. Which TWO components are required to allow instances in the private subnet to access the internet?

Select 2 answers
A.NAT gateway in a public subnet
B.Route table entry in the private subnet routing 0.0.0.0/0 to the NAT gateway
C.VPC endpoint for S3
D.Internet gateway attached to the VPC
E.Virtual private gateway
AnswersA, B

A NAT gateway is a managed Network Address Translation service that enables instances in a private subnet to initiate outbound IPv4 traffic to the internet and receive replies, while preventing unsolicited inbound connections from the internet. It must be placed in a public subnet with a route to an Internet Gateway and an associated Elastic IP, so it can translate private-source IPs to the public IP. This is the core component that gives private instances internet access in a VPC design with public and private subnets.

Why this answer

A NAT gateway in a public subnet is required because it allows instances in a private subnet to initiate outbound traffic to the internet (e.g., for software updates) while preventing unsolicited inbound connections. The NAT gateway must be placed in a public subnet with an Internet Gateway (IGW) route to translate private IPs to the gateway's Elastic IP. Without the NAT gateway, private instances have no path to the internet.

Exam trap

The trap here is that candidates often think an Internet Gateway alone is sufficient for private subnet internet access, but they overlook the need for a NAT device to translate private IPs, as the IGW only works with public IPs.

190
MCQeasy

A SysOps administrator needs to allow an EC2 instance in a private subnet to download patches from the internet. Which AWS service should be used to achieve this securely?

A.Internet Gateway (IGW)
B.NAT Gateway
C.AWS VPN
D.VPC Peering
AnswerB

A NAT Gateway is a fully managed AWS service that enables instances in a private subnet to initiate outbound connections to the internet (for example, to download patches or access external APIs) while preventing unsolicited inbound connections from the internet. It is deployed in a public subnet with an Elastic IP address, and the private subnet's route table points a default route (0.0.0.0/0) to the NAT Gateway. The NAT Gateway translates the private source IP of outbound traffic to its Elastic IP and uses connection tracking to drop inbound packets that are not part of an established outbound flow. This makes it the correct choice for providing outbound-only internet access to a private EC2 instance.

Why this answer

A NAT Gateway is a managed AWS service deployed in a public subnet that allows instances in private subnets to initiate outbound connections to the internet (such as downloading patches) while preventing inbound connections from the internet. It provides the secure, one-way egress path the scenario requires.

Exam trap

The trap is confusing inbound vs. outbound connectivity — candidates pick IGW because they think 'internet access' means IGW, but IGWs are for public subnets and inbound reachability, while NAT is for private-subnet egress.

How to eliminate wrong answers

Option A is wrong because an Internet Gateway provides bidirectional internet connectivity and requires the subnet to have a route to it plus a public IP — placing an instance in a private subnet with an IGW route would defeat the purpose of the private subnet and expose it to inbound traffic. Option C is wrong because AWS VPN connects on-premises networks to a VPC; it does not provide internet egress for private-subnet instances. Option D is wrong because VPC Peering connects two VPCs privately and does not provide any path to the public internet.

191
MCQhard

A SysOps administrator is troubleshooting connectivity issues between Amazon EC2 instances in two different VPCs that are connected via a VPC peering connection. The instances can successfully send ICMP (ping) traffic, but TCP connections on port 443 (HTTPS) fail. The security groups of both instances allow all inbound and outbound traffic. What is the most likely cause of the issue?

A.The Network ACL associated with the subnets is blocking the return traffic for TCP connections on ephemeral ports
B.The VPC peering connection is not properly configured for TCP traffic
C.The route tables in the VPCs do not contain a route for the other VPC's CIDR
D.The security group on the EC2 instance is blocking inbound TCP traffic on port 443
AnswerA

Network ACLs are stateless, so they require explicit rules for traffic in both directions. While ICMP may be permitted by the inbound/outbound rules, TCP return traffic (such as the acknowledgment and response packets) arrives on ephemeral ports (typically 1024–65535). If the outbound NACL rule does not explicitly allow these high ports, the TCP handshake or established connections will fail even though ping works. This is the classic symptom of a NACL blocking return traffic.

Why this answer

The Network ACL (NACL) is stateless, meaning it must explicitly allow both inbound and outbound traffic. While ICMP (ping) works because it doesn't rely on ephemeral ports for return traffic, TCP connections on port 443 require the return traffic to come from the target instance on a high ephemeral port (typically 1024-65535). If the NACL's outbound rules block these ephemeral ports, the TCP handshake fails, even though the security groups allow all traffic.

Exam trap

The trap here is that candidates assume security groups are the only firewall layer, overlooking that Network ACLs are stateless and require explicit rules for ephemeral port return traffic, which is why ICMP works but TCP fails.

How to eliminate wrong answers

Option B is wrong because VPC peering connections are transparent to protocols; they operate at Layer 3 and do not differentiate between ICMP and TCP traffic. Option C is wrong because if the route tables lacked a route for the other VPC's CIDR, ICMP (ping) would also fail, as routing is required for all traffic types. Option D is wrong because the question explicitly states that the security groups allow all inbound and outbound traffic, so they cannot be blocking TCP port 443.

192
Multi-Selectmedium

A SysOps administrator is troubleshooting DNS resolution issues for a custom domain used by an Application Load Balancer. Which TWO steps should the administrator take to diagnose the issue? (Choose two.)

Select 2 answers
A.Ensure the VPC's CIDR block does not overlap with the ALB's IP range
B.Verify that the Route 53 alias record points to the ALB's DNS name
C.Run 'dig' or 'nslookup' from a client to verify the domain resolves to the correct IP
D.Verify that the ALB's security group allows inbound traffic on port 443
E.Check the health status of the ALB's target group
AnswersB, C

The Route 53 alias record must reference the ALB's canonical DNS name (e.g., myapp-1234567890.us-east-1.elb.amazonaws.com) rather than a static IP address, because ALB IPs are ephemeral and can change during scale operations. If the alias target is misspelled, points to a deleted resource, or uses a non-alias type with an IP, Route 53 returns no valid answer or a stale address. Verifying this alias configuration directly corrects the misconfiguration that causes resolution failures.

Why this answer

A Route 53 alias record must point to the ALB's DNS name (e.g., my-alb-1234567890.us-east-1.elb.amazonaws.com) to properly route traffic to the load balancer. If the alias record is misconfigured or points to an incorrect resource, DNS resolution will fail or resolve to an unintended IP, causing the custom domain not to work.

Exam trap

The trap here is that candidates confuse DNS resolution issues with network connectivity or load balancer health, leading them to select security group or target group checks instead of focusing on the DNS configuration itself.

193
Multi-Selecthard

Which THREE of the following are valid options for connecting a VPC to an on-premises network? (Select THREE.)

Select 3 answers
A.Transit gateway with VPN attachment
B.AWS Direct Connect
C.VPC peering
D.AWS Site-to-Site VPN
E.VPC endpoint
AnswersA, B, D

An AWS Transit Gateway acts as a network transit hub, and adding a Site-to-Site VPN attachment lets an on-premises network connect to the gateway over an IPsec tunnel using the public internet. This is a valid hybrid connectivity option because the transit gateway can route traffic between many VPCs and the VPN attachment, simplifying the network while still supporting site-to-site VPN connectivity.

Why this answer

A Transit Gateway with a VPN attachment allows you to connect your VPC to an on-premises network by acting as a central hub that interconnects VPCs and on-premises networks via IPsec VPN tunnels. This is a valid option because the Transit Gateway can terminate multiple VPN connections, enabling hybrid connectivity with centralized routing and scalability.

Exam trap

The trap here is that candidates confuse VPC peering (which only connects VPCs) with hybrid connectivity options, or mistakenly think VPC endpoints can extend to on-premises networks, when they are strictly for accessing AWS services privately within a VPC.

← PreviousPage 3 of 3 · 193 questions total

Ready to test yourself?

Try a timed practice session using only Networking and Content Delivery questions.