Courseiva

CCNA Soa Networking Cdn Questions

75 of 193 questions · Page 1/3 · Soa Networking Cdn topic · Answers revealed

1
MCQhard

A SysOps administrator is troubleshooting connectivity issues between an Amazon EC2 instance in a VPC and an on-premises data center connected via AWS Direct Connect. The EC2 instance can reach other instances in the same VPC but cannot reach the on-premises network. The virtual private gateway (VGW) is attached to the VPC and the Direct Connect virtual interface is up. Which configuration step should the administrator verify first?

A.Check the security group rules for the EC2 instance
B.Confirm that the Direct Connect virtual interface is associated with the correct VLAN
C.Add a route in the VPC route table for the on-premises CIDR pointing to the virtual private gateway
D.Verify the network ACL inbound and outbound rules for the VPC subnet
AnswerC

The VPC route table must contain a route for the on-premises CIDR targeting the virtual private gateway; without it, traffic to on-premises has no path despite the Direct Connect virtual interface being up. This is the most common cause of this symptom.

Why this answer

For an EC2 instance to reach an on-premises network via Direct Connect, the VPC route table must contain a route for the on-premises CIDR block pointing to the virtual private gateway (VGW). Since the instance can reach other VPC instances, local routing works; the missing piece is the route to the on-premises destination. Without this route, traffic has no path to the VGW and is dropped.

Exam trap

SOA-C02 often tests whether candidates jump to security groups or NACLs (familiar troubleshooting steps) instead of first verifying routing—the most common cause of hybrid connectivity failures is a missing route, not a security rule.

How to eliminate wrong answers

Option A is wrong because security group rules control instance-level traffic; if they blocked traffic, the instance likely couldn't reach other VPC instances either, and the symptom is specifically on-premises reachability. Option B is wrong because the question states the Direct Connect virtual interface is up, implying VLAN association is correct; verifying it is not the first step when the VIF is already operational. Option D is wrong because network ACLs are stateless subnet-level filters; while they could block traffic, the more fundamental issue is the absence of a route, and NACLs would typically affect all traffic, not just on-premises.

2
Multi-Selectmedium

A company is using Amazon CloudFront to deliver content from an S3 bucket. The SysOps administrator wants to restrict access so that only CloudFront can access the S3 bucket. Which TWO steps should be taken?

Select 2 answers
A.Generate presigned URLs for all objects in the S3 bucket.
B.Configure the S3 bucket policy to grant the OAI s3:GetObject permission.
C.Configure CloudFront signed URLs to limit viewer access.
D.Create an Origin Access Identity (OAI) for the CloudFront distribution.
E.Set the S3 bucket policy to allow access only from the CloudFront distribution ID.
AnswersB, D

Configuring the S3 bucket policy to grant the OAI s3:GetObject permission is the critical step that makes the origin access control effective. The policy explicitly identifies the OAI as the only principal allowed to read objects, which permits CloudFront to fetch content on behalf of viewers while denying all direct S3 access requests. This is the recommended pattern because it combines the OAI identity with the necessary authorization, ensuring that the S3 bucket remains private and only CloudFront can serve content.

Why this answer

To restrict access so that only CloudFront can access the S3 bucket, the correct steps are to create an Origin Access Identity (OAI) for the CloudFront distribution (option D) and then configure the S3 bucket policy to grant the OAI s3:GetObject permission (option B). This ensures that only the CloudFront distribution with that OAI can read objects from the bucket, while all other principals are denied access. Option A is incorrect because presigned URLs grant temporary access to individual users, not to CloudFront.

Option C is incorrect because signed URLs control viewer access, not origin access. Option E is incorrect because bucket policies reference the OAI, not the distribution ID.

3
Multi-Selectmedium

A SysOps administrator is designing a VPC with public and private subnets. The private subnets need to access the internet for software updates. Which THREE components are required to achieve this?

Select 3 answers
A.A VPC Gateway Endpoint
B.An Internet Gateway attached to the VPC
C.A NAT Gateway in a public subnet
D.A Site-to-Site VPN connection
E.A route table in the private subnet with a default route to the NAT Gateway
AnswersB, C, E

An Internet Gateway (IGW) is the linchpin of public internet access in a VPC; it is a horizontally scaled, redundant, and highly available target for the 0.0.0.0/0 default route placed in public subnet route tables. It performs NAT for instances that have public IP addresses, enabling bidirectional traffic with the internet, and it is also required for a NAT Gateway in a public subnet to receive and send traffic. Because it connects the VPC directly to the internet, it is essential for any design where private subnets need egress.

Why this answer

Option B is correct because an Internet Gateway must be attached to the VPC to provide the public subnet (and the NAT Gateway within it) with a path to the internet; without an IGW, no traffic can reach external destinations. Option C is correct because a NAT Gateway deployed in a public subnet performs source NAT, allowing instances in private subnets to initiate outbound internet traffic while remaining unreachable from the internet. Option E is correct because the private subnet's route table must contain a default route (0.0.0.0/0) targeting the NAT Gateway so that outbound traffic from private instances is forwarded to it.

Option A is incorrect because a VPC Gateway Endpoint only provides private access to specific AWS services such as S3 or DynamoDB, not general internet access. Option D is incorrect because a Site-to-Site VPN connects the VPC to an on-premises network, not to the public internet for software updates.

Exam trap

The trap is assuming a VPC Gateway Endpoint or a VPN can provide general internet access; candidates often forget that a NAT Gateway alone is insufficient without the Internet Gateway and the correct route table entry.

4
MCQeasy

A SysOps administrator needs to create a VPC with both public and private subnets. The public subnet will host a NAT gateway and a bastion host. The private subnet will host application servers that need outbound internet access for updates. Which routing configuration should the administrator implement?

A.Public subnet route table: 0.0.0.0/0 -> Internet Gateway; Private subnet route table: 0.0.0.0/0 -> Internet Gateway via the NAT Gateway.
B.Public subnet route table: 0.0.0.0/0 -> Internet Gateway; Private subnet route table: 0.0.0.0/0 -> Internet Gateway.
C.Public subnet route table: 0.0.0.0/0 -> NAT Gateway; Private subnet route table: 0.0.0.0/0 -> Internet Gateway.
D.Public subnet route table: 0.0.0.0/0 -> Internet Gateway; Private subnet route table: 0.0.0.0/0 -> NAT Gateway.
AnswerD

This is the correct setup for a VPC with public and private subnets. The public subnet route table sends all outbound traffic (0.0.0.0/0) to the internet gateway, allowing resources like a bastion host or NAT gateway to reach the internet directly. The private subnet route table sends all outbound traffic to the NAT gateway, which resides in the public subnet and performs source network address translation (SNAT) to forward traffic to the internet while keeping instances in the private subnet unreachable from the internet. This preserves the security of private instances while still enabling them to download updates or access external services.

Why this answer

The public subnet needs a route to the Internet Gateway so the NAT gateway and bastion host are reachable from the internet. The private subnet needs a route to the NAT gateway (which itself lives in the public subnet) so application servers can initiate outbound internet traffic without being directly reachable inbound.

Exam trap

SOA-C02 often tests whether candidates correctly place the NAT gateway in the public subnet and point the private subnet's default route at the NAT gateway — distractors swap the IGW and NAT gateway targets to catch memorized-but-unverified answers.

How to eliminate wrong answers

Option A is wrong because it describes routing the private subnet to the Internet Gateway 'via the NAT Gateway' — a NAT gateway is not a path to an IGW; the private route target must be the NAT gateway's ENI, not the IGW. Option B is wrong because routing the private subnet directly to the Internet Gateway makes it a public subnet, defeating the purpose and exposing the app servers. Option C is wrong because it reverses the roles: a NAT gateway cannot serve as the public subnet's default route (it has no inbound path from the internet), and the private subnet pointed at the IGW would again be public.

5
MCQeasy

A SysOps administrator is troubleshooting an issue where an EC2 instance cannot be accessed via SSH from the internet. The security group allows inbound SSH (port 22) from 0.0.0.0/0. The network ACL (NACL) for the subnet has an inbound rule allowing SSH from 0.0.0.0/0. What else could be blocking access?

A.The NACL inbound rule is blocking traffic.
B.The internet gateway is not attached to the VPC.
C.The security group rule is misconfigured.
D.The NACL outbound rule is blocking return traffic.
AnswerD

NACLs are stateless, so the outbound rule is evaluated independently of the inbound rule. Even if the inbound NACL rule allows SSH (port 22) from the client, the instance's response traffic goes to a random ephemeral port (typically 1024–65535) on the client. If the outbound NACL rule does not allow these ephemeral ports, the return packets are dropped, causing the SSH connection to hang or time out. This is the classic cause of asymmetric traffic failures when using stateless filtering.

Why this answer

Network ACLs are stateless, meaning they evaluate inbound and outbound traffic separately. Even if the inbound rule allows SSH, the outbound rule must also allow the return traffic (ephemeral ports) for the SSH session to work. If the NACL outbound rule is blocking return traffic, the SSH connection will fail.

Exam trap

The trap is forgetting that NACLs are stateless; candidates often focus only on inbound rules and overlook the need for outbound rules to allow return traffic, especially for ephemeral ports.

How to eliminate wrong answers

Option A is wrong because the NACL inbound rule already allows SSH from 0.0.0.0/0, so it is not blocking inbound traffic. Option B is wrong because if the internet gateway were not attached, the instance would have no public IP and would not be reachable at all, but the question implies the instance is reachable via SSH (the security group allows it), so the IGW is likely attached. Option C is wrong because the security group rule is correctly configured to allow SSH from 0.0.0.0/0.

6
MCQhard

A company uses Amazon CloudFront to serve content from an S3 bucket. The bucket is configured as an origin with Origin Access Control (OAC). Users report that they can access the content via CloudFront but also directly via the S3 bucket URL. How can the company restrict direct access to the S3 bucket?

A.Disable OAC and use Origin Access Identity (OAI) instead.
B.Use pre-signed URLs for all S3 requests.
C.Remove the bucket policy and rely on ACLs.
D.Update the S3 bucket policy to deny access to any principal other than the CloudFront service.
AnswerD

This is correct because the S3 bucket policy can include an explicit deny statement that applies to any principal other than the CloudFront service, effectively closing the direct access path. By using a condition such as `aws:SourceArn` or `aws:SourceAccount`, the policy can allow only CloudFront while denying all other IAM users, roles, and anonymous requests. This approach is the recommended companion to OAC because it ensures that the bucket is not publicly accessible, and any attempt to access the object via the S3 website or REST endpoint is rejected before returning content.

Why this answer

With Origin Access Control (OAC), CloudFront signs requests to S3, and the S3 bucket policy must be updated to allow only the CloudFront distribution (via the cloudfront.amazonaws.com service principal with a condition on the distribution ARN) and deny all other principals. This blocks direct access via the S3 URL while preserving CloudFront access.

Exam trap

SOA-C02 often tests whether candidates know that enabling OAC alone is insufficient — the S3 bucket policy must also be updated to deny direct access, and candidates frequently pick 'switch to OAI' thinking it is a security fix rather than a legacy alternative.

How to eliminate wrong answers

Option A is wrong because OAI is the legacy mechanism; switching to OAI does not by itself block direct access unless the bucket policy is also updated, and OAC is the recommended modern approach. Option B is wrong because pre-signed URLs grant temporary access to specific objects and do not restrict direct bucket access — they are a different access pattern entirely. Option C is wrong because removing the bucket policy and relying on ACLs would not restrict direct access and would weaken security; ACLs are also deprecated for most use cases.

7
MCQhard

Refer to the exhibit. A security group is attached to an Application Load Balancer (ALB) that serves HTTPS traffic on port 443. Users can access the application via HTTPS. However, the ALB's health checks to targets on port 80 are failing. What is the reason?

A.The ALB's security group does not allow HTTPS traffic from the internet.
B.The security group for the target instances does not allow HTTP traffic from the ALB's security group.
C.The ALB's security group does not allow HTTP traffic from the target's IP range.
D.The health check is configured to use HTTPS, but the target only supports HTTP.
AnswerB

This is correct because the ALB sends health check requests from its own network interfaces, using the ALB's security group as the source in the allowed inbound rule on each target. The target instance's security group must explicitly allow inbound TCP on the health check port (HTTP/80) from the ALB's security group ID (or from the VPC CIDR if the security group reference is not used). Without that rule, the OS receives the SYN packet but the security group silently drops it, so the health check times out and the target is marked unhealthy. This is the standard root cause for healthy-app-turned-unhealthy after an ALB change or when targets are in a different security group.

Why this answer

ALB health checks originate from the ALB's nodes and are sent to the target's health-check port (here port 80/HTTP). For the check to succeed, the target instance's security group must allow inbound HTTP from the ALB's security group. Since users can reach the app over HTTPS on 443, the ALB listener and its security group are fine — the failure is on the target-side SG not permitting the health-check traffic.

Exam trap

SOA-C02 often tests the misconception that the ALB's own security group controls health-check success — in reality, the target's security group must allow the health-check port from the ALB.

How to eliminate wrong answers

Option A is wrong because users are already accessing the app via HTTPS, proving the ALB's security group allows inbound 443 from the internet. Option C is wrong because the ALB's security group governs inbound traffic to the ALB, not outbound health-check traffic to targets — and referencing the target's IP range is the wrong direction. Option D is wrong because the scenario states health checks fail on port 80, implying the check is HTTP; the target supports HTTP, so protocol mismatch is not the issue.

8
Multi-Selecteasy

Which TWO AWS services can be used to improve the security of a VPC? (Choose TWO.)

Select 2 answers
A.Security Groups
B.Internet Gateway
C.Route Tables
D.Network ACLs
E.VPC Peering
AnswersA, D

Security Groups are stateful virtual firewalls that operate at the ENI/instance level within a VPC. They evaluate all inbound and outbound traffic against a set of allow rules only—there is no explicit deny rule—and return traffic is automatically permitted regardless of the outbound rule configuration. For example, if you allow inbound HTTP from 0.0.0.0/0, the corresponding outbound response traffic is implicitly allowed, which simplifies security but requires careful rule design to avoid overly permissive configurations.

Why this answer

Security Groups (A) act as a virtual firewall for instances, controlling inbound and outbound traffic at the instance level based on allow rules only. Network ACLs (D) provide a stateless firewall layer at the subnet level, supporting both allow and deny rules, and are evaluated in numeric order. Together, they offer defense-in-depth for VPC traffic filtering.

Exam trap

The trap here is that candidates confuse routing components (Internet Gateway, Route Tables, VPC Peering) with security components, assuming any VPC construct that controls traffic flow also provides security filtering.

9
Multi-Selecteasy

Which TWO are valid methods to secure traffic between a client and an Application Load Balancer?

Select 2 answers
A.Configure a listener on port 443 with an SSL certificate from AWS Certificate Manager.
B.Use a security group that only allows HTTPS traffic from the client's IP.
C.Set up an IPsec VPN connection between the client and the ALB.
D.Configure a network ACL to allow only port 443.
E.Enable the ALB's built-in SSL/TLS encryption without a certificate.
AnswersA, B

An Application Load Balancer (ALB) can terminate TLS by configuring an HTTPS listener on port 443. You must associate a valid SSL/TLS certificate, such as one issued by AWS Certificate Manager (ACM), which the ALB uses to decrypt incoming traffic and establish encrypted sessions with clients. This ensures data in transit is protected against eavesdropping and tampering. ACM integrates natively with ALB, handling certificate renewal automatically.

Why this answer

Configuring a listener on port 443 with an SSL certificate from ACM enables TLS encryption between the client and the ALB. Option B is also correct: using a security group that only allows HTTPS traffic enforces that all traffic must be encrypted, securing the communication by blocking unencrypted HTTP traffic. Options C, D, and E are incorrect: IPsec VPN is not terminated on an ALB (C), network ACLs do not provide encryption (D), and SSL/TLS encryption requires a valid certificate (E).

Exam trap

The trap is that candidates often think only option A (SSL termination) secures traffic, but using a security group to allow only HTTPS (option B) also ensures encryption by blocking unencrypted traffic.

10
MCQeasy

A company has an Amazon CloudFront distribution with an S3 bucket as origin. The bucket contains sensitive data. Which configuration ensures that users access the content only through CloudFront and not directly via the S3 URL?

A.Enable S3 server-side encryption
B.Configure an Origin Access Identity (OAI) in CloudFront and update the bucket policy
C.Use CloudFront signed URLs or signed cookies
D.Enable S3 Block Public Access on the bucket
AnswerB

An Origin Access Identity is a special CloudFront principal that S3 recognizes; after creating it, you attach it to your distribution and rewrite the bucket policy to grant s3:GetObject only to that OAI's canonical user ID. This makes the bucket private to everyone except CloudFront, so users cannot bypass CloudFront by hitting the S3 endpoint directly. Combined with the distribution's behavior, it is the standard way to force all traffic through CloudFront for a private S3 origin.

Why this answer

An Origin Access Identity (OAI) is a special CloudFront user that the distribution uses to fetch objects from the S3 bucket. By updating the bucket policy to grant read access only to that OAI and removing public access, direct requests to the S3 URL are denied while CloudFront can still serve the content. This is the standard AWS pattern for locking an S3 origin behind CloudFront.

Exam trap

The trap is assuming that signed URLs or Block Public Access alone secure the origin — candidates forget that without an OAI/OAC and a restrictive bucket policy, the S3 URL remains directly reachable.

How to eliminate wrong answers

Option A is wrong because SSE encrypts objects at rest but does not prevent users from accessing the object via the S3 URL if the bucket policy allows it. Option C is wrong because signed URLs/cookies control who can access content through CloudFront, but they do not stop someone from bypassing CloudFront and hitting the S3 endpoint directly. Option D is wrong because Block Public Access prevents public access but does not by itself grant CloudFront the necessary permissions — without an OAI and bucket policy, CloudFront would also be denied.

11
MCQmedium

A company has deployed a web application behind an Application Load Balancer (ALB) across multiple Availability Zones. Users in some regions report slow page load times. Which action should the SysOps Administrator take to improve performance for all users?

A.Use AWS Global Accelerator to route traffic over the AWS global network.
B.Increase the ALB capacity by adding more target instances.
C.Enable Amazon CloudFront to cache dynamic content.
D.Move the application to a single Availability Zone to reduce network hops.
AnswerA

AWS Global Accelerator assigns two static anycast IP addresses at AWS edge locations and directs traffic onto the AWS global backbone, bypassing congested public internet segments. This reduces the number of intermediate hops and round-trip latency for users worldwide, while also providing automatic failover across healthy ALB endpoints. It is specifically designed for TCP/UDP workloads where each request requires low and stable latency, unlike caching services that only speed up repeated content.

Why this answer

AWS Global Accelerator improves performance by directing traffic over the AWS global network and using edge locations close to users, reducing latency for all users. Option A is correct because it optimizes the path from users to the application. Option B is incorrect because increasing ALB capacity only helps with handling more requests, not latency for geographically distant users.

Option C is incorrect because CloudFront is primarily for caching static content, and the application serves dynamic content that may not be cacheable. Option D is incorrect because moving to a single Availability Zone reduces fault tolerance and does not address latency for users far from that zone.

12
MCQhard

A company has a VPC with a public subnet and a private subnet. An Amazon EC2 instance in the private subnet needs to download security patches from the internet, but the instance must not be directly accessible from the internet. The SysOps administrator configured a NAT gateway in the public subnet and added a route in the private subnet's route table pointing 0.0.0.0/0 to the NAT gateway. The instance's security group allows all outbound traffic. However, the instance still cannot reach the internet. What is the most likely missing configuration?

A.Attach an Elastic IP to the NAT gateway
B.Enable DNS resolution in the VPC
C.Add a route in the public subnet's route table that directs 0.0.0.0/0 traffic to an internet gateway
D.Modify the network ACL of the private subnet to allow inbound ephemeral ports from the NAT gateway's private IP
AnswerC

A NAT gateway must be launched in a public subnet, and that subnet's route table needs a destination of 0.0.0.0/0 pointing to an internet gateway, not to another gateway or target. Without this route, the NAT gateway's network interface cannot send translated packets to the IGW or receive return packets, so all traffic from private instances times out. Adding this route is the correct fix because it establishes the final hop between the NAT gateway and the internet.

Why this answer

The NAT gateway is in the public subnet, but for it to route traffic to the internet, the public subnet must have a route table entry that directs 0.0.0.0/0 traffic to an internet gateway (IGW). Without this route, the NAT gateway cannot forward outbound traffic to the IGW, so the private instance's traffic is dropped. Option C correctly identifies this missing route.

Exam trap

The trap here is that candidates assume configuring the private subnet's route table to point to the NAT gateway is sufficient, forgetting that the NAT gateway itself needs a route to the internet via an internet gateway in its own subnet.

How to eliminate wrong answers

Option A is wrong because a NAT gateway automatically gets an Elastic IP assigned at creation; if it were missing, the NAT gateway would fail to provision, not silently fail to route traffic. Option B is wrong because DNS resolution controls the ability to resolve domain names to IP addresses, not the underlying network path for outbound traffic; the instance can still fail to reach the internet even with DNS working. Option D is wrong because the network ACL of the private subnet must allow outbound ephemeral ports for return traffic, not inbound; the default NACL already allows all inbound/outbound traffic, and the issue is the missing route in the public subnet, not NACL rules.

13
MCQmedium

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). The application experiences intermittent 502 errors. The SysOps administrator checks the ALB access logs and sees that the error occurs when the target group has 'unhealthy' targets. What is the MOST likely cause of the 502 errors?

A.The SSL certificate on the ALB is expired.
B.The ALB does not have enough capacity to handle the traffic.
C.The client request exceeds the idle timeout.
D.The target instances are not passing health checks.
AnswerD

If the target instances are failing health checks, the ALB will eventually stop routing traffic to them, but while they are in a transitional state or if health checks are misconfigured, the ALB may still attempt to send requests to a non-responsive instance. When the ALB cannot establish a connection or receives no valid response from the target, it returns 502 Bad Gateway. This is one of the most common causes of 502 errors in ALB deployments, especially when targets intermittently fail health checks.

Why this answer

A 502 Bad Gateway error from an ALB occurs when the load balancer cannot successfully forward a request to a healthy target. If the target group has unhealthy targets, the ALB may have no healthy targets to route to, resulting in 502 errors. The most likely cause is that the target instances are failing health checks, so the ALB marks them as unhealthy and cannot serve requests.

Exam trap

The trap here is that candidates may attribute 502 errors to network or capacity issues, but the key clue is 'unhealthy targets' in the logs, pointing directly to health check failures.

How to eliminate wrong answers

Option A is wrong because an expired SSL certificate on the ALB would cause SSL/TLS handshake failures, typically resulting in 503 or certificate errors, not 502. Option B is wrong because ALB capacity is managed by AWS and scales automatically; insufficient capacity is not a typical cause of 502 errors. Option C is wrong because if the client request exceeds the idle timeout, the ALB may close the connection, but this usually results in a 504 Gateway Timeout, not a 502.

14
MCQmedium

An application running on EC2 instances sends large amounts of data to an S3 bucket. The SysOps administrator wants to reduce data transfer costs while ensuring the traffic stays within AWS. What is the most cost-effective solution?

A.Set up an AWS Direct Connect connection.
B.Use S3 Transfer Acceleration.
C.Create a VPC Endpoint for S3 (Gateway type) and use it from the EC2 instances.
D.Route traffic through a NAT Gateway in a public subnet.
AnswerC

A Gateway VPC Endpoint for S3 allows EC2 instances in a private subnet to reach S3 without an internet gateway, NAT device, or public IP address. It is free of charge, has no data processing fees, and works by adding a service prefix list to the route table, which keeps S3 traffic on AWS's private network. This makes it the most direct and cost-effective solution for large data transfers from EC2.

Why this answer

A VPC Endpoint for S3 (Gateway type) allows EC2 instances to access S3 over the AWS private network without traversing the public internet, eliminating data transfer costs for traffic within the same region. Since the traffic stays within AWS, this is the most cost-effective solution as it avoids NAT Gateway, Direct Connect, or S3 Transfer Acceleration charges.

Exam trap

The trap here is that candidates often confuse Gateway VPC Endpoints with Interface Endpoints or assume that S3 Transfer Acceleration is cheaper for large data volumes, when in fact Gateway Endpoints are free and provide the most cost-effective private connectivity within a region.

How to eliminate wrong answers

Option A is wrong because AWS Direct Connect is a dedicated network connection from on-premises to AWS, which incurs monthly port fees and data transfer costs, and is not designed for traffic between EC2 and S3 within the same region. Option B is wrong because S3 Transfer Acceleration uses AWS edge locations and charges per GB transferred, increasing costs for large data transfers, and it still routes traffic over the public internet. Option D is wrong because routing traffic through a NAT Gateway in a public subnet incurs per-GB data processing charges and does not provide private connectivity to S3, as NAT Gateways are used for outbound internet access, not for optimized S3 access.

15
MCQmedium

A company has a VPC with multiple subnets. An EC2 instance in a public subnet needs to communicate with an RDS database in a private subnet. The RDS security group allows inbound traffic from the EC2 instance's security group. However, the EC2 instance cannot connect. What is the most likely cause?

A.The VPC does not have DNS resolution enabled, so the RDS endpoint cannot be resolved.
B.The network ACL for the private subnet blocks inbound traffic from the public subnet.
C.The security group of the RDS database does not allow outbound traffic.
D.The EC2 instance does not have a public IP address.
AnswerA

Amazon RDS exposes its database via a fully qualified domain name, such as `dbname.xxxxx.rds.amazonaws.com`, which the EC2 instance must resolve to an IP address. In a VPC, DNS resolution is governed by the `enableDnsSupport` attribute; if this is set to false, the VPC's Route 53 Resolver does not answer DNS queries. Without DNS resolution, the RDS endpoint cannot be translated into a private IP, so the connection attempt fails at the name resolution stage. This is the direct cause of the connectivity failure described.

Why this answer

The RDS database is in a private subnet and its endpoint is a DNS name. If DNS resolution is disabled on the VPC, the EC2 instance cannot resolve the RDS endpoint's hostname to an IP address, preventing the TCP connection from being established even though security group rules are correctly configured.

Exam trap

The trap here is that candidates focus on security group or NACL misconfigurations, overlooking that DNS resolution is a prerequisite for connecting to any service using a DNS endpoint, especially when the database is in a private subnet without a direct route to a public resolver.

How to eliminate wrong answers

Option B is wrong because network ACLs are stateless and, by default, allow all inbound and outbound traffic unless explicitly modified; the question does not indicate any custom NACL rules blocking traffic. Option C is wrong because security groups are stateful — if inbound traffic from the EC2 instance is allowed, the RDS database automatically allows outbound return traffic, so no explicit outbound rule is needed. Option D is wrong because the EC2 instance is in a public subnet and can have a public IP or use a NAT gateway to initiate outbound connections; the issue is DNS resolution, not the instance's public IP address.

16
MCQmedium

A company is using Amazon CloudFront to distribute content globally. The origin is an S3 bucket. The SysOps administrator notices that cache hit ratio is low. Which configuration change would MOST improve the cache hit ratio?

A.Use query string parameters to differentiate content.
B.Configure custom error responses for 404 errors.
C.Set longer Cache-Control max-age headers on the S3 objects.
D.Enable Origin Shield for the distribution.
AnswerC

Setting a longer Cache-Control: max-age header on the S3 objects tells CloudFront how many seconds the object remains fresh in the edge cache. With a longer cache duration, an object is more likely to still be present and valid when subsequent requests arrive, so more requests are served directly from the edge without a round trip to the origin. This directly increases the CloudFront cache hit ratio, making it the optimal choice.

Why this answer

Cache hit ratio measures how often CloudFront serves content from edge caches instead of forwarding requests to the origin. The Cache-Control max-age header (and its s-maxage/Expires equivalents) directly controls how long CloudFront keeps an object in cache before revalidating with S3. Extending max-age on the S3 objects means each cached copy satisfies more subsequent requests, which raises the hit ratio without changing request patterns.

Exam trap

SOA-C02 often tests the misconception that adding more cache-key dimensions (query strings, headers, cookies) improves caching, when in fact every added dimension splits the cache and reduces the hit ratio.

How to eliminate wrong answers

Option A is wrong because adding query string parameters to the cache key fragments the cache — each unique query string creates a separate cached variant, which lowers the hit ratio rather than improving it. Option B is wrong because custom error responses only change what CloudFront returns to the viewer on a 4xx/5xx; they do not affect whether an object is served from cache. Option D is wrong because Origin Shield adds an additional caching layer between edge locations and the origin, reducing origin load and latency, but it does not increase the proportion of viewer requests served from cache — the TTL still governs that.

17
MCQhard

A company is using Amazon CloudFront to serve static content from an S3 bucket. They want to restrict access so that only CloudFront can access the S3 bucket. How should this be configured?

A.Configure Origin Access Control (OAC) with the S3 bucket policy.
B.Use CloudFront signed URLs or cookies.
C.Attach an IAM role to CloudFront that grants S3 read access.
D.Create a bucket policy that allows access only from the CloudFront distribution's IP addresses.
AnswerA

Origin Access Control (OAC) is the modern, recommended way to restrict an S3 bucket to serve content only through CloudFront. OAC uses a service principal of cloudfront.amazonaws.com with a condition that requires the distribution's ID to match, and the bucket policy grants only GetObject to that principal. This blocks direct S3 access from outside CloudFront while also supporting encrypted S3 objects and SSE-KMS, giving verifiable origin security.

Why this answer

Origin Access Control (OAC) is the recommended method to restrict access to an S3 bucket so that only CloudFront can retrieve objects. When OAC is enabled, CloudFront signs requests to S3 using a specific principal, and the S3 bucket policy is configured to allow access only to that principal. This prevents direct access to the bucket via S3 URLs or other AWS services, ensuring that content is served exclusively through CloudFront.

Exam trap

The trap here is that candidates often confuse viewer-side access control (signed URLs) with origin-side access control (OAC/OAI), or mistakenly think that CloudFront can use IAM roles or static IP addresses to authenticate to S3.

How to eliminate wrong answers

Option B is wrong because signed URLs or cookies control access to CloudFront content at the viewer level, not between CloudFront and the S3 origin; they do not restrict the S3 bucket from being accessed directly. Option C is wrong because CloudFront does not support attaching an IAM role directly to the distribution; IAM roles are used for AWS services like EC2 or Lambda, not for CloudFront-to-S3 authentication. Option D is wrong because CloudFront does not have a fixed set of IP addresses that can be used in a bucket policy; its IP addresses are dynamic and shared across distributions, making this approach unreliable and insecure.

18
Multi-Selecteasy

Which TWO of the following are features of Amazon Route 53? (Select TWO.)

Select 2 answers
A.SSL/TLS termination
B.Health checking of resources
C.SSL certificate management
D.Domain name registration
E.Content caching at edge locations
AnswersB, D

Route 53 supports health checking of endpoints by actively sending periodic TCP, HTTP, or HTTPS requests to configured IPs or domains to verify availability. These health checks integrate with failover routing policies, allowing Route 53 to automatically remove unhealthy resources from DNS responses and direct traffic to healthy ones. This is a core feature that extends beyond basic name resolution.

Why this answer

Amazon Route 53 is a DNS web service that provides domain name resolution, domain registration, and health checking of resources. Health checking monitors the availability and performance of endpoints (e.g., web servers) via HTTP/HTTPS/TCP requests, and can automatically failover DNS responses to healthy resources, ensuring high availability.

Exam trap

The trap here is that candidates confuse Route 53's DNS-level health checking with application-layer features like SSL termination or caching, leading them to select options that belong to other AWS services like CloudFront or ALB.

19
MCQhard

A company has a web application behind an Application Load Balancer (ALB) with sticky sessions enabled. The ALB's target group contains EC2 instances in an Auto Scaling group. After a deployment, users report that they are being logged out frequently. What is the most likely cause?

A.The deregistration delay is set too low.
B.The ALB's stickiness cookie is not configured or is being overwritten.
C.Health checks are too frequent and marking instances unhealthy.
D.Cross-zone load balancing is disabled.
AnswerB

Sticky sessions on an Application Load Balancer rely on the AWSALB cookie being issued and honored by the client. If the stickiness policy is not enabled on the target group, or the application overwrites or strips the Set-Cookie header, the ALB receives no cookie and treats each request as a new session, routing it to any available target. This directly causes the observed behavior of users losing their session.

Why this answer

Sticky sessions (session affinity) rely on a cookie generated by the ALB (AWSALB) to route subsequent requests from a user to the same target. If the cookie is not configured or is overwritten (e.g., by the application after deployment), the ALB treats each request as new and may route to different instances, causing the user to be logged out. Option A is incorrect because deregistration delay controls how long the ALB waits before deregistering an instance, which does not affect existing sessions unless instances are being removed.

Option C is incorrect because while frequent health checks may cause instances to be marked unhealthy, this would result in connection errors or routing to other instances, but it does not explain logouts due to sticky session loss. Option D is incorrect because cross-zone load balancing distributes traffic across zones but does not affect session stickiness.

20
Multi-Selecthard

Which THREE AWS services can be used to improve security and performance for a web application that uses an Application Load Balancer? (Select three.)

Select 3 answers
A.AWS Shield Advanced
B.AWS WAF
C.Amazon Route 53
D.Amazon CloudFront
E.AWS Direct Connect
AnswersA, B, D

AWS Shield Advanced provides always-on network and transport layer DDoS protection with automatic inline mitigations. It offers enhanced detection for sophisticated attacks, access to the AWS DDoS Response Team (DRT), and cost protection against scaling charges. It integrates with CloudFront, Application Load Balancer, and Elastic Load Balancing to monitor traffic patterns and mitigate large-scale volumetric attacks.

Why this answer

AWS Shield Advanced provides enhanced protection against Distributed Denial of Service (DDoS) attacks, including application-layer attacks targeting the Application Load Balancer (ALB). It integrates directly with ALB to offer always-on detection and automatic mitigation, improving security without requiring changes to the application architecture.

Exam trap

The trap here is that candidates often confuse Amazon Route 53's DNS routing features (like latency-based routing or geolocation) with performance improvement for the application itself, but Route 53 does not cache content or accelerate traffic; it only resolves DNS queries, which is a separate concern from web application performance.

21
MCQhard

Instances in a private subnet need outbound internet access for software updates. The route table sends 0.0.0.0/0 to a NAT gateway, but updates fail. Which condition should you check first?

A.Confirm the NAT gateway is in a public subnet whose route table has 0.0.0.0/0 to an internet gateway.
B.Attach an internet gateway directly to the private subnet instances.
C.Replace all security groups with network ACLs.
D.Enable VPC peering to another account.
AnswerA

A NAT gateway only provides outbound internet access when placed in a public subnet whose route table points 0.0.0.0/0 to an internet gateway. If it sits in a private subnet, traffic never reaches the internet, so updates fail.

Why this answer

A NAT gateway must reside in a public subnet with a route table entry directing 0.0.0.0/0 to an internet gateway (IGW). Without this, the NAT gateway cannot translate private IPs to the IGW's public IP, so outbound traffic from private instances fails. This is the most common root cause for failed internet access through a NAT gateway.

Exam trap

The trap here is that candidates assume any subnet with a NAT gateway automatically has internet access, overlooking the requirement that the NAT gateway itself must be in a public subnet with a default route to an internet gateway.

How to eliminate wrong answers

Option B is wrong because attaching an internet gateway directly to a private subnet is not supported; an IGW can only be attached to a VPC and associated with public subnets, and private subnet instances lack public IPs to use it directly. Option C is wrong because replacing security groups with network ACLs does not solve the routing issue; NACLs are stateless and can filter traffic, but they do not provide internet connectivity. Option D is wrong because VPC peering does not provide internet access; it only enables private connectivity between VPCs, and does not route traffic to the internet.

22
Multi-Selectmedium

Which TWO actions should a SysOps administrator take to improve the availability and reduce latency for a web application hosted on EC2 instances behind an Application Load Balancer?

Select 2 answers
A.Use larger EC2 instance types to handle more traffic.
B.Configure the ALB health check to have a shorter interval.
C.Use an Amazon CloudFront distribution in front of the ALB to cache content at edge locations.
D.Implement Auto Scaling to add instances based on CPU utilization.
E.Deploy EC2 instances in multiple Availability Zones.
AnswersD, E

Implementing Auto Scaling with a CPU utilization-based policy enables the fleet to add instances during demand spikes and remove them when load drops, which distributes the request load across more targets and reduces response time. This horizontal elasticity directly addresses latency and performance constraints by expanding capacity in an automated and predictable way. Combined with multi-AZ deployment, it also provides a self-healing, resilient architecture, but its primary benefit here is maintaining performance under changing load.

Why this answer

Auto Scaling based on CPU utilization dynamically adjusts the number of EC2 instances to match demand, improving availability by ensuring sufficient capacity during traffic spikes and reducing latency by distributing load across more instances. Option E is correct because deploying EC2 instances in multiple Availability Zones (AZs) provides fault tolerance: if one AZ fails, the ALB continues routing traffic to healthy instances in other AZs, which also reduces latency by serving users from the closest AZ.

Exam trap

The trap here is that candidates often confuse vertical scaling (larger instances) with horizontal scaling (more instances across AZs), or they mistakenly think that reducing health check intervals always improves availability, when in fact it can cause flapping and reduce stability.

23
MCQhard

A company has two VPCs in different AWS regions (us-east-1 and eu-west-1) that are peered. Applications in both VPCs need to communicate using private IP addresses. The ping tests are successful, but the latency is significantly higher than expected. Which change is most likely to improve the latency between the VPCs?

A.Enable DNS resolution for the VPC peering connection.
B.Use a Transit Gateway instead of VPC Peering for cross-region connectivity.
C.Increase the MTU on the instances' network interfaces to 9001.
D.Configure ECMP (Equal-Cost Multi-Path) routing on the VPC peering connection.
AnswerA

When a VPC peering connection has DNS resolution enabled in both VPCs, instances can resolve private DNS hostnames of the peer VPC through the Amazon-provided DNS resolver, which returns private IP addresses instead of public ones. This keeps all cross-VPC traffic on the AWS backbone, avoiding the extra latency of routing over the public internet. Without this setting, private DNS names may fail to resolve or map to public endpoints, forcing traffic outside the VPC and adding avoidable round-trip delay.

Why this answer

Enabling DNS resolution for the VPC peering connection allows instances to resolve public DNS hostnames to the private IP addresses of the peered VPC. Without this, DNS queries may return public IP addresses, forcing traffic to traverse the internet or NAT gateways, which adds significant latency. By resolving to private IPs, traffic stays within the AWS backbone, reducing latency.

Exam trap

The trap here is that candidates often assume latency is caused by network path or bandwidth issues (leading them to choose Transit Gateway or MTU changes), but the real culprit is DNS resolution misconfiguration forcing traffic over the public internet instead of the private AWS backbone.

How to eliminate wrong answers

Option B is wrong because using a Transit Gateway instead of VPC Peering for cross-region connectivity does not inherently reduce latency; both use the AWS global backbone, and latency is primarily affected by physical distance and routing, not the service type. Option C is wrong because increasing the MTU to 9001 (jumbo frames) improves throughput for large packets but does not reduce latency; in fact, jumbo frames can increase serialization delay for small packets and are not supported over VPC peering connections (MTU is limited to 1500). Option D is wrong because ECMP routing is not configurable on VPC peering connections; VPC peering does not support multiple paths or load balancing, and ECMP is a feature of Transit Gateway or Direct Connect, not VPC peering.

24
MCQmedium

A company has two Amazon VPCs (VPC-A and VPC-B) in the same AWS Region with non-overlapping CIDR blocks. The SysOps administrator needs to establish private IP connectivity between the two VPCs with high throughput and minimal cost. Which solution should the administrator implement?

A.VPC Peering
B.AWS Transit Gateway
C.AWS VPN CloudHub
D.AWS Direct Connect
AnswerA

VPC peering allows private connectivity between two VPCs using AWS's private network. It is simple to set up, has no bandwidth limitations, and incurs no hourly cost. It is the most cost-effective solution for connecting two VPCs in the same region.

Why this answer

VPC Peering is the correct solution because it allows direct private IP connectivity between two VPCs in the same AWS Region using the AWS global network backbone, with no bandwidth bottlenecks, no single point of failure, and no additional cost beyond data transfer charges. Since the VPCs have non-overlapping CIDR blocks, they can be peered without route conflicts, and traffic flows entirely within AWS without traversing the public internet or requiring a transit hub.

Exam trap

The trap here is that candidates often over-engineer the solution by choosing AWS Transit Gateway for its centralized routing features, forgetting that for a simple two-VPC peering scenario with non-overlapping CIDRs, VPC Peering is the most cost-effective and high-performance option without the overhead of a transit hub.

How to eliminate wrong answers

Option B (AWS Transit Gateway) is wrong because it introduces unnecessary complexity and cost (hourly per-attachment charges and data processing fees) for a simple two-VPC scenario where VPC Peering provides the same high throughput at lower cost. Option C (AWS VPN CloudHub) is wrong because it requires VPN connections over the public internet, which adds latency, reduces throughput, and incurs hourly VPN connection charges, making it less performant and more expensive than VPC Peering. Option D (AWS Direct Connect) is wrong because it is designed for hybrid connectivity between on-premises networks and AWS, not for VPC-to-VPC communication, and involves significant setup costs, long lead times, and monthly port fees that are unnecessary for this use case.

25
MCQmedium

A company has a VPC with an IPv4 CIDR block of 10.0.0.0/16. They need to add an IPv6 CIDR block to the VPC and ensure that EC2 instances can communicate over IPv6. Which step is necessary?

A.Attach an internet gateway that supports IPv6.
B.Create a new VPC with an IPv6 CIDR block and migrate resources.
C.Associate an Amazon-provided IPv6 CIDR block with the VPC.
D.Enable DNS64 in the VPC.
AnswerC

Associating an Amazon-provided IPv6 CIDR block with the VPC is the correct first step to enable IPv6. The VPC's IPv4 CIDR remains unchanged, and AWS automatically assigns a /56 IPv6 CIDR from Amazon's global unicast address pool. After this association, you must also assign /64 IPv6 CIDRs to subnets, attach an internet gateway, update route tables, and add IPv6 rules to security groups and NACLs to complete native IPv6 support.

Why this answer

To enable IPv6 communication in an existing VPC, you must first associate an Amazon-provided IPv6 CIDR block with the VPC. This is a prerequisite for configuring subnets, route tables, and internet gateways to support IPv6 traffic. Without an IPv6 CIDR block assigned to the VPC, no EC2 instance can obtain an IPv6 address or route IPv6 traffic.

Exam trap

The trap here is that candidates often think attaching an IPv6-capable internet gateway is the first step, but the VPC must first have an IPv6 CIDR block assigned before any IPv6 routing or addressing can occur.

How to eliminate wrong answers

Option A is wrong because attaching an internet gateway that supports IPv6 is necessary only after an IPv6 CIDR block has been associated with the VPC; the gateway itself does not add IPv6 addressing to the VPC. Option B is wrong because you do not need to create a new VPC; you can add an IPv6 CIDR block to an existing VPC without migrating resources. Option D is wrong because DNS64 is used to translate IPv6 DNS queries to IPv4 addresses for NAT64 scenarios, not to add an IPv6 CIDR block or enable native IPv6 communication.

26
MCQmedium

A SysOps administrator manages a web application hosted on EC2 instances behind an Application Load Balancer. The application uses sticky sessions (session affinity) based on cookies. Recently, the development team deployed a new version that increases the load time for certain pages. Users report that they are randomly seeing other users' data. The administrator suspects that the sticky session configuration is not working correctly. The ALB target group is configured with stickiness enabled using the AWSALB cookie. What should the administrator do to verify that sticky sessions are being honored?

A.Increase the stickiness duration to 7 days and test again
B.Check the ALB access logs for the presence of the stickiness cookie
C.Use a browser's developer tools to inspect the cookies on the client side and verify the AWSALB cookie is being set and includes the correct target group identifier
D.Check the target group health check settings to ensure all instances are healthy
AnswerC

Using a browser's developer tools directly exposes the client-side cookie jar, allowing you to confirm the presence of the AWSALB or AWSALBCORS cookie and its value, which encodes the target group identifier. You can also inspect the Network tab to see the Set-Cookie header on the initial response and verify that subsequent requests include the same cookie value. This provides definitive, real-time evidence that sticky sessions are functioning, because the cookie is the mechanism that the ALB uses to pin a session to a specific target.

Why this answer

To verify sticky sessions, inspect browser developer tools to confirm the AWSALB cookie is set and remains unchanged across requests. The cookie value is opaque and cannot be decoded to reveal the target group identifier. ALB access logs can also be used to correlate the cookie with the target IP, and the presence of the cookie in access logs does prove the client sent it.

27
MCQeasy

A company has an application that requires UDP traffic to be distributed across multiple EC2 instances. Which AWS load balancer type should be used?

A.Network Load Balancer
B.Classic Load Balancer
C.Amazon CloudFront
D.Application Load Balancer
AnswerA

Network Load Balancer (NLB) operates at Layer 4 of the OSI model and explicitly supports UDP traffic, along with TCP and TLS. It is designed to handle millions of requests per second with ultra-low latency, making it the only Elastic Load Balancer variant capable of routing connectionless UDP packets, such as DNS or NTP queries, to backend targets. For UDP workloads, NLB preserves the client source IP and can be allocated a static Elastic IP, which is often required for firewall allow-listing in front of your application.

Why this answer

A Network Load Balancer (NLB) operates at Layer 4 and can handle both TCP and UDP traffic, making it the correct choice for distributing UDP traffic across multiple EC2 instances. Unlike other load balancers, NLB preserves the source IP address and can forward UDP packets without inspecting application-layer headers, which is essential for UDP-based applications such as DNS, VoIP, or gaming servers.

Exam trap

The trap here is that candidates may confuse the Application Load Balancer's support for WebSockets (which start as HTTP) with UDP support, or assume the Classic Load Balancer can handle any Layer 4 protocol, but AWS specifically removed UDP support from CLB and ALB, reserving it for NLB.

How to eliminate wrong answers

Option B (Classic Load Balancer) is wrong because it does not support UDP traffic; it only supports HTTP, HTTPS, TCP, and SSL. Option C (Amazon CloudFront) is wrong because it is a content delivery network (CDN) that works over HTTP/HTTPS and does not support UDP traffic distribution. Option D (Application Load Balancer) is wrong because it operates at Layer 7 and only supports HTTP, HTTPS, and WebSocket protocols, not UDP.

28
MCQmedium

A company uses Amazon CloudFront to deliver static content from an S3 bucket. The SysOps administrator wants to restrict access so that only CloudFront can access the S3 bucket. Which solution should be used?

A.Use pre-signed URLs for all objects.
B.Use an S3 bucket policy that allows access from any AWS service.
C.Generate CloudFront key pairs and configure signed URLs.
D.Configure an origin access control (OAC) and update the S3 bucket policy to allow CloudFront access.
AnswerD

Configuring an origin access control (OAC) attaches a CloudFront distribution to an S3 bucket using a service principal (cloudfront.amazonaws.com) and an aws:SourceArn condition that uniquely identifies the distribution. The bucket policy then explicitly grants that principal s3:GetObject permission, ensuring only your CloudFront distribution (and not the public or arbitrary AWS services) can read the objects. OAC also supports SSE-KMS encrypted origins, making it the current best practice over the legacy origin access identity (OAI).

Why this answer

Origin Access Control (OAC) is the recommended method to restrict S3 bucket access exclusively to CloudFront. OAC uses a CloudFront-owned service principal to sign requests, and the S3 bucket policy must explicitly grant the `s3:GetObject` action to that principal, ensuring no direct S3 access from other sources.

Exam trap

The trap here is confusing origin security (restricting S3 bucket access to CloudFront) with viewer security (restricting who can view content via signed URLs or cookies), leading candidates to incorrectly choose signed URLs or key pairs.

How to eliminate wrong answers

Option A is wrong because pre-signed URLs grant temporary access to specific objects but do not restrict the bucket to CloudFront; they are used for individual object access, not for origin access control. Option B is wrong because allowing access from any AWS service would permit any AWS service or principal to access the bucket, violating the requirement to restrict access solely to CloudFront. Option C is wrong because CloudFront key pairs and signed URLs are used to restrict viewer access to content, not to secure the origin; they control who can view content, not which origin can fetch from S3.

29
MCQhard

A web application on EC2 instances behind an ALB experiences increased latency during peak hours. The SysOps administrator notices that the ALB's RequestCount per target is high. What design change should improve performance?

A.Switch to a Network Load Balancer.
B.Add more EC2 instances to the target group.
C.Enable sticky sessions on the ALB.
D.Reduce the idle timeout on the ALB.
AnswerB

Adding more EC2 instances to the target group horizontally scales the application and directly reduces the number of concurrent requests each instance must handle. Since the ALB already distributes traffic at the request level, an increase in target count lets the same request rate be spread across more processing capacity, lowering queue wait times and therefore end-to-end latency. This is the standard approach when per-instance CPU utilization is high or when the request queue delay is proportional to the load per target. It is the correct choice among the options.

Why this answer

Increasing the number of targets (EC2 instances) spreads the load and reduces latency.

30
MCQmedium

A company has a VPC with public and private subnets across two Availability Zones. An application running on EC2 instances in the private subnets needs to access the internet for updates. Which configuration should be used to provide internet access while minimizing administrative overhead?

A.Assign public IP addresses to the private instances and update route tables accordingly.
B.Set up AWS Direct Connect to an internet gateway.
C.Deploy a NAT Gateway in a public subnet and update private route tables to point to it.
D.Launch a NAT instance in the private subnet and configure routing.
AnswerC

A NAT gateway is a highly available, fully managed AWS service that allows instances in a private subnet to initiate outbound traffic to the internet while blocking unsolicited inbound connections. It must be placed in a public subnet with a route to an internet gateway, and the private subnet's route table should direct 0.0.0.0/0 traffic to the NAT gateway's network interface. This design is the standard for providing internet access to private resources securely, with no need to patch or manage the gateway yourself.

Why this answer

A NAT Gateway, deployed in a public subnet with an Elastic IP, allows instances in private subnets to initiate outbound traffic to the internet (e.g., for updates) while preventing inbound traffic from the internet. This is a fully managed AWS service, so it requires no patching or scaling management, minimizing administrative overhead. The private subnet's route table must have a default route (0.0.0.0/0) pointing to the NAT Gateway's network interface.

Exam trap

The trap here is that candidates confuse a NAT Gateway with a NAT instance, assuming both require similar administrative effort, or they mistakenly think assigning public IPs to private instances is sufficient for outbound-only internet access.

How to eliminate wrong answers

Option A is wrong because assigning public IP addresses to instances in private subnets would not automatically provide internet access; you would also need an Internet Gateway in the VPC and a route from the private subnet to it, which would expose the instances to inbound traffic, violating the private subnet's purpose. Option B is wrong because AWS Direct Connect is a dedicated private network connection from on-premises to AWS, not a service for providing internet access to VPC resources; it does not replace an Internet Gateway or NAT Gateway for outbound internet traffic. Option D is wrong because a NAT instance is a self-managed EC2 instance that requires manual configuration, patching, and scaling, which increases administrative overhead compared to the managed NAT Gateway.

31
MCQhard

A company has a VPC with public and private subnets. The private subnets need outbound internet access to download software updates while preventing any inbound internet traffic. The SysOps administrator must minimize costs. Which solution should the administrator implement?

A.Create a NAT Gateway in a public subnet and update the private subnet route table to use it
B.Launch a NAT instance in a public subnet with an Elastic IP and disable source/destination check, then update private subnet route tables
C.Attach an Internet Gateway to the VPC and add a default route to the Internet Gateway in the private subnets
D.Use AWS Transit Gateway with a VPN connection to an on-premises data center for internet access
AnswerB

Launching a NAT instance is the correct cost-minimizing solution because it uses a regular EC2 instance, which incurs only standard instance-hour charges and no per-gigabyte data processing fees, unlike a NAT Gateway. To make it work, you must assign an Elastic IP so the NAT instance has a stable public address, disable the source/destination check so the instance can forward traffic, and update the private subnet route tables to point 0.0.0.0/0 at the NAT instance's private IP. This configuration provides outbound internet access for private instances while preserving the cost advantage over the managed gateway service.

Why this answer

A NAT instance, when launched in a public subnet with an Elastic IP and source/destination check disabled, can route outbound traffic from private subnets to the internet while blocking unsolicited inbound connections. This solution minimizes costs compared to a NAT Gateway, as NAT instances use existing EC2 instance pricing and can be further reduced with spot instances or smaller instance types.

Exam trap

The trap here is that candidates often choose the NAT Gateway (Option A) because it is fully managed and simpler, overlooking the explicit cost-minimization requirement that favors the cheaper, self-managed NAT instance.

How to eliminate wrong answers

Option A is wrong because a NAT Gateway incurs hourly charges and data processing fees, making it more expensive than a NAT instance, which is contrary to the requirement to minimize costs. Option C is wrong because attaching an Internet Gateway directly to private subnets and adding a default route would expose those subnets to inbound internet traffic, violating the security requirement to prevent inbound traffic. Option D is wrong because AWS Transit Gateway with a VPN connection to an on-premises data center is over-engineered and costly for simple outbound internet access, and it does not directly provide internet access without additional routing and infrastructure.

32
MCQeasy

Refer to the exhibit. A SysOps administrator runs the describe-target-health command and sees that an EC2 instance in the target group is unhealthy with a timeout error. What is the most likely cause?

A.The target group is configured with an incorrect port
B.The instance's security group does not allow traffic from the ALB on the health check port
C.The instance is in a private subnet without a NAT gateway
D.The instance does not have a route to the internet
AnswerB

The ALB health check requests are sent from the ALB nodes' private IP addresses to the target's health check port. If the instance's security group lacks an inbound rule that permits TCP on port 80 from the ALB's security group (or the VPC CIDR), the packets are silently dropped. This causes the health check to time out and the target to be marked unhealthy, which matches the observed symptom.

Why this answer

The health check is timing out, which indicates that the instance is not responding to health check requests on port 80. The security group must allow inbound traffic from the ALB on the health check port. Option A is wrong because the target group is configured with port 80, which matches.

Option C is wrong because the route table is less likely to cause a timeout; it would cause unreachability. Option D is wrong because the instance is in a public subnet? Not necessarily; but the health check timeout is most often a security group issue.

33
MCQhard

An application uses Amazon Route 53 weighted routing to distribute traffic across two AWS regions. After a deployment, users in one region are experiencing errors. What should the administrator do to mitigate the issue immediately?

A.Update the alias record to point to a different load balancer.
B.Change the routing policy from weighted to latency-based.
C.Restart the EC2 instances in the affected region.
D.Set the weight of the affected region's record to 0 and verify health checks are configured.
AnswerD

Weighted routing with weight 0 stops Route 53 returning that region's record while leaving the other region serving traffic, giving immediate mitigation. Health checks then prevent DNS from resolving to the failing region if it is re-enabled.

Why this answer

Setting the weight of the affected region's Route 53 record to 0 immediately removes that region from the weighted routing rotation, diverting all traffic to the healthy region. Verifying that health checks are configured ensures Route 53 can automatically fail over if the region becomes unhealthy again, providing both immediate mitigation and ongoing resilience.

Exam trap

The trap is reaching for a design change (latency-based routing) or a disruptive action (restarting instances) when the question asks for immediate mitigation — candidates must recognize that setting weight to 0 is the fastest, least disruptive Route 53-native way to drain traffic from a failing region.

How to eliminate wrong answers

Option A is wrong because updating an alias record to point to a different load balancer is a manual, disruptive change that doesn't leverage Route 53's weighted routing capabilities and could cause additional downtime. Option B is wrong because changing the routing policy from weighted to latency-based is a design change, not an immediate mitigation — it also doesn't guarantee traffic avoids the failing region if latency is still low. Option C is wrong because restarting EC2 instances is a guess at the root cause and may not resolve the issue; it also causes additional disruption without guaranteeing recovery.

34
MCQmedium

A SysOps Administrator is troubleshooting connectivity issues between two EC2 instances in the same VPC but different subnets. The instances can communicate over private IP addresses when security groups are set to allow all traffic, but fail when security groups are configured with specific rules. The Administrator wants to allow HTTP (port 80) and HTTPS (port 443) traffic from the client instance to the server instance. What security group rules are needed?

A.Add inbound rules on the server to allow HTTP and HTTPS from the client security group.
B.Add inbound rules on both the client and server.
C.Add outbound rules on both the client and server.
D.Add inbound rules on the client and outbound rules on the server.
AnswerA

Security groups are stateful, so adding inbound rules on the server to permit HTTP (80) and HTTPS (443) from the client security group is the correct, minimal fix. The inbound rule allows the client's request to reach the server, and because stateful filtering tracks the connection, the server's response is automatically allowed back to the client without any outbound rule on the server. The client security group as the source scopes access precisely to instances with that group, avoiding a 0.0.0.0/0 exposure.

Why this answer

Security groups are stateful, meaning that if you allow inbound traffic, the response outbound is automatically allowed regardless of outbound rules. Therefore, you only need to add inbound rules on the server instance to allow HTTP and HTTPS traffic from the client security group. Option B is incorrect because no inbound rules are needed on the client.

Option C is incorrect because no outbound rules are needed on either instance for this traffic. Option D is incorrect because outbound rules on the server are not required.

35
MCQeasy

A SysOps administrator is configuring a VPC peering connection between two VPCs in the same AWS account and Region. The VPCs have non-overlapping CIDR blocks. The administrator needs to ensure that instances in both VPCs can communicate with each other. Which additional configuration is required after accepting the peering connection?

A.Create a transit gateway and attach both VPCs to it, then route traffic through the transit gateway.
B.Modify the security groups in both VPCs to allow traffic from the peer VPC's CIDR block.
C.Update the route tables in both VPCs to include a route to the peer VPC's CIDR block through the VPC peering connection.
D.Configure a VPN connection between the two VPCs to enable communication.
AnswerC

VPC peering connections do not automatically add routes. You must manually add a route in each VPC's route table that points to the peering connection for the peer VPC's CIDR block. This enables traffic to be routed between the VPCs. Without these routes, instances cannot communicate even though the peering connection is active.

Why this answer

After establishing a VPC peering connection, you must update the route tables in both VPCs to direct traffic destined for the peer VPC's CIDR block to the peering connection. Security groups must also allow the traffic, but the question asks for the additional configuration specifically required after accepting the peering connection, which is route table updates. Without these routes, communication fails.

Exam trap

The trap here is assuming that VPC peering automatically updates route tables or that security group changes alone are sufficient, when manual route table entries are mandatory.

36
MCQhard

A company has a VPC with public and private subnets. An Application Load Balancer (ALB) is deployed in the public subnets, and an Auto Scaling group of web servers is deployed in the private subnets. The web servers need to frequently make HTTPS requests to an external API. The API provider requires that all requests originate from a consistent set of static IP addresses for whitelisting. The SysOps administrator must ensure that outbound traffic from the web servers has static source IP addresses. Which solution should be implemented?

A.Place the web servers in public subnets and assign each instance an Elastic IP address.
B.Deploy a NAT gateway in a public subnet with an Elastic IP and route outbound traffic from the private subnets through the NAT gateway.
C.Create a VPC endpoint for the external API service.
D.Use AWS Global Accelerator to provide static IP addresses for outbound traffic.
AnswerB

Deploying a NAT gateway in a public subnet and adding a route (0.0.0.0/0) to the private subnets' route tables enables outbound internet access while preserving the private nature of the instances. The NAT gateway's Elastic IP provides a consistent, static public source IP for all outbound traffic, meeting the requirement to whitelist a single address for the external API. No inbound connections are permitted, as the NAT gateway is one-way, and this managed service is highly available within each Availability Zone. This is the standard AWS architecture for outbound-only internet access from private subnets.

Why this answer

A NAT gateway placed in a public subnet with an Elastic IP provides a consistent, static source IP for all outbound traffic from instances in private subnets. The web servers route their outbound HTTPS requests through the NAT gateway, which performs source NAT (SNAT) using the Elastic IP, satisfying the API provider's whitelisting requirement. This design keeps the web servers in private subnets for security while ensuring a fixed public IP for outbound traffic.

Exam trap

The trap here is that candidates confuse AWS Global Accelerator's static IPs for inbound traffic with the need for static outbound IPs, or mistakenly think VPC endpoints can be used for any external service, when they only work with supported AWS services.

How to eliminate wrong answers

Option A is wrong because placing web servers in public subnets with Elastic IPs would expose them directly to the internet, bypassing the ALB and compromising security; it also requires managing individual Elastic IPs per instance, which is not scalable for an Auto Scaling group. Option C is wrong because a VPC endpoint is used for private connectivity to AWS services (e.g., S3, DynamoDB) via the AWS network, not for reaching external HTTPS APIs over the internet; it does not provide static IP addresses for outbound traffic to third-party endpoints. Option D is wrong because AWS Global Accelerator provides two static Anycast IP addresses for inbound traffic to your application endpoints (e.g., ALB, NLB), not for outbound traffic from instances; it does not affect the source IP of outbound requests from web servers.

37
MCQeasy

A company has a VPC that requires DNS resolution for custom domain names within the VPC. They want to use a private hosted zone in Amazon Route 53. Which resource is required to associate the private hosted zone with the VPC?

A.A resolver rule
B.A public hosted zone
C.A VPC
D.A CNAME record
AnswerC

A private hosted zone must be associated with one or more Amazon VPCs before resources inside those VPCs can resolve the zone's records. Without this explicit association, the zone remains created but unusable, even if instances are in the same AWS account. Route 53 merges the private hosted zone's records with the default VPC DNS only after the association request succeeds, which makes the VPC the required target resource.

Why this answer

To associate a private hosted zone with a VPC in Amazon Route 53, you must specify the VPC ID and the AWS Region of the VPC. The VPC itself is the required resource because the private hosted zone is scoped to one or more VPCs, enabling DNS resolution for custom domain names only within those VPCs. Without a VPC association, the private hosted zone cannot serve DNS queries.

Exam trap

The trap here is that candidates often confuse the resource needed for association (the VPC) with DNS record types or resolver configurations, mistakenly thinking a CNAME record or resolver rule is required to link the hosted zone to the VPC.

How to eliminate wrong answers

Option A is wrong because a resolver rule is used with Route 53 Resolver to forward DNS queries to or from on-premises networks, not to associate a private hosted zone with a VPC. Option B is wrong because a public hosted zone is used for DNS resolution over the internet, not for private DNS within a VPC, and it cannot be associated with a VPC. Option D is wrong because a CNAME record is a DNS record type that maps an alias to a canonical name, not a resource that associates a hosted zone with a VPC.

38
MCQhard

A company uses Amazon CloudFront to serve static content from an S3 bucket. The S3 bucket is configured as an origin with RestrictBucketAccess set to Yes, and the origin access identity (OAI) is configured. Users can access the content via CloudFront, but direct S3 URLs return Access Denied. However, some users report that they can still access the content directly via S3 URLs. What is the most likely reason?

A.The OAI is not properly associated with the CloudFront distribution.
B.The S3 bucket policy allows public read access in addition to the OAI.
C.The CloudFront distribution is using a custom origin instead of S3.
D.CloudFront is using pre-signed URLs that are being shared.
AnswerB

The OAI only authenticates CloudFront to S3; it does not automatically override a bucket policy that grants `s3:GetObject` to the public. If the bucket policy includes an `Allow` for `*` (or `AllPrincipals`), any user can access objects directly via the S3 bucket URL or website endpoint, entirely bypassing CloudFront. This explains the reported behavior: CloudFront works via the OAI, but the bucket remains publicly readable, so the security requirement is violated.

Why this answer

The most likely reason users can still access content directly via S3 URLs is that the S3 bucket policy allows public read access in addition to the OAI. Even though CloudFront is configured with OAI and RestrictBucketAccess, if the bucket policy grants public read permissions (e.g., via a statement with Principal: "*"), then direct S3 access remains possible. The OAI only restricts access when the bucket policy explicitly denies public access and allows only the OAI.

Exam trap

SOA-C02 often tests the misconception that configuring OAI and RestrictBucketAccess automatically blocks all direct S3 access, ignoring the possibility of a permissive bucket policy that overrides these settings.

How to eliminate wrong answers

Option A is wrong because if the OAI were not properly associated, users would not be able to access content via CloudFront either, but the scenario states they can. Option C is wrong because if CloudFront were using a custom origin instead of S3, the RestrictBucketAccess and OAI settings would not apply, but the scenario indicates S3 is the origin. Option D is wrong because pre-signed URLs are a feature of CloudFront or S3 that grant temporary access, but the scenario describes direct S3 URL access, not pre-signed URLs; also, pre-signed URLs would not be the default behavior.

39
Multi-Selectmedium

A company is using Amazon CloudFront to distribute content globally. They want to restrict access to their content so that only users from specific countries can access it. Which TWO actions can be taken to achieve this?

Select 2 answers
A.Configure an S3 bucket policy with a condition for aws:SourceIp.
B.Configure CloudFront geo restriction (whitelist or blacklist) at the distribution level.
C.Use IAM policies to restrict access based on the user's location.
D.Use AWS WAF associated with CloudFront to create a rule that blocks requests based on geographic origin.
E.Set up an Application Load Balancer rule to deny traffic from certain IP ranges.
AnswersB, D

CloudFront geo restriction (whitelist or blacklist) is a native feature that uses a country-level database derived from the request's source IP to allow or block requests at the edge. It is configured directly on the distribution through the 'Restrictions' tab and applies to all content types before the request reaches the origin, requiring no changes to your application or backend. This is the simplest and most cost-effective way to enforce geographic access controls, as it requires no additional AWS services and works automatically with the CloudFront's global edge network.

Why this answer

CloudFront geo restriction allows you to whitelist or blacklist countries at the distribution level, directly controlling access based on the geographic location of the viewer's IP address. This is a native CloudFront feature that does not require additional services, making it a straightforward solution for country-based access control.

Exam trap

The trap here is that candidates often confuse the ability to use S3 bucket policies with aws:SourceIp for CloudFront-distributed content, not realizing that CloudFront acts as a proxy and the source IP seen by S3 is the CloudFront edge IP, not the end user's IP.

40
MCQmedium

A company has a web application running on EC2 instances behind an Application Load Balancer (ALB). The application uses sticky sessions (session affinity) based on cookies. Recently, the SysOps team noticed that user sessions are being lost intermittently, causing users to be logged out. The team checks the ALB configuration and finds that the stickiness is enabled with a cookie name 'AWSALB' and duration of 1 hour. The application also sets its own cookie. What is the most likely cause of session loss?

A.The ALB's health check interval is too short, causing instances to be marked unhealthy
B.The application cookie is overwriting the ALB's stickiness cookie
C.Cross-zone load balancing is disabled on the ALB
D.The application's session cookie has a shorter expiration than the ALB's stickiness duration
AnswerD

In this scenario, the ALB's stickiness cookie (AWSALB) remains valid and continues to route the client to the same EC2 instance for the configured duration, but the application's own session cookie (e.g., JSESSIONID) expires earlier. Once the application session expires, the server-side session data is discarded or considered invalid, causing the user to be logged out even though the ALB still sends them to the exact same server. The user then perceives a lost session, but the underlying issue is the mismatch between the application session timeout and the ALB stickiness duration, not the load balancer's routing behavior.

Why this answer

The most likely cause is that the application's session cookie expires before the ALB's stickiness cookie, causing the user to be logged out even though the ALB still routes to the same instance. The ALB stickiness duration is 1 hour, but if the application cookie has a shorter lifespan, the session ends prematurely. This is a common misconfiguration when application and load balancer session timeouts are not aligned.

Exam trap

SOA-C02 often tests the confusion between ALB stickiness and application session management, leading candidates to blame the ALB cookie or health checks instead of misaligned timeouts.

How to eliminate wrong answers

Option A is wrong because a short health check interval would cause instances to be marked unhealthy only if they fail checks, leading to removal from rotation, but the symptom is intermittent session loss, not complete unavailability. Option B is wrong because the ALB's stickiness cookie (AWSALB) and the application cookie have different names; they do not overwrite each other. Option C is wrong because cross-zone load balancing affects distribution across AZs, not session stickiness; disabling it does not cause session loss.

41
MCQeasy

A SysOps administrator has deployed an Application Load Balancer (ALB) that distributes traffic to a fleet of Amazon EC2 instances. The administrator notices that the ALB is sending all traffic to instances in a single Availability Zone (AZ), ignoring instances in other AZs. The ALB was created with default settings. Which action should the administrator take to ensure traffic is distributed evenly across all AZs?

A.Enable cross-zone load balancing on the ALB.
B.Enable connection draining on the target group.
C.Enable sticky sessions (session stickiness) on the target group.
D.Configure health checks on the target group to ensure unhealthy instances are not used.
AnswerD

Health checks ensure traffic is only sent to healthy instances, but they do not control the AZ-level distribution. If all instances are healthy, the ALB will still only send traffic to instances in the same AZ as the node that received the request if cross-zone is disabled.

Why this answer

By default, an Application Load Balancer has cross-zone load balancing always enabled, so traffic can be sent to healthy targets in any enabled Availability Zone. If traffic is not reaching instances in other AZs, the likely cause is that targets in those AZs are failing health checks or are not registered. Configuring accurate health checks on the target group will allow the ALB to mark those targets healthy and distribute traffic across all AZs.

Connection draining and sticky sessions do not affect AZ-level distribution.

Exam trap

Candidates often believe cross-zone load balancing must be enabled on an Application Load Balancer. However, ALB cross-zone load balancing is always enabled by default (unlike Network Load Balancers, where it is disabled by default). When an ALB appears to ignore instances in other AZs, check target health checks and registration instead of cross-zone settings.

How to eliminate wrong answers

Option B is wrong because connection draining (also known as deregistration delay) is used to complete in-flight requests before an instance is deregistered or becomes unhealthy, not to distribute traffic across AZs. Option C is wrong because sticky sessions (session stickiness) bind a client's requests to a specific target instance, which can actually prevent even distribution across AZs by concentrating traffic on a single instance. Option D is wrong because health checks only mark unhealthy instances as out of service; they do not influence how traffic is distributed across AZs—traffic would still be sent to healthy instances in the same AZ even if other AZs have healthy instances.

42
MCQeasy

Which AWS service can be used to create a private, dedicated connection between an on-premises data center and AWS?

A.AWS Site-to-Site VPN
B.AWS Transit Gateway
C.VPC Peering
D.AWS Direct Connect
AnswerD

AWS Direct Connect is the correct answer because it provides a dedicated, private, physical network connection from your on-premises data center directly to AWS, completely bypassing the public internet. This is achieved through a cross-connect at an AWS Direct Connect location, and you can create private virtual interfaces to access your VPC resources with consistent latency and higher bandwidth. It fulfills the requirement for a private dedicated connection, unlike VPN or other network constructs.

Why this answer

AWS Direct Connect provides a dedicated, private network connection from an on-premises data center to AWS, bypassing the public internet. It offers more consistent network performance, lower latency, and reduced bandwidth costs compared to internet-based connections. This makes it the correct choice for a private, dedicated connection.

Exam trap

SOA-C02 often tests the distinction between a dedicated private connection (Direct Connect) and an encrypted connection over the public internet (Site-to-Site VPN). Candidates may confuse Transit Gateway as a connectivity service, but it is a hub, not a direct connection.

How to eliminate wrong answers

Option A is wrong because AWS Site-to-Site VPN uses the public internet to create an encrypted tunnel, not a dedicated private connection. Option B is wrong because AWS Transit Gateway is a network transit hub for connecting VPCs and on-premises networks, but it does not itself provide the dedicated physical connection; it can be used with Direct Connect or VPN. Option C is wrong because VPC Peering connects two VPCs within AWS, not an on-premises data center to AWS.

43
Multi-Selectmedium

A SysOps administrator is planning a VPC design with high availability for an application that must tolerate the failure of an entire Availability Zone. Which TWO configurations should be implemented? (Select TWO.)

Select 2 answers
A.Use a single NAT Gateway for all private subnets.
B.Deploy a NAT Gateway in each Availability Zone.
C.Launch EC2 instances in at least two Availability Zones.
D.Use a placement group to ensure instances are in different AZs.
E.Use only one public subnet and one private subnet.
AnswersB, C

A NAT Gateway is a zonal resource: each gateway runs from a specific Availability Zone and has its own elastic IP, and its availability is tied to that AZ. By deploying one NAT Gateway in each Availability Zone and routing each private subnet's 0.0.0.0/0 traffic to the gateway in its own AZ, outbound internet access from private instances continues to work even if an entire AZ fails. This design eliminates the cross-AZ dependency and avoids a single point of failure for private-subnet egress.

Why this answer

Option B is correct because a NAT Gateway is an AZ-scoped resource, so deploying one in each Availability Zone ensures that private subnet egress continues to function if a single AZ fails; a single NAT Gateway would become a single point of failure. Option C is correct because launching EC2 instances in at least two Availability Zones provides the actual compute redundancy needed to tolerate the loss of an entire AZ, allowing traffic to be served from the surviving AZ. Option A is incorrect because one NAT Gateway shared by all private subnets concentrates the egress path in a single AZ and fails during an AZ outage.

Option D is incorrect because placement groups (cluster, spread, or partition) do not by themselves guarantee multi-AZ resilience and are not the mechanism for AZ-level failover. Option E is incorrect because a single public and single private subnet confines resources to one AZ, directly contradicting the high-availability requirement.

Exam trap

The trap here is that candidates often think a single NAT Gateway is sufficient for high availability because it is a managed service, but they overlook that it is still tied to a single AZ and will fail if that AZ fails, making per-AZ deployment essential for AZ-level fault tolerance.

44
MCQhard

An organization has a VPC with public and private subnets. The private subnets need to access the internet for software updates. A NAT gateway is deployed in a public subnet and the private subnet route table has a route for 0.0.0.0/0 pointing to the NAT gateway. However, instances in the private subnet cannot reach the internet. What could be the issue?

A.The NAT gateway's subnet does not have a route to an internet gateway
B.The private subnet's network ACL blocks outbound HTTPS traffic
C.The security group attached to the NAT gateway does not allow outbound traffic
D.The private instances do not have a public IP address assigned
AnswerA

For the NAT gateway to successfully forward traffic from private subnets to the internet, the subnet where the NAT gateway resides must have a route to an internet gateway (IGW). Without a route to the IGW in that subnet's route table, the NAT gateway cannot send or receive traffic from the internet, even though it has a public Elastic IP. This is the most common reason for failed outbound internet access from private instances when a NAT gateway is present.

Why this answer

The NAT gateway must be in a public subnet with a route table that includes a default route (0.0.0.0/0) pointing to an internet gateway (IGW). Without this route, the NAT gateway cannot forward traffic from the private subnet to the internet, because the IGW is the only way to reach public IP addresses. The question states the NAT gateway is deployed in a public subnet, but if that subnet's route table lacks the IGW route, outbound traffic from the NAT gateway will fail.

Exam trap

The trap here is that candidates assume placing a NAT gateway in a 'public subnet' automatically gives it internet access, but the subnet must have a route table entry pointing 0.0.0.0/0 to an internet gateway for the NAT gateway to function.

How to eliminate wrong answers

Option B is wrong because a network ACL (NACL) is stateless and would need to block both outbound HTTPS (port 443) and the corresponding inbound ephemeral return traffic; however, the default NACL allows all traffic, and the question does not indicate any custom NACL changes, so this is unlikely the root cause. Option C is wrong because security groups are stateful and are attached to resources like EC2 instances, not to NAT gateways; NAT gateways do not have security groups, so this option is technically invalid. Option D is wrong because instances in a private subnet do not need public IP addresses; they rely on the NAT gateway's public IP for outbound internet access, so the absence of a public IP on the private instances is not the issue.

45
MCQeasy

A SysOps administrator needs to allow traffic from a specific IP address range (203.0.113.0/24) to access an Amazon EC2 instance in a VPC. Which configuration step should be performed?

A.Create an IAM policy that allows inbound traffic from 203.0.113.0/24.
B.Add a rule to the network ACL associated with the subnet to allow inbound traffic from 203.0.113.0/24.
C.Modify the route table of the subnet to include a route for 203.0.113.0/24 to the internet gateway.
D.Add an inbound rule to the security group associated with the EC2 instance allowing traffic from 203.0.113.0/24.
AnswerD

A security group is a stateful, instance-level virtual firewall that filters traffic at the elastic network interface. Adding an inbound rule that permits 203.0.113.0/24 on the desired port allows that specific source to reach the EC2 instance, and because security groups are stateful, the return traffic is automatically allowed without any additional outbound rule. This provides the most precise and correct method for the stated requirement.

Why this answer

Security groups are the stateful, instance-level virtual firewalls in AWS that control inbound and outbound traffic to EC2 instances. To permit traffic from a specific CIDR block like 203.0.113.0/24 to reach an EC2 instance, you must add an inbound rule to the security group attached to that instance, specifying the source as the CIDR. This is the most direct and correct configuration step because security groups operate at the ENI level and are required for any inbound traffic to be allowed.

Exam trap

SOA-C02 often tests the confusion between security groups and network ACLs, leading candidates to select network ACLs when the question asks for allowing traffic to a specific EC2 instance.

How to eliminate wrong answers

Option A is wrong because IAM policies control AWS API permissions and identity-based access, not network traffic to EC2 instances. Option B is wrong because network ACLs are stateless subnet-level firewalls; while they can allow traffic, they are not the primary or sufficient step—security groups must also allow it, and the question asks for the step to allow traffic to the instance, which is best done via security group. Option C is wrong because route tables direct traffic between subnets and gateways; they do not filter or permit traffic based on source IP, and adding a route for 203.0.113.0/24 to an internet gateway would not allow inbound access to the instance.

46
Multi-Selecteasy

A company has an Application Load Balancer (ALB) that distributes traffic to EC2 instances. The company wants to enable path-based routing to send requests to different target groups. Which TWO resources must be created to achieve this?

Select 2 answers
A.Subnet for the ALB
B.Target group for each backend service
C.Network Load Balancer (NLB)
D.Listener rule with a path pattern condition
E.Security group for the ALB
AnswersB, D

In an Application Load Balancer, traffic is not forwarded directly to backend instances; it is forwarded to target groups. A target group logically groups a set of backend instances or IP addresses for one specific service, and each target group has its own health checks, stickiness policy, and routing metadata. Because each backend service is a distinct application, you need a separate target group per service so that a listener rule can route a specific URL path to the correct group of instances.

Why this answer

(Target group for each backend service) and Option D (Listener rule with a path pattern condition) are correct. Path-based routing requires creating target groups for each backend service and a listener rule with a path pattern condition to direct requests to the appropriate target group. Option A is incorrect because subnets are needed for the ALB, but they are not specifically required for path-based routing.

Option C is incorrect because a Network Load Balancer is not used; the ALB itself handles path-based routing. Option E is incorrect because a security group controls traffic but does not enable path-based routing.

47
MCQmedium

A company runs an application across multiple Availability Zones. The application servers are in private subnets and need outbound internet access to download software updates and patches. The SysOps administrator needs a highly available, fully managed solution to provide this outbound connectivity. Which solution should be used?

A.Deploy a NAT instance in each private subnet
B.Deploy a single NAT Gateway in one public subnet
C.Deploy a NAT Gateway in each public subnet
D.Attach an Internet Gateway directly to the private subnets
AnswerC

By deploying a NAT Gateway in each Availability Zone's public subnet and configuring private subnets to use the NAT Gateway in the same AZ, the solution is both fully managed and highly available. If one AZ fails, the other AZ's NAT Gateway continues to provide internet access.

Why this answer

Deploying a NAT Gateway in each public subnet provides a highly available, fully managed solution for outbound internet access from private subnets. NAT Gateways are managed by AWS, automatically scale, and are resilient within an Availability Zone; using one per AZ ensures that if one AZ fails, the others continue to provide outbound connectivity. This meets the requirement for high availability without the operational overhead of managing NAT instances.

Exam trap

The trap here is that candidates often confuse NAT Gateways with NAT instances or assume a single NAT Gateway is sufficient for high availability, overlooking the need for one per Availability Zone to achieve true fault tolerance.

How to eliminate wrong answers

Option A is wrong because NAT instances are self-managed EC2 instances that require manual patching, scaling, and failover configuration, which contradicts the 'fully managed' requirement and introduces a single point of failure if only one instance is used per subnet. Option B is wrong because a single NAT Gateway in one public subnet creates a single point of failure; if that Availability Zone becomes unavailable, all private subnets lose outbound internet access, violating the high availability requirement. Option D is wrong because attaching an Internet Gateway directly to private subnets would expose those subnets to inbound internet traffic, defeating the purpose of a private subnet and violating security best practices; Internet Gateways are designed for public subnets only.

48
MCQhard

A SysOps administrator is setting up a Network Load Balancer (NLB) to handle millions of requests per second. The target group consists of EC2 instances that are in a single Availability Zone. Which of the following is a potential issue?

A.If the single AZ becomes unavailable, the NLB will not automatically fail over to other AZs.
B.The NLB cannot be associated with only one Availability Zone.
C.The NLB cannot preserve the source IP address of the client.
D.The NLB will not be able to handle the traffic volume due to the single AZ limitation.
AnswerA

If only one Availability Zone is configured, the NLB has a single load balancer node with an Elastic Network Interface in that AZ. When that AZ becomes unavailable, the NLB node itself and every registered target are unreachable simultaneously, so the NLB cannot re-route traffic elsewhere because no other AZ has an ENI or target group membership. Automatic failover to another AZ is only possible if at least one additional AZ is enabled and has healthy targets.

Why this answer

Option A is the correct answer because if the NLB is provisioned in a single Availability Zone (AZ) and that AZ fails, the NLB will not automatically fail over to other AZs, which is a potential issue for high availability. Option B is incorrect because an NLB can be associated with only one AZ. Option C is incorrect because the NLB can preserve the source IP address when using instance targets.

Option D is incorrect because the NLB can handle high throughput even in a single AZ.

49
MCQmedium

A company runs a web application on EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). The application needs to serve HTTPS content. The SysOps administrator wants to offload SSL termination to the ALB and automatically renew the certificate before expiration. Which solution should the administrator implement?

A.Use AWS Certificate Manager (ACM) to request a public certificate and associate it with the ALB.
B.Upload a third-party certificate to IAM and associate it with the ALB.
C.Store the certificate in Amazon S3 and configure the ALB to read from S3.
D.Use a self-signed certificate on each EC2 instance and configure the ALB for TCP passthrough.
AnswerA

AWS Certificate Manager (ACM) public certificates are fully managed, so ACM automatically renews them before expiration and handles DNS or email validation. You can directly associate the certificate with an ALB listener, and the ALB terminates TLS, meaning EC2 instances receive only HTTP traffic. This offloads the cryptographic overhead and eliminates the need to install or rotate certificates on individual instances, making it the intended and least operationally burdensome approach.

Why this answer

AWS Certificate Manager (ACM) integrates natively with Application Load Balancers to handle SSL/TLS termination. ACM can automatically renew public certificates issued by Amazon's trusted certificate authority, eliminating the need for manual renewal. By associating the ACM certificate with the ALB's HTTPS listener, the administrator offloads SSL termination and ensures automatic certificate renewal before expiration.

Exam trap

The trap here is that candidates may confuse ACM's automatic renewal with manual certificate upload methods (IAM or S3) or incorrectly think self-signed certificates can be used with ACM, when in fact ACM only manages certificates from its own public CA or imported certificates that must be manually renewed.

How to eliminate wrong answers

Option B is wrong because uploading a third-party certificate to IAM is a legacy approach that does not support automatic renewal; IAM certificates must be manually re-uploaded before expiration. Option C is wrong because Amazon S3 cannot be used as a certificate store for ALB; ALB does not support reading certificates from S3. Option D is wrong because using a self-signed certificate on each EC2 instance with TCP passthrough would require the instances to handle SSL termination, defeating the requirement to offload SSL to the ALB, and self-signed certificates are not trusted by browsers and cannot be automatically renewed by ACM.

50
MCQeasy

A company has a VPC with an IPv4 CIDR block of 10.0.0.0/16. They need to connect to an on-premises network with a CIDR of 10.0.0.0/8. What is the issue?

A.The on-premises CIDR is private and cannot be used with AWS.
B.AWS does not support /8 CIDR blocks.
C.The CIDR blocks overlap, causing routing conflicts.
D.The VPC CIDR is too large.
AnswerC

The VPC CIDR block 10.0.0.0/16 and an on-premises CIDR that also uses part of the 10.0.0.0/16 range overlap. When you establish a VPN connection or AWS Direct Connect between the VPC and the on-premises network, overlapping CIDRs create ambiguous routing: the VPC route table cannot determine whether traffic for those IPs should go to the local network or the on-premises network, so traffic may be dropped or misrouted. AWS does not allow overlapping CIDRs for VPC peering or for VPN/Direct Connect connections, so you must redesign the IP addressing to avoid overlap.

Why this answer

Overlapping CIDR blocks prevent VPC peering or VPN connections because routes conflict. Option A is not the issue. Option B is not the primary issue.

Option D is not directly a problem.

51
MCQeasy

A company wants to provide low-latency access to static content (images, CSS) for global users. The content is stored in an S3 bucket. Which service should be used to cache content at edge locations?

A.Amazon ElastiCache
B.Amazon CloudFront
C.S3 Transfer Acceleration
D.AWS Global Accelerator
AnswerB

CloudFront is a global content delivery network that caches static content at edge locations worldwide, providing low latency and high transfer speeds to users by serving objects from the nearest edge. It integrates natively with S3 origins, supports HTTP/HTTPS, and automatically handles both static and dynamic content with customizable cache behavior. This directly meets the requirement for low latency access to static content.

Why this answer

Amazon CloudFront is a content delivery network (CDN) that caches static content (e.g., images, CSS) at edge locations worldwide, providing low-latency access to global users. It integrates directly with S3 as an origin, allowing you to serve content from edge caches while reducing load on the S3 bucket. This makes CloudFront the correct choice for caching static content at edge locations.

Exam trap

The trap here is confusing caching at edge locations (CloudFront) with acceleration of uploads (S3 Transfer Acceleration) or network routing optimization (Global Accelerator), leading candidates to pick a service that does not actually cache content.

How to eliminate wrong answers

Option A is wrong because Amazon ElastiCache is an in-memory caching service (e.g., Redis or Memcached) designed to cache dynamic data from databases or application servers, not for caching static content at edge locations. Option C is wrong because S3 Transfer Acceleration speeds up uploads to S3 over long distances using AWS edge locations, but it does not cache content for subsequent reads or serve it to end users. Option D is wrong because AWS Global Accelerator improves availability and performance for TCP/UDP traffic by routing users to the nearest healthy endpoint, but it does not cache static content at edge locations.

52
MCQeasy

A company has deployed a web application across multiple Availability Zones using an Application Load Balancer. The application experiences increased latency during peak hours. Which action would be MOST effective in reducing latency?

A.Add more EC2 instances to the target group.
B.Update the health check to use a more frequent interval.
C.Enable cross-zone load balancing on the ALB.
D.Increase the deregistration delay for the target group.
AnswerA

Adding more EC2 instances to the target group horizontally scales web application capacity, allowing the ALB to distribute incoming requests across more compute resources. When latency is caused by CPU saturation, connection exhaustion, or thread-pool limits, this directly reduces per-instance load and therefore reduces queuing delay. It is the correct action because it addresses the root cause of latency under sustained traffic.

Why this answer

Adding more EC2 instances to the target group increases aggregate capacity, distributing the request load across more targets and reducing per-instance queueing and response time. During peak-hour latency spikes, horizontal scaling is the most direct and effective remedy because the bottleneck is typically compute or connection saturation on existing targets.

Exam trap

The trap is picking a configuration knob (health check, cross-zone, deregistration) that sounds like it improves performance but actually only affects availability or traffic distribution — the real fix for peak-load latency is adding capacity.

How to eliminate wrong answers

Option B is wrong because a more frequent health check only affects how quickly unhealthy targets are detected and removed — it does not increase capacity or reduce latency for healthy targets, and overly aggressive checks can add overhead. Option C is wrong because cross-zone load balancing is enabled by default on ALBs and only affects how traffic is distributed across AZs; it does not add capacity and would not reduce latency if all targets are already saturated. Option D is wrong because increasing deregistration delay actually keeps targets in 'draining' state longer, which can slow deployments and does nothing to improve steady-state latency.

53
MCQmedium

A SysOps administrator notices that traffic to an Amazon EC2 instance is being blocked even though the security group allows all inbound traffic. The subnet's network ACL allows all inbound and outbound traffic. What could be the issue?

A.The instance's operating system firewall is blocking the traffic.
B.The network ACL is not associated with the subnet correctly.
C.VPC Flow Logs are misconfigured.
D.The route table does not have a default route to an internet gateway.
AnswerA

The operating system firewall runs inside the instance and is completely independent of AWS's virtual firewalls. Even if the security group and network ACL both allow the traffic, iptables/nftables, UFW, or Windows Defender Firewall can silently drop the packets when they arrive at the instance's network stack. To confirm, check the OS firewall rules, examine system logs, or temporarily disable the firewall to see if connectivity is restored.

Why this answer

The security group and network ACL both allow all traffic, so the issue must be at the instance level. The operating system's built-in firewall (e.g., iptables for Linux, Windows Firewall for Windows) can block inbound traffic independently of AWS networking constructs. Since the OS firewall is not managed by AWS, it can override security group rules, causing traffic to be dropped even when AWS-side configurations are permissive.

Exam trap

The trap here is that candidates assume AWS-side controls (security groups and network ACLs) are the only layers that can block traffic, overlooking the instance's own OS firewall, which operates independently and can override permissive AWS rules.

How to eliminate wrong answers

Option B is wrong because if the network ACL were not associated correctly, the subnet would use the default network ACL (which denies all inbound and outbound traffic by default), but the question states the network ACL allows all traffic, implying it is properly associated. Option C is wrong because VPC Flow Logs are a monitoring feature that captures metadata about IP traffic; they do not block or allow traffic, so misconfiguration would not cause blocking. Option D is wrong because a missing default route to an internet gateway would prevent traffic from reaching the instance from the internet, but the question states traffic is being blocked (not that it cannot reach the subnet), and the security group and network ACL allow all traffic, so the issue is at the instance OS level.

54
Multi-Selecthard

Which THREE components are required to set up a site-to-site VPN connection between a VPC and an on-premises network? (Choose three.)

Select 3 answers
A.Virtual private gateway or transit gateway
C.VPN connection
D.Customer gateway
E.Internet gateway
AnswersA, C, D

The virtual private gateway (VGW) or transit gateway (TGW) serves as the AWS-side endpoint for a site-to-site VPN connection. It must be attached to a VPC (or a transit gateway for centralized connectivity) and terminates the IPsec tunnels from the on-premises network. Without this component, there is no target for the VPN traffic on AWS, making it a mandatory piece.

Why this answer

A virtual private gateway or transit gateway is required as the AWS-side VPN concentrator that terminates the VPN tunnels and routes traffic between the VPC and the on-premises network. It provides the target for the VPN connection and must be attached to the VPC to enable site-to-site VPN functionality.

Exam trap

The trap here is that candidates often confuse a NAT Gateway or Internet Gateway as necessary for VPN connectivity, but neither is involved in IPsec tunnel establishment; the correct components are the virtual private gateway (or transit gateway), the VPN connection, and the customer gateway.

55
MCQmedium

A SysOps administrator notices that traffic from an Application Load Balancer to targets is failing intermittently. The targets are EC2 instances in an Auto Scaling group. The health check settings on the target group are: ping path '/health', healthy threshold 2, unhealthy threshold 2, timeout 5 seconds, interval 30 seconds. Which change would most likely improve the stability of the health checks?

A.Increase the interval to 60 seconds.
B.Decrease the healthy threshold to 1.
C.Decrease the timeout to 2 seconds.
D.Increase the unhealthy threshold to 5.
AnswerD

Increasing the unhealthy threshold to 5 requires five consecutive failed health checks before an instance is declared unhealthy, rather than immediately reacting to a single failure. This adds tolerance for short-lived network glitches or transient resource bottlenecks, filtering out spurious failures and significantly reducing flapping while still allowing the load balancer to eventually remove a truly unhealthy instance.

Why this answer

Increasing the unhealthy threshold reduces flapping; currently 2 consecutive failures mark an instance unhealthy, which may be too sensitive. Option A is wrong because a longer interval would delay detection. Option B is wrong because a shorter timeout may cause false positives.

Option C is wrong because decreasing healthy threshold increases sensitivity.

56
MCQeasy

A company has two VPCs: VPC-A (10.0.0.0/16) and VPC-B (10.1.0.0/16). The VPCs are in the same AWS region. The SysOps administrator needs to enable private IP connectivity between the two VPCs so that an EC2 instance in VPC-A can communicate with an EC2 instance in VPC-B using their private IP addresses. The administrator wants a simple, low-cost solution with high throughput. Which AWS service should be used?

A.VPC Peering
B.AWS Transit Gateway
C.AWS Direct Connect
D.Internet Gateway
AnswerA

VPC peering establishes a one-to-one network relationship between two VPCs using private IPv4 addresses over AWS's backbone. It requires no virtual appliance, gateway, or physical contract, making it the simplest and most cost-efficient method for a two-VPC scenario in the same region. Since the CIDRs are non-overlapping, route tables can be updated to exchange traffic directly with minimal latency and high throughput.

Why this answer

VPC Peering is the correct choice because it enables direct, private IP connectivity between two VPCs in the same AWS region using the existing AWS network infrastructure, with no bandwidth bottlenecks, no single point of failure, and no additional cost beyond data transfer. It meets the requirements for simplicity, low cost, and high throughput, as traffic stays within the AWS backbone and does not require a separate transit hub or VPN.

Exam trap

The trap here is that candidates often choose AWS Transit Gateway for any multi-VPC connectivity, overlooking that VPC Peering is simpler and cheaper for a two-VPC scenario, and that Transit Gateway’s benefits (centralized routing, transitive peering) are only cost-effective with many VPCs.

How to eliminate wrong answers

Option B (AWS Transit Gateway) is wrong because it introduces unnecessary complexity and cost (hourly charges per attachment) for a simple two-VPC scenario; it is designed for hub-and-spoke topologies with many VPCs. Option C (AWS Direct Connect) is wrong because it provides dedicated on-premises connectivity to AWS, not connectivity between two VPCs, and involves significant setup cost and latency overhead. Option D (Internet Gateway) is wrong because it enables internet-bound traffic, not private VPC-to-VPC communication, and would require public IPs and route traffic over the public internet, violating the private IP requirement.

57
MCQhard

A company has an Amazon VPC with a CIDR block of 10.0.0.0/16 and an AWS Site-to-Site VPN connection to an on-premises data center. The on-premises DNS servers host a private domain 'corp.example.com'. The SysOps administrator needs to enable EC2 instances in the VPC to resolve DNS names for 'corp.example.com' using the on-premises DNS servers. Which Route 53 feature should be configured?

A.Route 53 Resolver inbound endpoints
B.Route 53 Resolver outbound endpoints with forwarding rules
C.VPC peering between the VPC and the on-premises network
D.Route 53 private hosted zone for corp.example.com
AnswerB

Route 53 Resolver outbound endpoints, when paired with forwarding rules, are the correct mechanism for conditional DNS forwarding from a VPC to on-premises. The outbound endpoint creates ENIs in your VPC that Route 53 Resolver uses to send queries to target DNS servers you specify, while forwarding rules associate a domain name such as corp.example.com with those on-premises DNS server IPs. Any query from a resource in the VPC for that domain is forwarded based on the rule; queries for other domains continue to use the default VPC resolver, enabling seamless hybrid DNS resolution.

Why this answer

Route 53 Resolver outbound endpoints allow EC2 instances in a VPC to forward DNS queries for a specific domain (e.g., corp.example.com) to on-premises DNS servers via the Site-to-Site VPN connection. By creating a forwarding rule on the outbound endpoint, DNS queries for corp.example.com are sent to the on-premises DNS resolvers, enabling resolution of private DNS names without exposing the VPC to inbound traffic.

Exam trap

The trap here is that candidates often confuse inbound and outbound endpoints: inbound endpoints are for on-premises to query AWS DNS, while outbound endpoints are for AWS to query on-premises DNS, and the question specifically requires EC2 instances to resolve on-premises names, which is an outbound scenario.

How to eliminate wrong answers

Option A is wrong because Route 53 Resolver inbound endpoints are used to allow on-premises DNS resolvers to forward queries to Route 53 Resolver in the VPC, not for EC2 instances to query on-premises DNS servers. Option C is wrong because VPC peering is used to connect VPCs within AWS, not to connect a VPC to an on-premises network; the VPN connection already provides the network path, and peering does not enable DNS resolution across the VPN. Option D is wrong because a Route 53 private hosted zone for corp.example.com would require the domain to be hosted in Route 53, but the question states the domain is hosted on on-premises DNS servers; a private hosted zone would not forward queries to on-premises resolvers.

58
MCQhard

A company has a VPC with multiple subnets. The SysOps administrator wants to ensure that EC2 instances in a private subnet can access Amazon S3 without going through a NAT Gateway or internet gateway. Which solution meets this requirement?

A.Set up a NAT Gateway in a public subnet and route traffic through it.
B.Create a VPC Gateway Endpoint for S3.
C.Use S3 Transfer Acceleration.
D.Create a VPC Interface Endpoint for S3.
AnswerB

A VPC Gateway Endpoint attaches to route tables and provides private connectivity to S3 using prefix lists, so traffic never traverses a NAT gateway or internet gateway. This satisfies the requirement that private-subnet instances reach S3 without either egress device.

Why this answer

A VPC Gateway Endpoint for S3 provides private connectivity from a VPC to Amazon S3 without requiring a NAT Gateway, internet gateway, or VPN. Traffic to S3 stays entirely within the AWS network, and the endpoint is added as a target in the route table for the private subnet. This is the only option that satisfies the 'no NAT/IGW' constraint for S3 specifically.

Exam trap

SOA-C02 often tests the distinction between Gateway Endpoints (S3/DynamoDB, free, route-table based) and Interface Endpoints (PrivateLink, ENI-based, hourly cost) — candidates frequently pick Interface Endpoint for S3 because it sounds more 'private'.

How to eliminate wrong answers

Option A is wrong because a NAT Gateway still requires an internet gateway and routes traffic over the public internet path, which contradicts the requirement to avoid NAT/IGW. Option C is wrong because S3 Transfer Acceleration speeds up uploads over the public internet via edge locations; it does not provide private VPC connectivity. Option D is wrong because an Interface Endpoint (AWS PrivateLink) for S3 is not the standard, cost-effective solution for S3 — S3 uses a Gateway Endpoint, and Interface Endpoints for S3 are only relevant for specific use cases like on-premises access via Direct Connect, not for private subnet EC2 to S3.

59
MCQhard

A company uses AWS Direct Connect to connect its on-premises data center to AWS. The data center has multiple VLANs that need to connect to separate VPCs in AWS. The company wants to maintain isolation between the VPCs while maximizing bandwidth utilization. Which solution should the SysOps administrator recommend?

A.Use AWS Transit Gateway to connect all VPCs and the Direct Connect gateway, then configure route tables to isolate traffic.
B.Configure a single Direct Connect connection with multiple private virtual interfaces, each tagged with a different VLAN ID and associated with a different VPC.
C.Provision multiple Direct Connect connections, one for each VPC, and use a different VLAN on each connection.
D.Establish a single Direct Connect connection and use IPsec VPN tunnels over it to connect to each VPC.
AnswerB

A single AWS Direct Connect connection supports multiple private virtual interfaces, each configured with a unique 802.1Q VLAN tag on the customer router and a distinct BGP session. Each private VIF is associated with a separate Virtual Private Gateway or through a Direct Connect Gateway, enabling isolated, dedicated connectivity to a specific VPC over the same physical fiber. This design maximizes bandwidth utilization by sharing the underlying port while maintaining Layer 2 isolation between VPCs, and it is the standard, cost-effective way to connect one on-premises network to multiple VPCs.

Why this answer

A single Direct Connect connection can support multiple private virtual interfaces (VIFs), each tagged with a unique 802.1Q VLAN ID. This allows the on-premises data center to connect to separate VPCs while maintaining traffic isolation via VLAN tagging, and it maximizes bandwidth utilization by sharing the single connection's capacity across all VIFs.

Exam trap

The trap here is that candidates often assume multiple VPCs require multiple Direct Connect connections, but AWS allows multiple private virtual interfaces on a single connection, each with its own VLAN ID, to achieve isolation and maximize bandwidth utilization.

How to eliminate wrong answers

Option A is wrong because AWS Transit Gateway does not eliminate the need for separate virtual interfaces; it aggregates routing but still requires either a Direct Connect gateway with multiple VIFs or a single VIF with transit VIF, and it does not directly address the requirement to use multiple VLANs for isolation. Option C is wrong because provisioning multiple Direct Connect connections is unnecessary and wasteful; a single connection can support multiple VIFs, and using separate connections would increase cost without improving isolation or bandwidth utilization. Option D is wrong because IPsec VPN tunnels over Direct Connect add unnecessary complexity and overhead, and they do not natively support multiple VLANs; the requirement is for private virtual interfaces with VLAN tagging, not encrypted tunnels.

60
Multi-Selecteasy

Which TWO statements about Amazon CloudFront origins are correct? (Choose two.)

Select 2 answers
A.CloudFront only supports HTTP origins, not HTTPS.
B.CloudFront can only use S3 buckets as origins.
C.CloudFront can use an Application Load Balancer as an origin.
D.CloudFront origins must be in the same region as the distribution.
E.CloudFront can use an S3 bucket configured as a static website as an origin.
AnswersC, E

An Application Load Balancer is a supported custom origin for CloudFront, which is why the statement is correct. You point the origin domain name to the ALB's DNS name (for example, my-alb-1234567890.us-east-1.elb.amazonaws.com) and configure the protocol (HTTP or HTTPS) that CloudFront should use when forwarding requests. Because the ALB is a public endpoint, you must ensure its security group allows inbound traffic from CloudFront's IP ranges, and it can be used to serve dynamic or mixed content behind CloudFront.

Why this answer

CloudFront can use an Application Load Balancer (ALB) as a custom origin. This allows you to distribute traffic from a web application running behind an ALB, enabling dynamic content delivery with CloudFront's edge caching and HTTPS termination.

Exam trap

The trap here is that candidates often assume CloudFront origins are limited to S3 buckets, but the service supports a wide variety of custom origins, including ALBs, EC2 instances, and external HTTP servers.

61
MCQeasy

A SysOps administrator needs to monitor network traffic to and from an EC2 instance for troubleshooting. Which AWS feature captures IP traffic information at the VPC level?

A.VPC Flow Logs
B.Amazon CloudWatch Logs
C.AWS CloudTrail
D.AWS Config
AnswerA

VPC Flow Logs capture IP traffic metadata at the elastic network interface level, including source/destination IP addresses, ports, protocol, and action (accept or reject) for each packet. This data is published to Amazon CloudWatch Logs or Amazon S3, enabling administrators to monitor traffic patterns, troubleshoot connectivity issues, and analyze security groups or network ACL behavior. Unlike logging services, VPC Flow Logs are the native AWS mechanism specifically for network traffic monitoring.

Why this answer

VPC Flow Logs capture IP traffic information for network interfaces within a VPC, including source/destination IPs, ports, protocols, and packet accept/reject decisions. This feature operates at the VPC level and is specifically designed for network traffic monitoring and troubleshooting, making it the correct choice for capturing IP traffic information to and from an EC2 instance.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs with CloudWatch Logs or CloudTrail, mistakenly thinking that CloudTrail captures network traffic or that CloudWatch Logs is the primary service for network monitoring, when in fact VPC Flow Logs are the dedicated feature for IP traffic capture at the VPC level.

How to eliminate wrong answers

Option B (Amazon CloudWatch Logs) is wrong because it is a service for storing, monitoring, and accessing log files from AWS resources, but it does not natively capture IP traffic information at the VPC level; it can only store VPC Flow Logs if they are published to it, but it is not the feature that captures the traffic. Option C (AWS CloudTrail) is wrong because it records API activity and user actions within your AWS account, not network traffic or IP packet-level information at the VPC level. Option D (AWS Config) is wrong because it evaluates and records configuration changes to AWS resources, providing compliance and resource inventory, but it does not capture IP traffic data.

62
MCQmedium

Users are intermittently reporting 502 Bad Gateway errors when accessing the application through an Application Load Balancer. The team needs to identify which target IPs are associated with the failures and the request processing time for those requests. Application logs on instances do not capture failures before the ALB connection. What should be enabled?

A.Enable ALB access logs, specify an S3 bucket destination, and query the logs to filter on elb_status_code=502
B.Enable AWS X-Ray on the ALB to trace each request end-to-end from client to target
C.Configure a VPC Flow Log on the subnets containing the ALB to capture all network traffic
D.Install an agent on the application instances that logs all incoming connection attempts from the ALB
AnswerA

Access logs capture every ALB request including 502s. Each log entry contains the target_ip:target_port field identifying which instance handled (or failed to handle) the request, and request_processing_time and target_processing_time values for performance analysis. This data is available without any changes to instance-side software.

Why this answer

ALB access logs capture detailed information about each request, including the target IP address, request processing time, and the HTTP status code returned by the ALB. By enabling these logs and querying for `elb_status_code=502`, you can identify which target IPs were associated with the failures and the `request_processing_time` for those requests. This directly addresses the need to correlate failures with specific targets and timing, without relying on application instance logs that miss pre-connection failures.

Exam trap

The trap here is that candidates often confuse ALB access logs with VPC Flow Logs or X-Ray, assuming any logging mechanism that captures network traffic or traces will include HTTP-level details like status codes and request processing times, but only ALB access logs provide the specific fields needed to correlate 502 errors with target IPs and timing.

How to eliminate wrong answers

Option B is wrong because AWS X-Ray traces requests end-to-end, but it requires the application to be instrumented with the X-Ray SDK and does not capture failures that occur before the ALB establishes a connection to the target (e.g., connection timeouts or TLS handshake failures that result in a 502). Option C is wrong because VPC Flow Logs capture metadata about network traffic (source/destination IP, ports, protocol, and packet counts) but do not include HTTP status codes, request processing times, or ALB-specific error codes like 502. Option D is wrong because installing an agent on the application instances would only log connection attempts that reach the instance; it would not capture failures that occur before the ALB successfully connects to the target (e.g., connection refused or health check failures), which are the very failures causing the 502 errors.

63
Multi-Selectmedium

A company has a VPC with a public subnet and a private subnet. The private subnet hosts a database. Which TWO components are required to allow an EC2 instance in the public subnet to connect to the database?

Select 2 answers
A.A NAT Gateway in the public subnet.
B.A network ACL rule on the private subnet allowing inbound traffic from the public subnet CIDR.
C.An Internet Gateway attached to the VPC.
D.A VPC Endpoint for the database service.
E.A security group rule on the database allowing inbound traffic from the EC2 instance's security group.
AnswersB, E

Network ACLs are stateless and operate at the subnet boundary. To allow an EC2 instance in the public subnet to reach a database in the private subnet, the private subnet's NACL must have an inbound rule permitting traffic from the public subnet's CIDR on the database's port. Because NACLs are stateless, you also need a corresponding outbound rule on the private subnet NACL to allow the return traffic back to the EC2 instance, and reciprocal inbound/outbound rules on the public subnet NACL if it has restrictive rules.

Why this answer

A security group rule on the database allowing inbound traffic from the EC2 instance's security group (Option E) is required because security groups act as a virtual firewall at the instance level, and by default they deny all inbound traffic. A network ACL rule on the private subnet allowing inbound traffic from the public subnet CIDR (Option B) is also required because network ACLs are stateless and control traffic at the subnet boundary; without an inbound allow rule, traffic from the public subnet would be dropped by the private subnet's ACL.

Exam trap

The trap here is that candidates often confuse the purpose of a NAT Gateway (outbound internet) with the need for subnet-to-subnet traffic, or they assume an Internet Gateway is required for any cross-subnet communication within a VPC.

64
MCQmedium

A company has a VPC with public and private subnets. An EC2 instance in a private subnet needs to download software patches from the internet. Which component should be used to provide internet access to the instance?

A.NAT Gateway in a public subnet
B.AWS Site-to-Site VPN
C.Internet Gateway attached to the VPC
D.VPC Endpoint for Amazon S3
AnswerA

A NAT Gateway is a fully managed service that enables instances in private subnets to initiate outbound IPv4 traffic to the internet while preventing inbound connections from the internet. It must be deployed in a public subnet with a route table entry in each private subnet pointing 0.0.0.0/0 to the NAT Gateway's network interface. This is the correct solution because it provides reliable, scalable outbound internet access without assigning public IPs to private instances, and it automatically handles connection tracking and dynamic scaling.

Why this answer

A NAT Gateway in a public subnet allows EC2 instances in private subnets to initiate outbound traffic to the internet (e.g., to download patches) while preventing unsolicited inbound connections. The NAT Gateway uses an Elastic IP and routes traffic from the private subnet through the internet gateway attached to the VPC, translating the private IP to the public IP of the NAT Gateway.

Exam trap

The trap here is that candidates often confuse an Internet Gateway with a NAT Gateway, assuming the IGW can be used directly by private instances, but the IGW requires a public IP on the instance and a route to 0.0.0.0/0 via the IGW, which is only possible from a public subnet.

How to eliminate wrong answers

Option B is wrong because an AWS Site-to-Site VPN connects your VPC to an on-premises network over the internet, but it does not provide direct internet access to instances in a private subnet; it only extends your corporate network. Option C is wrong because an Internet Gateway attached to the VPC provides internet access only to resources in public subnets (with a route table entry pointing to the IGW); a private subnet cannot use the IGW directly without a NAT device. Option D is wrong because a VPC Endpoint for Amazon S3 provides private connectivity to S3 over the AWS network, not general internet access for downloading patches from arbitrary internet hosts.

65
MCQmedium

A company has an Amazon VPC with public and private subnets across two Availability Zones. The company hosts a web application on EC2 instances in the private subnets. The application needs to access an Amazon S3 bucket to upload and download files. The SysOps administrator must ensure that traffic to S3 does not traverse the internet and minimizes data transfer costs. Which solution should the administrator implement?

A.Create an S3 VPC Gateway Endpoint in the VPC and associate it with the route tables of the private subnets.
B.Create an S3 VPC Interface Endpoint in the VPC and associate it with the security groups of the private subnets.
C.Set up a NAT Gateway in the public subnets and add a route to the private subnets' route tables pointing to the NAT Gateway for S3 traffic.
D.Use AWS PrivateLink with an S3 endpoint service hosted in a different VPC.
AnswerA

Gateway Endpoints provide private connectivity to S3 at no additional cost (only standard data transfer rates apply). By adding a route for the S3 prefix list to the private subnet route tables, traffic destined for S3 is routed through the endpoint.

Why this answer

An S3 VPC Gateway Endpoint provides a private, cost-effective connection to S3 from within the VPC without traversing the internet. By associating the endpoint with the route tables of the private subnets, traffic destined for S3 is routed directly through AWS's internal network, avoiding data transfer costs and internet egress charges.

Exam trap

The trap here is that candidates often confuse Gateway Endpoints with Interface Endpoints, assuming both are equally suitable for S3, but Gateway Endpoints are free and optimized for S3 and DynamoDB, while Interface Endpoints incur costs and are better for other AWS services.

How to eliminate wrong answers

Option B is wrong because an S3 VPC Interface Endpoint uses AWS PrivateLink with an elastic network interface, incurring per-hour and per-GB data processing costs, which is more expensive than a Gateway Endpoint and unnecessary for S3 access. Option C is wrong because a NAT Gateway routes traffic through the internet to reach S3, incurring data transfer costs and internet egress charges, violating the requirement to avoid internet traversal. Option D is wrong because AWS PrivateLink with an S3 endpoint service hosted in a different VPC is not a standard or supported method for accessing S3; S3 Gateway Endpoints are designed for direct VPC-to-S3 connectivity without cross-VPC complexity.

66
MCQhard

A company uses AWS Global Accelerator to improve the performance of a web application hosted in multiple AWS regions. The application uses an Application Load Balancer (ALB) in each region as the endpoint. Users report that traffic is not being routed to the closest region. What could be the cause?

A.The Global Accelerator is not configured with a custom routing accelerator.
B.The ALBs are not configured to allow cross-region communication.
C.The health checks for the ALBs are failing, so traffic is diverted to other regions.
D.The endpoints are configured in the same AWS region.
AnswerC

Global Accelerator continuously performs TCP or HTTP(S) health checks against each endpoint in an endpoint group, using the configured interval, thresholds, and path. When an ALB fails these checks consecutively, it is marked unhealthy and Global Accelerator immediately excludes it from traffic routing, redistributing the load to other healthy endpoint groups, often in different regions. This is exactly the behavior described in the scenario, so the failing health checks are the root cause of the traffic being diverted.

Why this answer

Global Accelerator uses health checks to determine endpoint availability. If the health checks for an ALB in a user's closest region are failing, Global Accelerator will consider that endpoint unhealthy and route traffic to the next closest healthy region. This causes users to be directed to a region farther away, even though a closer region exists.

Exam trap

The trap here is that candidates often overlook the impact of health checks on routing decisions and assume the issue is a misconfiguration of the accelerator or endpoints, rather than a failure in endpoint health monitoring.

How to eliminate wrong answers

Option A is wrong because custom routing accelerators are used for specific use cases like gaming or VoIP where you need to control traffic routing per client, not for standard HTTP/HTTPS traffic to ALBs; the default routing accelerator is appropriate here. Option B is wrong because ALBs do not need cross-region communication for Global Accelerator to route traffic to the closest region; Global Accelerator itself handles cross-region routing independently of ALB configuration. Option D is wrong because if all endpoints were in the same region, traffic would still be routed to that region, not to a different one, and the reported issue is traffic not going to the closest region, which implies multiple regions are configured.

67
MCQmedium

A company runs a web application on Amazon EC2 instances in private subnets across multiple Availability Zones. The instances need to download software patches from the internet. The SysOps administrator requires a highly available, fully managed solution for outbound internet connectivity. Which solution should be implemented?

A.Deploy a NAT gateway in each Availability Zone and update the route tables for each private subnet to point to the NAT gateway in the same Availability Zone.
B.Attach an Internet Gateway to the VPC and add a default route (0.0.0.0/0) to the Internet Gateway in the private subnet route tables.
C.Create a VPC endpoint for Amazon S3 and route traffic through it.
D.Set up an AWS Direct Connect connection and route all internet-bound traffic through it.
AnswerA

Deploying a NAT gateway in each Availability Zone and updating the private subnet route tables to point to the local NAT gateway is the correct pattern for highly available outbound internet access. Each NAT gateway is itself a managed, redundant resource within an AZ, and by pairing it with the private subnets in that same AZ, traffic from instances in one AZ keeps working even if another AZ fails. Crucially, NAT gateways are not a single point of failure, unlike a single NAT instance, and they automatically receive a public IP and can route traffic to the internet without requiring the private instances to have public IPs. This design satisfies both the availability requirement and the need for private instances to reach the internet for patch downloads.

Why this answer

A NAT gateway in each Availability Zone provides highly available outbound internet connectivity for instances in private subnets. By placing a NAT gateway in each AZ and routing private subnet traffic to the NAT gateway in the same AZ, you eliminate a single point of failure and ensure that internet-bound traffic remains within the same AZ for low latency and fault tolerance. This is a fully managed AWS service that handles scaling and failover automatically.

Exam trap

The trap here is that candidates often confuse NAT gateways with Internet Gateways, thinking that a single NAT gateway in one AZ provides high availability, but the correct design requires a NAT gateway in each AZ to avoid cross-AZ data transfer costs and single points of failure.

How to eliminate wrong answers

Option B is wrong because attaching an Internet Gateway to the VPC and adding a default route to it in private subnet route tables would allow direct outbound traffic from private instances, but private subnets do not have a route to the Internet Gateway by design; instances in private subnets cannot reach the Internet Gateway directly without a NAT device or a transit gateway. Option C is wrong because a VPC endpoint for Amazon S3 only provides private connectivity to S3, not general internet access for downloading software patches from arbitrary internet hosts. Option D is wrong because AWS Direct Connect is a dedicated private connection to AWS, not a solution for outbound internet connectivity; it does not provide a route to the public internet unless combined with a NAT device or a virtual private gateway with internet access.

68
Multi-Selecthard

Which THREE components are required to set up a site-to-site VPN connection between an on-premises network and an AWS VPC? (Choose three.)

Select 3 answers
A.Virtual private gateway
B.Internet gateway
C.VPN connection
D.Customer gateway
E.Direct Connect virtual interface
AnswersA, C, D

The virtual private gateway is the AWS-side VPN concentrator attached to the VPC; it terminates the two IPSec tunnels from the customer gateway. Without it, no site-to-site VPN endpoint exists on the AWS side, so the connection cannot be established.

Why this answer

A site-to-site VPN between on-premises and AWS requires a virtual private gateway (A), which is the AWS-side VPN concentrator attached to the VPC and terminating the IPSec tunnels; a customer gateway (D), which is the AWS resource representing the on-premises VPN device (its public IP and BGP ASN) that terminates the other end of the tunnels; and a VPN connection (C), which is the actual IPSec tunnel resource linking the virtual private gateway to the customer gateway and carrying traffic between the two networks. An internet gateway (B) is not required for this design because it provides internet access for public subnets, not the encrypted VPN termination, and a Direct Connect virtual interface (E) belongs to AWS Direct Connect private/public transit VIFs, which are a separate dedicated-connection service rather than an IPSec site-to-site VPN component.

Exam trap

The trap here is that candidates confuse an internet gateway with a virtual private gateway, thinking any gateway can serve as a VPN endpoint, but only the VGW supports IPsec termination and route propagation for site-to-site VPNs.

69
MCQeasy

EC2 instances in private subnets need to access S3 buckets. Currently the instances use a NAT Gateway to reach S3 over the internet. The team wants to keep S3 traffic private (within the AWS network) and reduce NAT Gateway data processing costs. What is the correct solution?

A.Create an S3 Gateway VPC endpoint and add it to the private subnet's route table; S3 traffic will bypass the NAT Gateway
B.Create an S3 Interface VPC endpoint in the private subnet to route S3 traffic privately
C.Add a route in the private subnet's route table directing all traffic (0.0.0.0/0) to an Internet Gateway
D.Use S3 Transfer Acceleration to route traffic over AWS edge locations instead of NAT
AnswerA

After the Gateway endpoint is created and the route table updated, the AWS networking layer automatically routes S3 API calls from instances in those subnets through the private endpoint path. The NAT Gateway processes zero S3 bytes, eliminating the per-GB data processing cost for S3 traffic. No code changes are required.

Why this answer

An S3 Gateway VPC endpoint allows EC2 instances in private subnets to access S3 privately using AWS’s internal network, bypassing the NAT Gateway entirely. This eliminates NAT data processing costs and keeps traffic within the AWS backbone, as the endpoint is added to the private subnet’s route table with a prefix list for S3, directing traffic directly to S3 without internet routing.

Exam trap

The trap here is that candidates confuse Gateway VPC endpoints with Interface VPC endpoints, assuming both incur costs, but S3 Gateway endpoints are free and designed specifically for S3 and DynamoDB, while Interface endpoints are for other AWS services and have associated charges.

How to eliminate wrong answers

Option B is wrong because an S3 Interface VPC endpoint uses AWS PrivateLink with an elastic network interface in the subnet, incurring hourly charges and per-GB data processing costs, which does not reduce costs compared to a NAT Gateway and is unnecessary for S3 access when a Gateway endpoint (free of charge) is available. Option C is wrong because adding a route directing all traffic (0.0.0.0/0) to an Internet Gateway would expose private instances directly to the internet, violating security requirements and not keeping traffic private within AWS. Option D is wrong because S3 Transfer Acceleration uses AWS edge locations and the public internet to speed up uploads, but it does not keep traffic private within the AWS network and still requires internet connectivity, failing to reduce NAT Gateway costs.

70
MCQmedium

A SysOps administrator needs to ensure that all traffic to an Amazon S3 bucket is encrypted in transit. Which configuration should be used?

A.Use Amazon CloudFront with the S3 bucket as origin and require HTTPS.
B.Create a VPC endpoint for S3 and route all traffic through it.
C.Enable default encryption on the S3 bucket.
D.Add a bucket policy that denies requests where aws:SecureTransport is false.
AnswerD

This bucket policy explicitly denies any request for which the aws:SecureTransport condition is false, meaning the request was not made over HTTPS or TLS. Because a deny in an identity-based or bucket policy overrides any allows, every request must present a valid TLS connection or it will be rejected. This enforces encryption in transit at the S3 bucket level for all clients, including those using the public endpoint, and is the standard method for ensuring HTTPS-only access.

Why this answer

A bucket policy that denies requests where the aws:SecureTransport condition key is false enforces encryption in transit at the S3 API layer, rejecting any HTTP (non-TLS) request regardless of client. This is the canonical AWS-documented method for requiring TLS on an S3 bucket.

Exam trap

SOA-C02 often tests whether candidates confuse encryption at rest (default encryption, SSE) with encryption in transit (aws:SecureTransport deny policy) — the question wording 'in transit' is the discriminator.

How to eliminate wrong answers

Option A is wrong because CloudFront only encrypts traffic between the viewer and CloudFront; the origin fetch to S3 can still be HTTP unless separately enforced, and it does not prevent direct S3 access over HTTP. Option B is wrong because a VPC endpoint (Gateway or Interface) keeps traffic on the AWS backbone but does not itself require TLS — HTTP requests over the endpoint are still possible. Option C is wrong because default encryption (SSE-S3, SSE-KMS, or DSSE-KMS) protects data at rest, not in transit, so it does nothing for the requirement.

71
MCQhard

A company has a VPC with a CIDR of 10.0.0.0/16. They have two subnets: subnet-A (10.0.1.0/24) and subnet-B (10.0.2.0/24). An EC2 instance in subnet-A needs to send traffic to an EC2 instance in subnet-B. Both instances are in the same VPC and have appropriate security group rules. However, traffic is not reaching the destination. What is the MOST likely cause?

A.The route table for subnet-A does not have a route for subnet-B's CIDR.
B.The network ACL associated with subnet-B is denying inbound traffic from subnet-A.
C.The security group on the destination instance does not allow inbound traffic from the source instance.
D.The VPC peering connection is not established between the two subnets.
AnswerB

Network ACLs operate at the subnet boundary and are stateless, meaning both inbound and outbound rules must be evaluated independently. If subnet-B's inbound NACL rules lack an allow rule for traffic from subnet-A's CIDR, the traffic is implicitly denied even if security groups permit it. Since NACLs are enforced before traffic reaches the instance, this would block communication even with appropriate security group rules.

Why this answer

Network ACLs are stateless and must explicitly allow both inbound and outbound traffic for each subnet. If the NACL on subnet-B denies inbound traffic from subnet-A's CIDR (10.0.1.0/24), the packets will be dropped even though security groups allow them. Since the instances are in the same VPC, the default route table includes a local route for the entire VPC CIDR (10.0.0.0/16), so routing is not the issue.

Security groups are stateful and already allow the traffic per the scenario.

Exam trap

SOA-C02 often tests the misconception that security groups are the only access control for EC2 instances, causing candidates to overlook stateless NACLs that can block traffic even when security groups allow it.

How to eliminate wrong answers

Option A is wrong because the default route table for a VPC automatically includes a local route for the VPC CIDR (10.0.0.0/16), which covers both subnets, so no additional route is needed for intra-VPC traffic. Option C is wrong because the scenario states that both instances have appropriate security group rules, so the security group is not the cause. Option D is wrong because VPC peering is used between VPCs, not between subnets within the same VPC; subnets in the same VPC communicate via the local route by default.

72
Multi-Selecteasy

A SysOps administrator needs to ensure high availability for a web application running on EC2 instances across multiple Availability Zones. Which TWO actions should the administrator take?

Select 2 answers
A.Launch EC2 instances in at least two different Availability Zones.
B.Place a CloudFront distribution in front of the instances.
C.Launch all EC2 instances in a single Availability Zone for consistency.
D.Register the instances with an Application Load Balancer that has health checks enabled.
E.Attach an EBS volume to each instance and replicate data in real-time.
AnswersA, D

Spreading instances across two or more Availability Zones ensures an outage affecting one data centre does not take down the whole application, directly satisfying the multi-AZ high-availability constraint. Each AZ has independent power, cooling and networking, so a single-zone failure leaves capacity running elsewhere.

Why this answer

Option A is correct because distributing EC2 instances across at least two Availability Zones ensures the application survives the failure of a single AZ, which is the foundation of high availability in AWS. Option D is correct because an Application Load Balancer with health checks automatically detects unhealthy instances and routes traffic only to healthy targets across those AZs, maintaining availability during instance or AZ failures. Option B is not correct because CloudFront is a CDN that caches content at edge locations; it improves latency and offloads origin traffic but does not by itself provide multi-AZ failover for EC2 compute.

Option C is not correct because concentrating all instances in one AZ creates a single point of failure, directly contradicting the high-availability requirement. Option E is not correct because EBS volumes are tied to a single AZ and cannot be attached across AZs, and real-time replication of EBS is not how EC2-level high availability is achieved.

Exam trap

SOA-C02 often tests the confusion between content delivery (CloudFront) and high availability, or between data replication (EBS) and compute redundancy, causing candidates to select options that do not address AZ-level fault tolerance.

73
MCQmedium

A company has deployed an Application Load Balancer (ALB) in a VPC. The ALB is configured with a target group pointing to EC2 instances in a private subnet. Clients receive HTTP 503 errors. What is the likely cause?

A.The ALB does not have an Elastic IP address.
B.The security group for the ALB does not allow inbound HTTP traffic.
C.The target instances are unhealthy and the target group has zero healthy hosts.
D.The route table for the private subnet does not have a route to the ALB.
AnswerC

A 503 Service Unavailable response is returned by the ALB when its target group contains zero healthy hosts, meaning all registered target instances have failed their configured health checks. The ALB cannot forward the request to any instance, so it returns 503 to the client. This is the only condition among the options that directly explains the error, as it happens at the ALB's request-routing layer after the listener accepts the traffic.

Why this answer

HTTP 503 errors from an Application Load Balancer indicate that the target group has no healthy registered targets to forward traffic to. When all EC2 instances in the target group are unhealthy (e.g., failing health checks), the ALB cannot route requests, resulting in a 503 response. This is the most common cause of 503 errors in ALB deployments.

Exam trap

The trap here is that candidates often confuse HTTP 503 (service unavailable due to no healthy targets) with HTTP 504 (gateway timeout) or assume the issue is with the ALB's own configuration, such as security groups or IP addressing, rather than focusing on the health of the target instances.

How to eliminate wrong answers

Option A is wrong because ALBs do not require Elastic IP addresses; they are internet-facing or internal and use DNS names, not static IPs. Option B is wrong because the security group for the ALB controls inbound traffic to the ALB itself, but HTTP 503 errors occur after the ALB accepts the request and fails to find healthy targets; if inbound HTTP were blocked, clients would receive a 504 or timeout, not a 503. Option D is wrong because the route table for the private subnet does not need a route to the ALB; the ALB communicates with targets via their private IPs within the VPC, and traffic flows through the VPC's internal routing, not via a route to the ALB.

74
MCQhard

A company has a VPC with public and private subnets. The private subnets host application servers that need to make outbound HTTPS connections to the internet. The SysOps administrator must implement a solution that provides outbound internet connectivity while preventing inbound connections from the internet. Additionally, the solution must allow the company to control which domains the application servers can access. Which solution should the administrator implement?

A.Configure a NAT Gateway and use security group outbound rules to restrict destinations.
B.Configure a NAT instance with proxy software and use route tables to direct traffic from private subnets to the NAT instance.
C.Configure an egress-only Internet Gateway and route private subnet traffic to it.
D.Configure a VPC endpoint for HTTPS and route private subnet traffic to it.
AnswerB

A NAT instance is an Amazon EC2 instance that performs source network address translation for instances in private subnets, and it can be configured with proxy software such as Squid to enable domain-level access control. By running a proxy, the NAT instance can terminate HTTP/HTTPS requests, inspect the requested DNS names, and apply allow/deny policies based on those names—something security groups and NAT Gateways cannot do. You direct traffic from private subnets to the NAT instance by adding a route in the private route tables that points 0.0.0.0/0 to the instance ID; the proxy software then provides the required domain filtering while still blocking unsolicited inbound connections.

Why this answer

A NAT instance with proxy software (e.g., Squid) allows outbound HTTPS connections from private subnets while blocking inbound connections, and the proxy software can enforce domain-level access control via allow/deny lists. This meets the requirement to restrict which domains the application servers can access, which a standard NAT Gateway cannot do because it only translates IP addresses and cannot filter by domain name.

Exam trap

The trap here is that candidates often assume a NAT Gateway with security group rules can control domain access, but security groups cannot filter by domain name—only by IP address—so the proxy-based NAT instance is required for domain-level restriction.

How to eliminate wrong answers

Option A is wrong because a NAT Gateway translates private IPs to a public IP for outbound traffic, but security group outbound rules can only filter by IP address or CIDR, not by domain name, so it cannot control which domains are accessed. Option C is wrong because an egress-only Internet Gateway is used for IPv6 traffic only, and the question does not specify IPv6; it also cannot filter by domain. Option D is wrong because a VPC endpoint for HTTPS (e.g., interface endpoint) provides private connectivity to specific AWS services (like S3 or DynamoDB) via AWS PrivateLink, not general internet access, and cannot route traffic to arbitrary internet domains.

75
MCQhard

A company has a VPC with public and private subnets in two Availability Zones. An Application Load Balancer (ALB) in the public subnets routes traffic to EC2 instances in the private subnets. The EC2 instances need to access the internet for software updates. Which solution is MOST secure and cost-effective?

A.Deploy a NAT Gateway in a public subnet and add a route in the private subnet route tables pointing 0.0.0.0/0 to the NAT Gateway.
B.Set up a VPN connection to an on-premises network and route internet traffic through it.
C.Assign public IP addresses to the EC2 instances and route traffic directly.
D.Attach an internet gateway to the private subnets and route 0.0.0.0/0 to it.
AnswerA

A NAT Gateway is a managed service placed in a public subnet with an Elastic IP, and by adding a route for 0.0.0.0/0 in the private subnet route tables that targets the NAT Gateway, instances receive outbound internet access for tasks like software updates while remaining completely unreachable from the internet. This is the secure and correct design because the NAT Gateway performs stateful address translation, only allowing responses to initiated outbound connections, and it scales automatically without requiring you to manage a separate instance.

Why this answer

A NAT Gateway in a public subnet allows EC2 instances in private subnets to initiate outbound connections to the internet (e.g., for software updates) while preventing inbound connections from the internet. This is the most secure and cost-effective solution because it uses a managed AWS service that scales automatically and incurs charges only for usage and hourly uptime, avoiding the need for a bastion host or VPN.

Exam trap

The trap here is that candidates often confuse NAT Gateways with Internet Gateways, assuming an IGW can be attached to private subnets, or they overlook that assigning public IPs to private instances breaks the subnet's isolation and security model.

How to eliminate wrong answers

Option B is wrong because routing internet traffic through a VPN to an on-premises network adds unnecessary latency, complexity, and cost (e.g., VPN connection charges, bandwidth costs) and is not designed for general internet access—it is intended for hybrid connectivity. Option C is wrong because assigning public IP addresses to EC2 instances in private subnets exposes them directly to the internet, violating the security principle of private subnets and increasing the attack surface; it also requires managing Elastic IPs and security groups. Option D is wrong because an internet gateway (IGW) cannot be attached to private subnets—IGWs are attached to VPCs and route traffic only from subnets with route tables pointing to the IGW; attaching an IGW to a private subnet would require making the subnet public, defeating its purpose.

Page 1 of 3 · 193 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Soa Networking Cdn questions.

CCNA Soa Networking Cdn Questions — Page 1 of 3 | Courseiva