Courseiva

SOA-C02 · topic practice

Networking and Content Delivery practice questions

This domain covers VPC design and connectivity, subnet routing, security groups and NACLs, NAT and internet gateways, VPC peering, Transit Gateway, Site-to-Site VPN, Direct Connect, Route 53, and CloudFront. Questions present a connectivity or content-delivery scenario and ask which configuration, service, or troubleshooting step meets the requirement.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Networking and Content Delivery

What the exam tests

What to know about Networking and Content Delivery

Be able to pick the right connectivity service for a scenario and verify route tables, subnet associations, and security rules. The most important thing is knowing when to use NAT, peering, Transit Gateway, VPN, or Direct Connect, and how traffic actually flows.

Choosing NAT Gateway versus NAT instance for private subnet outbound internet access

Selecting VPC peering, Transit Gateway, or PrivateLink for VPC-to-VPC connectivity

Configuring security groups, NACLs, route tables, and subnet associations correctly

Using Direct Connect, Site-to-Site VPN, Route 53, and CloudFront for hybrid and edge delivery

Watch out for

Common Networking and Content Delivery exam traps

  • ▸Assuming VPC peering supports transitive routing; it does not, so a mesh or Transit Gateway is needed for three or more VPCs.
  • ▸Forgetting that security groups are stateful and NACLs are stateless, causing return-traffic rules to be missed.
  • ▸Placing a NAT Gateway in a private subnet or omitting the route table entry, so private instances still lack outbound access.

Practice set

Networking and Content Delivery questions

20 questions · select your answer, then reveal the explanation

A company has deployed a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application's IP addresses are used by a third-party service to allowlist traffic. The EC2 instances are part of an Auto Scaling group that may scale up and down. The SysOps administrator needs to ensure that the third-party service always has the current IP addresses of the ALB without requiring manual updates. Which solution should the administrator implement?

Question 2hardmultiple choice
Review the full subnetting walkthrough →

A company has three VPCs in the same AWS region: VPC A (production), VPC B (development), and VPC C (shared services). The VPCs have overlapping CIDR blocks (e.g., VPC A: 10.0.0.0/16, VPC B: 10.0.0.0/16, VPC C: 10.1.0.0/16). The SysOps administrator needs to enable private IP communication between VPC A and VPC C, and between VPC B and VPC C, but not between VPC A and VPC B. The solution must also support a growing number of VPCs in the future. Which AWS service should be used?

Question 3mediummultiple choice
Review the full subnetting walkthrough →

A company has an Amazon VPC with public and private subnets. The private subnets host database instances that should not have direct internet access. However, the database instances need to download patches from an Amazon S3 bucket. The SysOps administrator needs to enable access to S3 from the private subnets without traversing the internet. Which solution should be used?

A company wants to host a static website using Amazon S3. The website files are stored in an S3 bucket. The SysOps administrator needs to make the website accessible via HTTP. Which action must be performed on the S3 bucket?

Question 5mediummultiple choice
Review the full subnetting walkthrough →

A company has an Application Load Balancer (ALB) that routes traffic to targets in private subnets. The SysOps administrator needs to log detailed information about HTTP requests, including client IP, request path, and response time. Which ALB feature should be enabled?

Question 6easymultiple choice
Review the full subnetting walkthrough →

A SysOps administrator is troubleshooting an issue where an Amazon EC2 instance cannot connect to the internet. The instance is in a public subnet with a route table that has a route to an internet gateway (IGW). The instance has a public IP assigned. What should the administrator check next?

Refer to the exhibit. A SysOps administrator created this S3 bucket policy to allow CloudFront to access objects in the bucket using an origin access identity (OAI). However, users are still receiving 403 Access Denied errors when accessing the CloudFront distribution. What is the most likely cause?

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "AWS": "arn:aws:iam::cloudfront:user/CloudFront Origin Access Identity E1A2B3C4D5E6F7"
      },
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::example-bucket/*"
    }
  ]
}
Question 8hardmultiple choice
Review the full subnetting walkthrough →

Refer to the exhibit. A SysOps administrator is troubleshooting internet connectivity for an EC2 instance in subnet subnet-0a1b2c3d4e5f6g7h8. The instance can reach other instances in the VPC but cannot access the internet. Based on the route table output, what is the most likely cause?

Network Topology
$ aws ec2 describe-route-tablesroute-table-id rtb-0a1b2c3d4e5f6g7h8Refer to the exhibit."RouteTables": ["Associations": ["SubnetId": "subnet-0a1b2c3d4e5f6g7h8","RouteTableAssociationId": "rtbassoc-0a1b2c3d4e5f6g7h8","Main": false],"RouteTableId": "rtb-0a1b2c3d4e5f6g7h8","Routes": ["DestinationCidrBlock": "10.0.0.0/16","GatewayId": "local","Origin": "CreateRouteTable","State": "active"},"DestinationCidrBlock": "0.0.0.0/0","NatGatewayId": "nat-0a1b2c3d4e5f6g7h8","Origin": "CreateRoute",

A SysOps administrator notices that traffic from an Application Load Balancer to EC2 instances is failing intermittently. Security groups for the instances allow traffic from the ALB security group on port 80. The ALB target group health checks are failing. What is the most likely cause?

Question 10hardmultiple choice
Review the full routing breakdown →

A SysOps administrator is troubleshooting connectivity issues between two VPCs in different AWS Regions. Both VPCs are connected via a VPC Peering connection. The main route tables in both VPCs have routes pointing to the peering connection. Security groups allow all traffic. However, an EC2 instance in VPC A cannot ping an EC2 instance in VPC B. What is the most likely cause?

Question 11hardmultiple choice
Review the full routing breakdown →

A SysOps administrator is configuring an Application Load Balancer to route traffic to multiple target groups based on the URL path. The ALB is not routing traffic correctly. Which listener rule configuration should be used to route requests with path /api/* to target group A and all other requests to target group B?

A company is running a critical application on EC2 instances in a VPC. The instances are in an Auto Scaling group across multiple Availability Zones. The application needs to maintain a fixed, private IP address for each instance. Which approach should be used to ensure each instance receives a consistent private IP address?

Question 13mediummultiple choice
Read the full VPN explanation →

A company has a VPC with an IPv4 CIDR block of 10.0.0.0/16. The company wants to connect two subnets: one in the VPC (10.0.1.0/24) and one in an on-premises network (192.168.1.0/24) via a Site-to-Site VPN. The VPN connection is established. However, instances in the VPC subnet cannot ping the on-premises server at 192.168.1.10. What is a possible cause?

Question 14hardmultiple choice
Review the full subnetting walkthrough →

A company has a VPC with multiple subnets across two Availability Zones. The company wants to set up a Network Load Balancer (NLB) to handle TCP traffic to a fleet of EC2 instances. The instances are in private subnets. Which configuration is necessary to ensure the NLB can route traffic to the instances?

Question 15mediummultiple choice
Study the full ACL explanation →

A SysOps administrator is troubleshooting connectivity issues between two VPCs that are peered together. The VPCs are in the same AWS region. An EC2 instance in VPC A (10.0.1.0/24) cannot ping an EC2 instance in VPC B (10.0.2.0/24). Both VPCs have route tables that include the CIDR of the other VPC with the peering connection as the target. The security groups and network ACLs allow all inbound and outbound traffic. What is the most likely issue?

Question 16hardmultiple choice
Review the full routing breakdown →

A company uses Amazon CloudFront to distribute content to users worldwide. The origin is an Application Load Balancer (ALB) that routes to EC2 instances. The SysOps administrator notices that some users are receiving cached responses even though the content has been updated on the origin. The administrator needs to ensure that users always receive the latest version of the content. What should the administrator do?

Question 17mediummultiple choice
Read the full DNS explanation →

A company has an internal Application Load Balancer (ALB) in a VPC. The ALB is used by an on-premises application via AWS Direct Connect. The on-premises application needs to resolve the ALB's DNS name. The VPC has Route 53 private hosted zone associated with the VPC. The on-premises DNS servers are configured to forward queries for the company's domain to the VPC's Route 53 inbound resolver endpoints. However, the on-premises application cannot resolve the ALB's DNS name. What is the likely cause?

Question 18hardmultiple choice
Read the full NAT/PAT explanation →

A company has a VPC with public and private subnets. A NAT Gateway is in the public subnet, and a private EC2 instance needs to download patches from the internet. The instance can reach the internet after a reboot. Which action should the SysOps administrator take to make the internet access persistent?

A company uses AWS Direct Connect to connect its on-premises data center to a VPC. The connection is redundant with two virtual interfaces (VIFs). Recently, one VIF failed, and the administrator notices that traffic is not automatically failing over. What must be configured to enable automatic failover?

An organization wants to block traffic from specific IP addresses at the edge of the AWS network before it reaches the application. Which service should be used?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Networking and Content Delivery sessions

Start a Networking and Content Delivery only practice session

Every question in these sessions is drawn from the Networking and Content Delivery domain — nothing else.

Related practice questions

Related SOA-C02 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SOA-C02 exam test about Networking and Content Delivery?
Be able to pick the right connectivity service for a scenario and verify route tables, subnet associations, and security rules. The most important thing is knowing when to use NAT, peering, Transit Gateway, VPN, or Direct Connect, and how traffic actually flows.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Networking and Content Delivery questions in a focused session?
Yes — the session launcher on this page draws every question from the Networking and Content Delivery domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SOA-C02 topics?
Use the topic links above to move to related areas, or go back to the SOA-C02 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SOA-C02 exam covers. They are not copied from any real exam or dump site.