Courseiva
Troubleshooting →mediumMultiple Select

CV0-004 Troubleshooting Practice Question

A cloud administrator is troubleshooting a connectivity issue between two VPCs in the same region. Which TWO actions should the administrator verify? (Choose two.)

⚠ Common exam trap

CV0-004 often tests the misconception that security groups or IGWs are the first thing to check for VPC-to-VPC connectivity, when in fact peering status and route tables are the prerequisites that must exist before any security control matters.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPC peering connection status

Option A (VPC peering connection status) is correct because a peering connection must be in the 'active' state for traffic to flow between the two VPCs; if it is 'pending-acceptance', 'rejected', or 'deleted', connectivity will fail regardless of routing. Option B (Route table entries) is correct because each VPC's route tables must contain routes pointing the destination CIDR of the peer VPC to the peering connection (pcx-xxxx), and missing or incorrect routes are a common cause of peering failures. Option C (Security group rules) is not the primary check here because security groups are stateful and typically evaluated after routing works, and the question targets VPC-to-VPC connectivity rather than instance-level filtering. Option D (VPN tunnel configuration) does not apply because VPC peering does not use VPN tunnels; VPNs are used for site-to-site or remote-access connections. Option E (Internet gateway attachment) is irrelevant because traffic between peered VPCs in the same region does not traverse an internet gateway.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    VPC peering connection status

    Why this is correct

    VPC peering provides a direct private route between two VPCs, so its connection status must be Active before traffic can flow. A Pending, Rejected or Expired state blocks all routing regardless of route tables or security groups, directly satisfying the stem's same-region VPC-to-VPC connectivity requirement.

  • ✓

    Route table entries

    Why this is correct

    Route table entries determine whether traffic can transit between the peered VPCs, since VPC peering requires explicit routes in each subnet's route table pointing to the peer's CIDR block. Without matching entries, packets lack a next hop and are dropped, directly satisfying the same-region connectivity constraint in the stem.

  • ✗

    Security group rules

    Why it's wrong here

    Security groups are not the first step; they filter traffic but peering connectivity is lower-level.

  • ✗

    VPN tunnel configuration

    Why it's wrong here

    VPN tunnels carry encrypted traffic over the public internet between on-premises networks or remote clients, not between two VPCs in the same region. It is tempting because VPNs do connect private networks, but intra-region VPC-to-VPC traffic uses VPC peering or a transit gateway, so no tunnel configuration applies here.

  • ✗

    Internet gateway attachment

    Why it's wrong here

    An internet gateway only handles traffic entering or leaving the VPC, so it plays no part in private VPC-to-VPC peering paths. It tempts because gateway misconfiguration frequently breaks public connectivity, yet it would be the correct check when instances must reach the internet.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.