CV0-004 Troubleshooting Practice Question
A cloud administrator is troubleshooting a network connectivity issue between two VPCs connected via a VPC peering connection. The administrator has verified that the route tables are correct and that the security groups allow traffic. However, instances in VPC A cannot ping instances in VPC B. Which TWO of the following could be causing the issue? (Choose TWO.)
⚠ Common exam trap
CV0-004 often tests the layered nature of cloud networking — candidates fixate on route tables and security groups and forget that network ACLs and host-based firewalls are separate, independent layers that can block traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Network ACLs in VPC B are blocking inbound ICMP
Option A is correct because network ACLs are stateless subnet-level filters that must explicitly allow inbound ICMP (for IPv4, protocol 1, type 8 echo request) and outbound ICMP echo reply (type 0); even though the administrator verified security groups, a restrictive NACL in VPC B would silently drop ping traffic. Option C is correct because a host-based firewall (e.g., iptables, Windows Firewall, or firewalld) running on the target instance operates above the VPC layer and can block ICMP echo requests regardless of correct route tables and security group rules. Option B is not correct because the scenario states security groups already allow traffic, and security groups are stateful, so inbound ICMP would be permitted if configured. Option D is not correct because VPC peering fully supports ICMP traffic between peered VPCs; it is not a protocol limitation. Option E is not correct because the administrator has already verified that the route tables are correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Network ACLs in VPC B are blocking inbound ICMP
Why this is correct
Network ACLs are stateless subnet-level filters separate from security groups. Even with security groups allowing traffic, an inbound rule in VPC B's NACL denying ICMP would silently drop echo requests, explaining why instances in VPC A cannot ping VPC B.
- ✗
Security groups in VPC A are blocking inbound ICMP
Why it's wrong here
The stem confirms security groups already allow the traffic, so inbound ICMP blocking is ruled out. It tempts because security groups are the usual culprit for dropped ping traffic, and would be correct had the administrator not already verified them.
- ✓
Host-based firewall on the target instance is blocking ping
Why this is correct
A host-based firewall such as iptables or Windows Firewall on the target instance can drop inbound ICMP independently of security groups. Since the stem confirms security groups permit traffic, this local filter remains a plausible cause of failed ping between the peered VPCs.
- ✗
VPC peering connection does not support ICMP
Why it's wrong here
VPC peering fully supports ICMP, so this cannot cause the failure. It tempts because ICMP is often blocked by security groups or NACLs, making ping failures look protocol-related; however, peering itself imposes no ICMP restriction, so the real cause lies in network ACLs or DNS resolution.
- ✗
Route tables are misconfigured
Why it's wrong here
The stem explicitly states route tables are already verified as correct, so this contradicts the given facts. It tempts because misconfigured routes are the classic cause of peering failures, and would be the right answer in a scenario where routing had not been checked.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.