Courseiva
Operations and Support →hardMultiple Choice

CV0-004 Operations and Support Practice Question

A cloud engineer is investigating why an application hosted on Amazon EC2 cannot connect to an Amazon RDS for MySQL database in the same VPC. The database security group allows traffic on port 3306 from the application's security group. The engineer confirms the application is using the correct endpoint and credentials. Which action should the engineer take NEXT to identify the cause?

⚠ Common exam trap

The trap here is overlooking that network ACLs are stateless, so the ephemeral return traffic must be explicitly permitted, unlike stateful security group behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify the network ACLs on the database subnet allow inbound and outbound traffic on the required ephemeral ports.

Because the security group already permits the database port from the application's security group, the remaining likely culprit is a stateless network ACL that blocks the request or the ephemeral return traffic. Network ACLs require explicit rules in both directions, unlike stateful security groups. Verifying NACL rules on the database subnet is the correct next step before making any disruptive or risky changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Modify the RDS security group to allow 0.0.0.0/0 on port 3306 to rule out a security group issue.

    Why it's wrong here

    Broadening the security group to the entire internet is a security regression and is unnecessary because the security group already references the application's security group correctly. Security group rules are stateful, so return traffic is automatically allowed once the request is permitted. This change would not diagnose the problem and would expose the database to unnecessary risk.

  • ✓

    Verify the network ACLs on the database subnet allow inbound and outbound traffic on the required ephemeral ports.

    Why this is correct

    Network ACLs are stateless and evaluate inbound and outbound rules separately, so return traffic to the client uses ephemeral ports that must be explicitly allowed on the outbound side. A common cause of a blocked connection, even when security groups permit it, is an NACL that denies the response traffic or the database port. Checking NACLs is the logical next diagnostic step.

  • ✗

    Reboot the RDS instance to clear any stale connection state and retest connectivity.

    Why it's wrong here

    Rebooting the database disrupts service and does not address a networking misconfiguration. If the cause is an NACL or routing issue, a reboot will not resolve it and the connection will still fail, while causing an avoidable outage. Rebooting is a disruptive action that should never precede a targeted network diagnostic when the symptom points to a connectivity path problem.

  • ✗

    Check whether the EC2 instance has a public IP address and attach an Elastic IP to ensure outbound connectivity.

    Why it's wrong here

    Communication within the same VPC uses private IP addresses and does not require a public IP or Elastic IP. Attaching one would not fix an intra-VPC connectivity problem and adds unnecessary exposure. The engineer should focus on the internal network path, including subnets, route tables, and NACLs, rather than public addressing.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.