CV0-004 Troubleshooting Practice Question
A company's application is unable to connect to a managed cloud database. The database is deployed in a VPC with public accessibility disabled. The application runs on an EC2 instance in the same VPC. Which three troubleshooting steps should the administrator take? (Choose three.)
⚠ Common exam trap
CV0-004 often tests the misconception that private intra-VPC connectivity requires an internet gateway or public IP, when in fact security groups, NACLs, and endpoint configuration are the real determinants.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check the network ACL associated with the database subnet for appropriate rules.
Option B is correct because network ACLs are stateless subnet-level firewalls; if the database subnet's NACL lacks an inbound rule allowing the database port (e.g., 3306 for MySQL or 5432 for PostgreSQL) from the EC2 instance's subnet CIDR, and a corresponding outbound rule for the return traffic, connectivity will fail even if security groups are correct. Option C is correct because a misconfigured endpoint (wrong hostname, port, or database name) in the application's connection string is a common cause of connection failures and must be verified before deeper network troubleshooting. Option E is correct because the database's security group must have an inbound rule referencing the EC2 instance's security group (or its CIDR) on the database listener port; since the database is not publicly accessible, this security group reference is the primary stateful access control. Option A is not needed because an internet gateway only enables internet connectivity for public subnets and is irrelevant for instance-to-database traffic within the same VPC. Option D is not needed because a public IP is only required for internet-facing communication, not for private communication between an EC2 instance and a database in the same VPC.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ensure the VPC has an internet gateway attached.
Why it's wrong here
An internet gateway only enables traffic to and from the public internet; the EC2 instance and database communicate privately inside the VPC, so no gateway is involved. It is tempting because internet gateways are a common cause of connectivity failures, and attaching one is correct when resources genuinely require outbound internet access.
- ✓
Check the network ACL associated with the database subnet for appropriate rules.
Why this is correct
Network ACLs are stateless and evaluated per subnet, unlike security groups. The database subnet's ACL must permit inbound traffic on the database port and outbound return traffic to the EC2 subnet's ephemeral range, or packets are dropped before reaching the database.
- ✓
Verify that the database endpoint is correctly configured in the application.
Why this is correct
The application must target the managed database's actual endpoint hostname and port. A stale or mistyped endpoint fails regardless of network path, so confirming the configured endpoint matches the instance's current address is a prerequisite before investigating security groups or network ACLs.
- ✗
Verify that the EC2 instance has a public IP address.
Why it's wrong here
A public IP is irrelevant when both the instance and the database sit in the same VPC and communicate over private addresses; the database's public accessibility is disabled anyway. It is tempting because public IPs commonly explain connectivity failures, and assigning one is correct when an instance must be reached from outside the VPC.
- ✓
Check the security group for the database to ensure it allows inbound traffic from the EC2 instance's security group.
Why this is correct
With public accessibility disabled, traffic must be permitted internally. The database's security group must reference the EC2 instance's security group as an allowed inbound source on the database port; otherwise the connection is silently dropped despite both resources sharing the VPC.
Visual reference
Go deeper
Related to this question
About these practice questions
This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on CV0-004
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company has a three-tier application in a cloud VPC: web servers in a public subnet, application servers in a private subnet, and database servers in a private subnet. The web servers can connect to the application servers, but the application servers cannot connect to the database servers. The security groups are configured as follows: - Web SG: inbound HTTP from 0.0.0.0/0, outbound all - App SG: inbound HTTP from Web SG, outbound all - DB SG: inbound MySQL from App SG, outbound all What is the most likely cause of the connectivity issue?
medium- A.The database security group is missing an inbound rule for MySQL.
- B.The application security group is missing an outbound rule for MySQL.
- ✓ C.The network access control list (NACL) on the database subnet is blocking inbound traffic from the application subnet.
- D.The web security group is blocking traffic to the database.
Why C: The most likely cause is a network ACL (NACL) on the database subnet blocking inbound traffic from the application subnet. Security groups are stateful and allow return traffic, but NACLs are stateless and must explicitly allow both inbound and outbound traffic on ephemeral ports. If the NACL denies inbound MySQL (port 3306) from the app subnet's CIDR, the connection fails even though the security groups are correctly configured.
Variation 2. Refer to the exhibit. An application running on an EC2 instance is failing to connect to an RDS database. What is the most likely issue?
easy- A.The database instance is in a different VPC
- ✓ B.The security group for the RDS instance does not allow inbound traffic from the EC2 instance
- C.The database instance is stopped
- D.The application is using the wrong database port
Why B: The most likely issue is that the security group for the RDS instance does not allow inbound traffic from the EC2 instance. Security groups act as virtual firewalls and must explicitly permit traffic on the database port (e.g., 3306 for MySQL) from the EC2 instance's security group or IP. Even if other configurations are correct, without this rule, the connection will be blocked. This is a common misconfiguration in AWS.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.