Courseiva
hardMultiple Select

Troubleshoot Database Connectivity in VPC: NACL vs Security Group

A cloud administrator is troubleshooting an application that fails to connect to a database. The application and database are in the same VPC. Which THREE steps should the administrator take to diagnose the issue?

⚠ Common exam trap

CompTIA often tests the distinction between stateful security groups and stateless network ACLs, and candidates mistakenly assume that allowing inbound traffic in the security group alone is sufficient, forgetting that network ACLs must also permit the traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Test connectivity to the database using a telnet or netcat command from the application server.

Option B is correct because using telnet or netcat from the application server to the database endpoint and port is a direct way to test whether the TCP connection is being established or blocked, which immediately narrows down whether the issue is network-level or application-level. Option C is correct because security groups are stateful virtual firewalls, and if the database's security group does not permit inbound traffic from the application's security group on the database port (e.g., 3306 for MySQL, 5432 for PostgreSQL), the connection will be refused or time out. Option E is correct because network ACLs are stateless subnet-level filters, and the database subnet's NACL must allow inbound traffic on the database port (and the corresponding ephemeral return traffic) for the connection to succeed. Option A is not relevant because the application and database are in the same VPC, so no internet route is required for internal communication. Option D is not the best diagnostic step here because the scenario specifies both resources are in the same VPC and the focus is on connectivity to the database; DNS resolution of the endpoint is less likely to be the root cause than security group or NACL misconfiguration, and it is not among the marked correct answers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Check the routing table for a route to the internet.

    Why it's wrong here

    An internet route in the route table is irrelevant when both application and database reside in the same VPC, since that traffic stays on local routes and never traverses an internet gateway. It is tempting because missing routes commonly break connectivity, but the correct checks target security groups, NACLs and subnet-level reachability.

  • ✓

    Test connectivity to the database using a telnet or netcat command from the application server.

    Why this is correct

    Testing with telnet or netcat from the application server isolates whether the database port is reachable across the VPC, distinguishing network or security-group blocking from application-layer faults. It directly satisfies the stem's same-VPC constraint, confirming layer-4 reachability before investigating credentials, driver configuration, or query errors.

  • ✓

    Verify that the security group associated with the database instance allows inbound traffic from the application's security group on the database port.

    Why this is correct

    Security groups are stateful and default-deny inbound, so the database's group must explicitly permit the application's group on the database port. Referencing the application's security group as the source, rather than a CIDR range, satisfies the same-VPC constraint and confirms whether the connection is blocked at the instance level.

  • ✗

    Check the DNS resolution of the database endpoint in the application's subnet.

    Why it's wrong here

    DNS resolution is a valid connectivity check, but the stem asks for three steps and this option duplicates the name-resolution angle rather than addressing the same-VPC path directly; the expected set covers security groups, network ACLs and route tables. It is tempting because unresolvable endpoints genuinely cause failures, yet the question's scope is VPC-internal reachability.

  • ✓

    Verify that the network ACL for the database subnet allows inbound traffic on the database port.

    Why this is correct

    Network ACLs are stateless and evaluated at subnet boundaries, so a rule blocking the database port silently drops traffic even when security groups permit it. Since both resources share a VPC, checking the database subnet's inbound ACL directly satisfies the stem's requirement to diagnose connectivity between the application and database.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.