SOA-C02 exam dumps

SOA-C02 practice question 276 of 341

AWS Certified SysOps Administrator - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SOA-C02 Question 276

Single answer

You are troubleshooting connectivity issues for an instance in a private subnet within your VPC. The instance needs to access the internet to download application updates. The following configurations are in place:

  1. The instance is in a private subnet with a route table that has a route to a NAT gateway in a public subnet.
  2. The NAT gateway is attached to an Elastic IP.
  3. The security group associated with the instance allows outbound HTTP and HTTPS traffic.
  4. The subnet’s network ACL allows both inbound and outbound HTTP and HTTPS traffic.

Despite these configurations, the instance cannot connect to the internet. What could be the possible reason for this issue?

  1. A

    The route table associated with the NAT gateway does not have a route to the internet gateway.

  2. B

    The security group associated with the NAT gateway does not allow inbound HTTP and HTTPS traffic.

  3. C

    The Elastic IP attached to the NAT gateway is not properly associated.

  4. D

    The network ACL associated with the public subnet blocks outbound traffic to the internet.

Show answer and explanation

Correct answer: A

Explanation

For instances in private subnets to access the internet via a NAT gateway, the public subnet where the NAT gateway resides must have a route table that directs traffic destined for the internet (0.0.0.0/0) to an internet gateway. Without this route, the NAT gateway cannot forward traffic from the private subnet to the internet, causing connectivity issues.

  • A. Correct.

    Correct. The NAT gateway itself relies on the public subnet's route table to reach the internet. If the route table for the public subnet doesn’t have a route to the internet gateway, the NAT gateway cannot forward traffic to the internet.

  • B. Incorrect.

    Incorrect. The NAT gateway does not use security groups. Instead, it relies on the route table and the network ACL of the public subnet for traffic management.

  • C. Incorrect.

    Incorrect. The Elastic IP is already associated with the NAT gateway, as specified in the question. If it were not associated, the NAT gateway would not function at all.

  • D. Incorrect.

    Incorrect. The network ACL associated with the public subnet is not mentioned to block traffic. The issue lies in the route table configuration for the public subnet.

Timed practice exam

Take a SOA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam