AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A CloudOps engineer is deploying an application with an Auto Scaling group through AWS CloudFormation. The deployment targets two existing private subnets, each using a /28 CIDR block inside a /16 VPC. During stack creation, several EC2 instance launches fail with the message "Subnet has no available IP addresses" and the stack ultimately rolls back. What is the most appropriate way to remediate this subnet-sizing issue while following AWS best practices?
Change the VPC CIDR block from /16 to /15 so the existing /28 subnets automatically receive more IP addresses without code changes.
Create two new /24 private subnets in the same Availability Zones, update the CloudFormation stack to use the new subnet IDs, and delete the /28 subnets after migration.
Lower the Auto Scaling group desired capacity and maximum size to stay within the current subnets' available IP addresses.
Disable auto-assignment of public IPv4 addresses on the current subnets to free additional private IP space for EC2 instances.
A /28 subnet provides only 11 usable IP addresses after AWS reserves five. Once those addresses are consumed by running instances and ENIs, additional launches fail. Because a subnet's CIDR block cannot be modified after it is created, expanding the VPC CIDR will not resize existing subnets. The recommended fix is to create new, larger subnets (for example, /24) in the same Availability Zones, update the CloudFormation template or parameters so the Auto Scaling group and other resources reference the new subnet IDs, and then remove the exhausted /28 subnets when they are no longer in use. Changing public-IP assignment, adjusting desired capacity, or attempting to resize existing subnets will not eliminate the underlying IP-address exhaustion.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why does AWS reserve five IP addresses in each subnet?
Open an interactive chat with Bash
Can a subnet’s CIDR block be resized after being created?
Open an interactive chat with Bash
What is the difference between a /28 and a /24 subnet in terms of IP addresses?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Deployment, Provisioning, and Automation
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .