AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

A company runs a two-tier application in a VPC (CIDR 10.20.0.0/16). An internet gateway is attached. Web servers in a private subnet (10.20.101.0/24) need to download OS updates from the internet through a NAT gateway deployed in a public subnet. Security groups and network ACLs allow outbound HTTPS. The web servers still cannot reach the internet. What change will restore connectivity?

  • Add a 0.0.0.0/0 route in the private subnet's route table that targets the NAT gateway ID.

  • Enable auto-assign public IPv4 address on the private subnet and restart the web servers.

  • Create an interface VPC endpoint for Amazon S3 in the private subnet's route table.

  • Add an outbound 0.0.0.0/0 rule to the web servers' security group.

AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot