AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

After applying a custom network ACL to a private subnet that hosts EC2 instances that call external SaaS APIs through a NAT gateway, outbound HTTPS traffic fails. The ACL allows outbound TCP 443 to 0.0.0.0/0 and denies all other outbound traffic. Inbound rules allow TCP 22 from 10.0.0.0/16 and TCP 443 from 0.0.0.0/0, then deny all. Which modification will restore connectivity with least privilege?

  • Add an outbound allow rule for TCP ports 1024-65535 to 0.0.0.0/0.

  • Change the existing outbound rule to allow all protocols to 0.0.0.0/0.

  • Add an inbound allow rule for TCP ports 1024-65535 from 0.0.0.0/0.

  • Replace the outbound rule with UDP port 443 to 0.0.0.0/0.

AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot