AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
After migrating a three-tier web application to a VPC, web servers in a public subnet cannot open MySQL connections to an Amazon RDS instance in a private subnet. All related security groups already allow TCP port 3306. The engineer enables VPC flow logs on the database subnet and sees multiple entries similar to:
The action field in a VPC flow-log record is set to ACCEPT when a packet passes the VPC's stateless and stateful controls and REJECT when it is blocked by a security group, network ACL, or AWS network firewall. Because the engineer has already confirmed that the security groups for both the web servers and the RDS instance allow the connection, the remaining layer inside the VPC data path that can reject the traffic is the subnet's network ACL. Network ACLs are stateless, so they require an explicit inbound rule that allows traffic from the web-server subnet to TCP 3306 and an outbound rule that allows the return traffic. A missing or incorrect NACL rule will cause every packet to be logged with action=REJECT, exactly as observed. Route tables, source/destination checking, and RDS parameter groups do not influence the action field in flow logs for this scenario.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a stateless network ACL in a VPC?
Open an interactive chat with Bash
What does the REJECT action in VPC flow logs indicate?
Open an interactive chat with Bash
How are network ACL rules configured to allow traffic flow in both directions?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .