AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

After migrating a three-tier web application to a VPC, web servers in a public subnet cannot open MySQL connections to an Amazon RDS instance in a private subnet. All related security groups already allow TCP port 3306. The engineer enables VPC flow logs on the database subnet and sees multiple entries similar to:

10.0.10.15 10.0.20.42 3306 44321 6 64 40 1680567227 1680567287 REJECT OK

Which VPC layer is most likely dropping the traffic, and what should the engineer investigate first?

  • Source/destination check is still enabled on the web server ENIs; disable it so return traffic is forwarded correctly.

  • The route table for the database subnet lacks a local target; add a route that points 10.0.0.0/16 to the local gateway.

  • A stateless network ACL associated with the RDS subnet is denying the connection; inspect and update its inbound and outbound rules.

  • The RDS instance's security group is rejecting the SYN packet; verify and correct its outbound rules.

AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot