AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

An Amazon ECS service runs on AWS Fargate in private subnets using the awsvpc network mode. Tasks continuously restart because health checks fail. Container logs captured in CloudWatch show the message:

ERROR dial tcp: lookup auth.example.com on 169.254.169.253:53: no such host

EC2 instances in a public subnet can reach the same domain, and the VPC already has DNS hostnames and DNS support enabled. Which change will allow the tasks to reach the external endpoint while adding the least additional cost?

  • Create an interface VPC endpoint for auth.example.com and add the endpoint to the service's security group.

  • Enable Auto-assign public IP for the ECS service and place the tasks in a subnet that routes 0.0.0.0/0 to an internet gateway.

  • Switch the service to bridge network mode and mount the host's resolv.conf inside the container.

  • Add a NAT gateway to each private subnet and add a default route to the NAT gateway.

AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot