AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

An engineer tightened the inbound network ACL of a private subnet (10.0.2.0/24) to: 100 ALLOW TCP 8080 10.0.1.0/24 110 DENY ALL 0.0.0.0/0 Outbound rules ALLOW ALL. Web-tier instances in 10.0.0.0/24 can no longer reach application-tier instances in 10.0.2.0/24 on TCP 8080, even though security groups permit the traffic. Which least-privilege change will restore connectivity?

  • Add a route to the private subnet's route table that sends 10.0.0.0/24 traffic to the internet gateway.

  • Add a security group rule on the application servers that ALLOWS TCP 8080 from 0.0.0.0/0.

  • Insert a new inbound network ACL rule 90 that ALLOWS TCP 8080 from 10.0.0.0/24.

  • Replace the custom network ACL with the default ACL that ALLOWS all inbound and outbound traffic.

AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot