AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
An engineer tightened the inbound network ACL of a private subnet (10.0.2.0/24) to: 100 ALLOW TCP 8080 10.0.1.0/24 110 DENY ALL 0.0.0.0/0 Outbound rules ALLOW ALL. Web-tier instances in 10.0.0.0/24 can no longer reach application-tier instances in 10.0.2.0/24 on TCP 8080, even though security groups permit the traffic. Which least-privilege change will restore connectivity?
Replace the custom network ACL with the default ACL that ALLOWS all inbound and outbound traffic.
Add a route to the private subnet's route table that sends 10.0.0.0/24 traffic to the internet gateway.
Add a security group rule on the application servers that ALLOWS TCP 8080 from 0.0.0.0/0.
Insert a new inbound network ACL rule 90 that ALLOWS TCP 8080 from 10.0.0.0/24.
Network ACLs are stateless and process rules in ascending order. Traffic from 10.0.0.0/24 destined for TCP 8080 does not match rule 100, so evaluation continues to rule 110, which denies all traffic. Inserting a lower-numbered rule (for example 90) that allows TCP 8080 from 10.0.0.0/24 introduces only the required permission and is reached before the blanket deny, restoring the connection while following least-privilege. Opening the security group to 0.0.0.0/0 or reverting to the default ACL would expose unnecessary traffic. Changing the subnet's route table would not affect traffic that already stays within the VPC.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why are network ACLs stateless?
Open an interactive chat with Bash
What is the role of rule evaluation order in network ACLs?
Open an interactive chat with Bash
How do network ACLs interact with security groups in AWS?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .