AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

An on-premises data center connects to a VPC by a Site-to-Site VPN with two IPSec tunnels. After a firewall firmware upgrade, users can reach the VPC only when Tunnel 2 is active; CloudWatch metrics show TunnelState=Down for Tunnel 1. The VPN logs display repeated Phase 1 failures with the error message "NO_PROPOSAL_CHOSEN." Which firewall change will MOST likely restore stable connectivity through Tunnel 1?

  • Set the firewall's IKE Phase 1 policy to use AES-256 encryption, SHA-256 integrity, and Diffie-Hellman group 14.

  • Change Tunnel 1's inside tunnel CIDR to 169.254.100.0/30 so it differs from Tunnel 2.

  • Enable NAT Traversal (UDP 4500) for both tunnels on the firewall.

  • Lower the Dead Peer Detection (DPD) interval on the firewall from 30 seconds to 10 seconds.

AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot