AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

An operations engineer is troubleshooting a Java application running on an EC2 instance in a private subnet that suddenly fails to connect to an Amazon RDS for MySQL database in the same VPC. The instance is attached to security group sg-app, whose only outbound rules allow TCP ports 80 and 443 to 0.0.0.0/0. The database is attached to sg-db, whose inbound rules allow TCP 3306 from sg-app. Network ACLs and route tables already permit all traffic between the subnets. Which change will most effectively restore connectivity while adhering to the principle of least privilege?

  • Associate both the EC2 instance and the database with the default security group.

  • Add an outbound rule to sg-app that allows TCP 3306 with sg-db as the destination.

  • Broaden sg-db's inbound rule to allow TCP 3306 from 0.0.0.0/0.

  • Add an inbound rule to sg-app that allows TCP 3306 from sg-db.

AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot