AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

EC2 instances in a private subnet are unable to connect to a public API over HTTPS. The private subnet's route table directs 0.0.0.0/0 traffic to a NAT gateway. The instances' security group allows outbound TCP port 443. VPC flow logs on the instances' network interfaces show 'REJECT' entries for inbound traffic on destination ports 1024-65535. Which action will restore connectivity without making the instances publicly accessible?

  • Update the private subnet's network ACL to allow inbound TCP traffic on ports 1024-65535 from 0.0.0.0/0.

  • Attach an internet gateway to the private subnet and add a 0.0.0.0/0 route to it.

  • Add an inbound rule for TCP port 443 to the EC2 instances' security group.

  • Disable source/destination checking on the NAT gateway's elastic network interface.

AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot