AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
EC2 instances in a private subnet time-out when using a NAT gateway in a public subnet to reach external HTTPS endpoints. Route tables and security groups are confirmed correct. The subnet's network ACL currently has only these rules: inbound ALLOW TCP 443 from 0.0.0.0/0, then DENY ALL; outbound ALLOW TCP 443 to 0.0.0.0/0, then DENY ALL. What network ACL change will restore connectivity while adhering to AWS best practices?
Move the NAT gateway into the same private subnet as the instances.
Replace the existing inbound rule with ALLOW TCP 80 from 0.0.0.0/0.
Add an outbound rule that allows UDP port 53 to 0.0.0.0/0.
Add an inbound rule that allows TCP ports 1024-65535 from the NAT gateway's CIDR to the subnet.
The NAT gateway translates the source address of each instance connection and returns response traffic to the instances on an ephemeral destination port (1024-65535). Because network ACLs are stateless, return traffic must be explicitly allowed by an inbound rule that covers this port range. Adding an inbound rule that permits TCP 1024-65535 from the NAT gateway's subnet (or 0.0.0.0/0) allows the response packets through and enables the HTTPS sessions to complete. Changing outbound rules, opening port 80, or moving the NAT gateway does not address the blocked return traffic.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a NAT Gateway in AWS?
Open an interactive chat with Bash
Why are ephemeral ports (1024-65535) important in this scenario?
Open an interactive chat with Bash
What does 'network ACLs are stateless' mean?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .