Skip to content
BytePatterns

SOA-C03 · Domain 5: Networking and Content Delivery · 18% of the exam

Task 5.3: Troubleshoot network connectivity issues.

Finding where packets stop: route tables, network ACLs and security groups, NAT and transit gateways, flow logs and access logs, CloudFront caching problems, VPN and private connectivity, and CloudWatch network monitoring.

Study it

  • Troubleshooting a VPC: Reachability Analyzer, route tables and security rules

    Partly covered by: VPC: Subnets, NAT & Firewalls

  • Reading network logs: flow logs, ELB, AWS WAF and CloudFront logs

    Lesson coming

  • CloudFront caching issues

    Partly covered by: CloudFront & Caching Layers

  • Hybrid and private connectivity issues; CloudWatch network monitoring

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A web server in a public subnet listens on TCP port 443, but clients on the internet time out. For each attempt, the VPC flow logs of the server's network interface show an ACCEPT record for the inbound packets to port 443 and a REJECT record for the server's response packets to the client's port, such as 51544. The security group allows inbound 443 from anywhere and keeps its default outbound rule. What should the team change?

  1. AAdd an outbound security group rule that allows TCP 1024-65535 to 0.0.0.0/0
  2. BAdd an inbound security group rule that allows TCP 1024-65535 from 0.0.0.0/0
  3. CAdd a 0.0.0.0/0 route to the internet gateway in the subnet's route table
  4. DAdd an outbound network ACL rule that allows TCP 1024-65535 to 0.0.0.0/0
Show the answer and why
  • AAdd an outbound security group rule that allows TCP 1024-65535 to 0.0.0.0/0

    Incorrect

    Security groups are stateful, so responses to allowed inbound traffic are allowed anyway, and the default outbound rule already allows all traffic.

  • BAdd an inbound security group rule that allows TCP 1024-65535 from 0.0.0.0/0

    Incorrect

    The inbound request is already accepted. Opening more inbound ports does not let the response leave.

  • CAdd a 0.0.0.0/0 route to the internet gateway in the subnet's route table

    Incorrect

    A REJECT record means the traffic was not allowed by a security group or network ACL, not that a route was missing.

  • DAdd an outbound network ACL rule that allows TCP 1024-65535 to 0.0.0.0/0

    Correct

    Network ACLs are stateless, so response traffic needs its own rule. Allowed inbound traffic whose response is rejected is the pattern AWS describes for a network ACL that lacks the outbound rule.

ACCEPT in, REJECT out on the same flow points to the stateless layer: the network ACL needs an outbound rule for the clients' ephemeral ports.

Question 2 · choose 1

An application instance can no longer connect to an Amazon RDS DB instance on port 5432 in another subnet of the same VPC. Several teams have changed route tables, network ACLs and security groups this week. The operations team wants to find out which component blocks the path by analyzing the configuration, without generating test traffic. What should the team use?

  1. AVPC flow logs on both network interfaces, reviewed after a new connection attempt
  2. BVPC Reachability Analyzer, with a path from the instance to the DB instance on port 5432
  3. CA Traffic Mirroring session that copies the instance's packets to a monitoring appliance
  4. DThe CloudTrail event history for the week's network changes
Show the answer and why
  • AVPC flow logs on both network interfaces, reviewed after a new connection attempt

    Incorrect

    Flow logs record accepted or rejected traffic that actually flows, and a REJECT does not say which security group or network ACL rule caused it.

  • BVPC Reachability Analyzer, with a path from the instance to the DB instance on port 5432

    Correct

    Reachability Analyzer analyzes the configuration between a source and a destination and, when the destination is unreachable, names the blocking component.

  • CA Traffic Mirroring session that copies the instance's packets to a monitoring appliance

    Incorrect

    Traffic Mirroring copies real network traffic for inspection. It needs traffic and does not evaluate the configuration.

  • DThe CloudTrail event history for the week's network changes

    Incorrect

    CloudTrail records who took which action. It does not show whether the resulting configuration blocks this path, or where.

Reachability Analyzer is configuration analysis: it walks route tables, network ACLs, security groups and load balancers and points at the hop that blocks.

Question 3 · choose 1

Product pages are served through an Amazon CloudFront distribution, and the cache hit ratio is below 10%. The cache policy puts all query strings, all cookies and the User-Agent header into the cache key, but the page content depends only on the id query string. The origin still needs to receive the session cookie for its analytics. What should the operations team do?

  1. ACreate an invalidation for the /* path every hour so that the edge caches stay fresh
  2. BLower the minimum, default and maximum TTLs in the cache policy
  3. CKey the cache on id only; send the cookie through an origin request policy
  4. DTurn on CloudFront standard logging for the distribution
Show the answer and why
  • ACreate an invalidation for the /* path every hour so that the edge caches stay fresh

    Incorrect

    Invalidation removes files from the edge caches, which sends even more requests back to the origin.

  • BLower the minimum, default and maximum TTLs in the cache policy

    Incorrect

    Shorter TTLs keep files in the cache for less time, so fewer requests are served from it.

  • CKey the cache on id only; send the cookie through an origin request policy

    Correct

    Fewer values in the cache key raise the chance of a hit, and an origin request policy sends information to the origin without adding it to the cache key.

  • DTurn on CloudFront standard logging for the distribution

    Incorrect

    Access logs record each request for analysis and troubleshooting. They do not change what is cached.

A low hit ratio usually means a fragmented cache key. Keep in the key only what changes the response, and send the rest to the origin through an origin request policy.

Question 4 · choose 2

A VPC is connected to a data center (10.50.0.0/16) through an AWS Site-to-Site VPN connection on a virtual private gateway, and both tunnels are UP. Administrators in the data center cannot open SSH sessions to instances in a private subnet. That subnet's route table has only the local route and a 0.0.0.0/0 route to a NAT gateway, and the instances' security group allows SSH only from the VPC's own CIDR block. Which changes are required? (Choose TWO.)

  1. AAttach an internet gateway to the VPC and route 10.50.0.0/16 to it
  2. BTurn on DNS hostnames for the VPC
  3. CTurn on route propagation from the virtual private gateway on the subnet's route table
  4. DAdd an inbound security group rule that allows SSH from 10.50.0.0/16
  5. EAssociate an Elastic IP address with each of the instances in the private subnet
Show the answer and why
  • AAttach an internet gateway to the VPC and route 10.50.0.0/16 to it

    Incorrect

    The VPN terminates on the virtual private gateway. Routes to the data center must point there, not to an internet gateway.

  • BTurn on DNS hostnames for the VPC

    Incorrect

    DNS attributes affect name resolution inside the VPC. They do not create a route or allow traffic.

  • CTurn on route propagation from the virtual private gateway on the subnet's route table

    Correct

    Traffic from the VPC reaches the customer gateway only if the route table holds the VPN's routes pointing to the virtual private gateway; propagation adds them automatically.

  • DAdd an inbound security group rule that allows SSH from 10.50.0.0/16

    Correct

    To allow access to instances from the remote network, the security group must allow the inbound traffic from that network.

  • EAssociate an Elastic IP address with each of the instances in the private subnet

    Incorrect

    An Elastic IP address is a public address for internet communication. VPN traffic uses the instances' private addresses.

A tunnel that is UP still needs two things on the VPC side: a route to the remote network through the virtual private gateway, and security group rules that let the remote network in.

Practise domain 5 →Practise all domains →