38 practice questions for Domain 5 of the AWS Certified CloudOps Engineer - Associate (SOA-C03) exam, which makes up 18% of its scored content. Your answers count towards one score and one timer for the whole exam.
Domain 5: Networking and Content Delivery
138. Instances in a private subnet cannot download operating system updates, and the subnet route table has no route for 0.0.0.0/0. Which solution meets these requirements?
Answer and explanation
Answer: B. A NAT gateway allows outbound-initiated connections while blocking inbound attempts, and the private route table must point default traffic at it. Routing directly to an internet gateway converts the subnet into a public one. Public addresses expose the instances. VPC peering provides no internet path and is not transitive.
139. An interface VPC endpoint must restrict which API actions can be called through it. Which solution meets these requirements?
Answer and explanation
Answer: C. An endpoint policy restricts which principals, actions, and resources may be reached through the endpoint. A security group controls network reachability rather than API actions. A network ACL filters by address and port. Interface endpoints are reached by DNS rather than a route table entry.
140. Traffic between two VPCs attached to the same AWS Transit Gateway is failing, although both attachments show as available. Which cause should the operations team investigate first?
Answer and explanation
Answer: B. An available attachment only means the VPC is connected to the gateway; traffic still requires the attachment to be associated with a route table and the destination CIDR to be propagated into it. Internet gateways govern internet access rather than transit routing. A Direct Connect gateway is unrelated to VPC-to-VPC traffic. Overlapping CIDRs would prevent routing entirely rather than being a requirement.
141. Outbound traffic from instances in three Availability Zones routes through one NAT gateway, and cross-zone data processing charges are significant. Which solution meets these requirements?
Answer and explanation
Answer: B. A NAT gateway per Availability Zone keeps outbound traffic within its own zone, removing cross-zone transfer charges and a single point of failure. A second gateway in the same zone does not change the cross-zone path. A NAT instance shifts cost to a managed instance and scales poorly. Consolidating into one zone removes the multi-zone resilience.
142. Instances in a private subnet must reach AWS Systems Manager for Session Manager with no internet path. Which solution meets these requirements?
Answer and explanation
Answer: D. Session Manager requires interface endpoints for ssm, ssmmessages, and ec2messages so the agent can register and maintain its session channel privately. Gateway endpoints exist only for Amazon S3 and DynamoDB. A NAT gateway and an internet gateway both provide the internet path the requirement excludes.
143. A company must audit whether AWS WAF, AWS Shield, and Route 53 Resolver DNS Firewall protections are correctly configured in an account. Which solution meets these requirements?
Answer and explanation
Answer: D. Auditing network protection services means confirming each is enabled and associated with the resources it should cover, which is a configuration and coverage review. GuardDuty detects threat activity rather than confirming protection coverage. Flow Logs record traffic. Config records configuration changes without assessing protection coverage.
144. An application must resolve private DNS names for resources inside a VPC, and those names must not be visible on the public internet. Which solution meets these requirements?
Answer and explanation
Answer: D. A private hosted zone serves records only to the VPCs it is associated with and is never published to public resolvers. A public hosted zone is queryable by anyone regardless of the record values. Host file entries do not scale and drift immediately. CloudFront distributes content publicly.
145. A zone apex such as example.com must resolve to an Application Load Balancer. Which solution meets these requirements?
Answer and explanation
Answer: D. DNS does not permit a CNAME at a zone apex, and Route 53 alias records resolve directly to the AWS resource at no query cost. A CNAME at the apex is invalid. Load balancer addresses change, so static A records break. TXT records hold arbitrary text and route no traffic.
146. Instances in a VPC intermittently fail to resolve an on-premises domain although a Route 53 Resolver forwarding rule exists. Which cause should the team investigate first?
Answer and explanation
Answer: B. Intermittent resolution points to one of the outbound endpoint's per-zone addresses being unable to reach the on-premises resolvers, since queries are distributed across them. DNS hostnames affect instance naming rather than forwarding. Association with another VPC does not affect this one. A public hosted zone is unrelated to a private forwarding rule.
147. Users worldwide report slow downloads of large static assets served from an Amazon S3 bucket in one Region. Which solution meets these requirements?
Answer and explanation
Answer: D. CloudFront caches objects at edge locations near viewers, so distance stops dominating download time. Storage class affects cost and retrieval characteristics rather than geographic latency. Versioning preserves object history. Replicating to every Region multiplies storage cost and requires clients to select the right bucket.
148. A dynamic API served from two Regions must fail over within seconds without waiting for DNS caches to expire. Which solution meets these requirements?
Answer and explanation
Answer: A. Global Accelerator uses static anycast addresses so failover happens in the AWS network within seconds, independent of resolver caching. Route 53 failover and latency routing both depend on resolvers honouring the time to live. CloudFront origin failover helps for cacheable content but is built around caching rather than second-scale API failover.
149. A team must record which clients query a hosted zone and which records they request, for troubleshooting. Which solution meets these requirements?
Answer and explanation
Answer: D. Route 53 query logging records the queries received for a hosted zone including the record requested. Flow Logs capture IP-level traffic without the queried name. CloudTrail records API activity such as record changes rather than resolution requests. Health checks test endpoint availability.
150. Traffic must be distributed across three Regional endpoints in proportion to their capacity, with the proportions adjustable. Which solution meets these requirements?
Answer and explanation
Answer: C. Weighted routing distributes queries in proportion to configured weights, which can be adjusted as capacity changes. Latency routing selects by proximity rather than capacity. Failover routing sends traffic to secondaries only when the primary is unhealthy. Multivalue answer routing returns several healthy records without proportional control.
151. An Amazon CloudFront distribution must serve private content so that only the application's authenticated users can retrieve objects under a path. Which solution meets these requirements?
Answer and explanation
Answer: C. Signed cookies grant time-limited access to objects matching a path pattern, which is how CloudFront restricts content to authenticated users. Origin Access Control stops direct origin access but does not authenticate viewers. Forwarding a header passes it to the origin without CloudFront enforcing anything. Geographic restriction filters by country rather than by user.
152. An engineer must determine why traffic from an EC2 instance cannot reach an Amazon RDS endpoint, evaluating security groups, network ACLs, and route tables together. Which solution meets these requirements?
Answer and explanation
Answer: B. Reachability Analyzer performs a static configuration analysis of the path between two resources and reports which component blocks it. Flow Logs show whether packets were accepted or rejected but require interpretation and only capture traffic actually attempted. GuardDuty detects threats. Trusted Advisor offers general best-practice checks.
153. VPC Flow Logs show REJECT entries for return traffic on ephemeral ports from a subnet that reaches the internet through a NAT gateway. Which cause is most likely?
Answer and explanation
Answer: A. Network ACLs evaluate each packet independently, so return traffic on ephemeral ports must be explicitly allowed inbound. Security groups are stateful and permit return traffic automatically, and they allow all outbound by default. A NAT gateway in another zone affects cost and resilience rather than causing port-specific rejects. DNS settings produce name resolution failures instead.
154. An Amazon CloudFront distribution continues serving an outdated object after the origin has been updated. Which solution meets these requirements?
Answer and explanation
Answer: B. An invalidation removes the cached object immediately, and a shorter time to live limits how long future updates remain stale. Disabling caching removes the benefit of the distribution. An origin request policy controls what is forwarded to the origin rather than cache freshness. Origin Shield consolidates origin fetches without refreshing cached objects.
155. A team must confirm which requests an Application Load Balancer received and how it responded during an incident. Which solution meets these requirements?
Answer and explanation
Answer: B. Access logs record each request with its response code, latency, and target, which is the per-request detail an incident review needs. Flow Logs capture IP-level metadata without HTTP detail. CloudTrail records configuration API calls rather than request traffic. Detailed monitoring reports aggregate metrics.
156. An on-premises network reaches AWS over both AWS Direct Connect and a Site-to-Site VPN, and traffic is unexpectedly using the VPN. Which cause should be investigated first?
Answer and explanation
Answer: D. Path selection between Direct Connect and VPN is governed by route propagation and BGP attributes, so an unexpected path points there first. Port speed affects capacity rather than which path is chosen. Tunnel encryption settings do not influence routing preference. DNS settings resolve names rather than select network paths.
157. VPC Flow Logs show ACCEPT records for traffic the application never received. Which cause should be investigated first?
Answer and explanation
Answer: C. An ACCEPT record means the VPC controls permitted the traffic, so the problem is inside the instance. Network ACLs, security groups, and routes would have produced REJECT records or no record.
158. An operator must determine whether a network path between two resources is permitted without sending traffic. Which tool is appropriate?
Answer and explanation
Answer: A. Reachability Analyzer evaluates configuration statically and names the blocking component. Flow Logs require traffic to have been attempted. CloudWatch and CloudTrail record metrics and API activity.
159. A Site-to-Site VPN tunnel is down, and the customer gateway shows no established session. Which cause should be investigated first?
Answer and explanation
Answer: B. A tunnel that never establishes points to a configuration mismatch at the negotiation layer. Internet gateways, routes, and instance addressing all matter once the tunnel is up.
160. An IAM user reports being denied an action their attached policy permits. Which cause should be investigated first?
Answer and explanation
Answer: C. An explicit deny anywhere in the evaluation overrides an allow, and boundaries and service control policies also cap permissions. Attachment recency, multi-factor status, and password expiry produce different symptoms.
161. An organization must confirm that all S3 buckets in an account have public access blocked. Which approach is appropriate?
Answer and explanation
Answer: C. A Config rule evaluates every bucket continuously with remediation. Console review does not scale. New-bucket-only settings leave existing buckets. Service control policies restrict actions rather than reporting existing state.
162. A KMS key's deletion has been scheduled in error. Which action is appropriate?
Answer and explanation
Answer: A. Scheduled deletion can be cancelled during the waiting period, after which the key is disabled and can be re-enabled. Key identifiers cannot be reused, keys are not backed up separately, and recreating produces a different key that cannot decrypt existing data.
163. An S3 bucket policy must require that all requests use TLS. Which condition is appropriate?
Answer and explanation
Answer: B. The aws:SecureTransport condition distinguishes TLS from plaintext requests. Source IP restricts network origin. The encryption header condition governs at-rest encryption. Organization ID restricts the caller.
164. Secrets Manager rotation for an RDS credential fails with a connectivity error. Which cause should be investigated first?
Answer and explanation
Answer: B. A rotation function in a VPC needs routes to both the database and the service. Value format, schedule frequency, and key type produce different errors.
165. An operator must confirm which principal deleted an S3 object. Which source provides this?
Answer and explanation
Answer: D. Object deletion is a data event recording the calling identity, and it must be enabled beforehand. Management events do not cover object operations. Server access logs are best-effort with less reliable attribution. A current listing shows what remains.
166. An operator must connect a VPC to an AWS service privately without a NAT gateway or internet gateway. Which approach is appropriate?
Answer and explanation
Answer: A. VPC endpoints provide private connectivity to AWS services. Public addresses, a proxy, and peering to an internet-connected VPC all route through public paths or add components.
167. A transit gateway attachment must not receive routes from another attachment. Which configuration is appropriate?
Answer and explanation
Answer: A. Transit gateway route tables control which attachments can reach which. Detaching removes connectivity entirely. Transit gateway attachments do not take security groups, and network ACLs apply to subnets.
168. An operator must increase the available IP addresses in a VPC that is running out. Which approach is appropriate?
Answer and explanation
Answer: D. A secondary CIDR block extends a VPC's address space without disruption. A primary CIDR cannot be modified. Recreating the VPC is disruptive. Elastic IP addresses are public and unrelated to private subnet capacity.
169. An instance cannot reach an AWS service through an interface VPC endpoint. Which cause should be investigated first?
Answer and explanation
Answer: A. Interface endpoints are reached through an elastic network interface governed by a security group. They are resolved by DNS rather than a route table entry, have no public address, and do not require an internet gateway.
170. Traffic between two subnets in the same VPC is being dropped in one direction only. Which cause should be investigated first?
Answer and explanation
Answer: B. Stateless network ACLs require explicit rules in both directions, which produces asymmetric drops. Security groups are stateful and permit return traffic automatically. Route tables and host routes would affect both directions.
171. An operator must determine which security group rule permitted a connection that should have been blocked. Which approach is appropriate?
Answer and explanation
Answer: A. Flow Logs record accept or reject without naming the rule, so the rules must be examined. CloudTrail records API calls rather than network connections. System logs record host activity.
172. An instance in a public subnet has an internet gateway route but cannot reach the internet. Which cause should be investigated first?
Answer and explanation
Answer: D. A public subnet route is insufficient without a public address on the instance. A NAT gateway is for private subnets. DNS resolution affects name lookup. Inbound rules do not govern outbound connections.
173. An on-premises host cannot reach a VPC resource over a Site-to-Site VPN although the tunnel is up. Which cause should be investigated first?
Answer and explanation
Answer: D. With the tunnel established, missing or unpropagated routes are the usual cause. The pre-shared key and gateway address would prevent the tunnel establishing. An internet gateway is unrelated to VPN traffic.
174. DNS resolution fails for an AWS service endpoint from instances in a VPC with a custom DHCP option set. Which cause should be investigated first?
Answer and explanation
Answer: B. A custom DHCP option set replaces the VPC Resolver, and custom servers unable to resolve AWS endpoints break service name lookup. Internet gateways, public addresses, and routes affect connectivity rather than resolution.
175. An operator must capture the actual packet contents of traffic to an instance for analysis. Which capability is appropriate?
Answer and explanation
Answer: A. Traffic Mirroring copies full packets for inspection. Flow Logs record metadata without payloads. CloudWatch Logs hold application output. CloudTrail records API activity.