Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AWS Certified Security - Specialty SCS-C02 All Questions

View all questions & answers for the AWS Certified Security - Specialty SCS-C02 exam

Exam AWS Certified Security - Specialty SCS-C02 topic 1 question 135 discussion

Two Amazon EC2 instances in different subnets should be able to connect to each other but cannot. It has been confirmed that other hosts in the same subnets are able to communicate successfully, and that security groups have valid ALLOW rules in place to permit this traffic.

Which of the following troubleshooting steps should be performed?

  • A. Check inbound and outbound security groups, looking for DENY rules
  • B. Check inbound and outbound Network ACL rules, looking for DENY rules
  • C. Review the rejected packet reason codes in the VPC Flow Logs
  • D. Use AWS X-Ray to trace the end-to-end application flow
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
yismail
2 weeks, 1 day ago
Correct answer is C, other Instances in the same subnet can communicate, this eliminate the issue of NACL, if the deny role is attached the NACL on the same subnet, other Instances will not be able to communicate, only VPC flow logs can determine the error msg
upvoted 1 times
...
navid1365
3 months, 2 weeks ago
Selected Answer: B
The answer is B. Here is the reason: 1) A cannot be correct since the questions explicitly mentions that SG are configured with correct rules 2) B is correct. NACLs are attached to a subnet and can have both ALLOW and DENY rules. Given that the other hosts in the two subnets can communicate successfully, there has to be an explicit DENY rule that denies access between the two hosts in question.
upvoted 1 times
...
DeadDropLabs
5 months, 1 week ago
Selected Answer: B
For C - While VPC Flow Logs can provide insights into why packets are being rejected, this is a more detailed troubleshooting step. Checking the NACL rules is a more direct approach to identifying potential network layer issues.
upvoted 4 times
...
aescudero51
5 months, 2 weeks ago
Selected Answer: C
C is more relevant due to "It has been confirmed that other hosts in the same subnets are able to communicate successfully" where it says "other hosts in the same subnets" excluding NACL issue..
upvoted 2 times
helloworldabc
1 month, 3 weeks ago
just B
upvoted 1 times
...
...
Certified101
5 months, 4 weeks ago
B - SG dont have deny rules
upvoted 3 times
...
Zek
6 months ago
Will go with B https://www.examtopics.com/discussions/amazon/view/30042-exam-aws-certified-security-specialty-topic-1-question-176/
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...