Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon SOA-C03 Exam - Topic 1 Question 13 Discussion

A CloudOps engineer launches an Amazon EC2 Linux instance in a public subnet. When the instance is running, the CloudOps engineer obtains the public IP address and attempts to remotely connect to the instance multiple times. However, the CloudOps engineer always receives a timeout error.Which action will allow the CloudOps engineer to remotely connect to the instance?
C) Modify the instance security group to allow inbound SSH traffic from the CloudOps engineer's IP address.
A) Add a route table entry in the public subnet for the CloudOps engineer's IP address.
B) Add an outbound network ACL rule to allow TCP port 22 for the CloudOps engineer's IP address.
D) Modify the instance security group to allow outbound SSH traffic to the CloudOps engineer's IP address.

Amazon SOA-C03 Exam - Topic 1 Question 13 Discussion

Actual exam question for Amazon's SOA-C03 exam
Question #: 13
Topic #: 1
[All SOA-C03 Questions]

A CloudOps engineer launches an Amazon EC2 Linux instance in a public subnet. When the instance is running, the CloudOps engineer obtains the public IP address and attempts to remotely connect to the instance multiple times. However, the CloudOps engineer always receives a timeout error.

Which action will allow the CloudOps engineer to remotely connect to the instance?

Show Suggested Answer Hide Answer
Suggested Answer: C

SSH access to a Linux EC2 instance requires inbound TCP port 22 to be allowed by the instance's security group from the administrator's source IP address. A timeout usually indicates that network traffic is being blocked before the SSH service can respond. Since the instance is in a public subnet and has a public IP address, the most likely missing control is an inbound security group rule. Security groups are stateful, so return traffic is automatically allowed after inbound SSH is permitted. Adding a route for the engineer's IP address is not needed because public subnets use a default route to the internet gateway. An outbound-only NACL or security group rule does not allow inbound SSH initiation. Therefore, the correct remediation is to allow inbound SSH from the engineer's public IP.


Contribute your Thoughts:

0/2000 characters
Kristal
1 day ago
C is the clear answer. Can't connect without the right inbound rule!
upvoted 0 times
...
Louvenia
7 days ago
I’m leaning towards A, but it seems less direct than C.
upvoted 0 times
...
Valda
12 days ago
Definitely C. It's all about the right permissions.
upvoted 0 times
...
Hollis
17 days ago
Right! If the security group blocks it, timeout errors happen.
upvoted 0 times
...
Elbert
22 days ago
I feel like C is straightforward. Just allow SSH from my IP.
upvoted 0 times
...
Edna
27 days ago
Option B could work too, but it's more about inbound rules.
upvoted 0 times
...
Glenna
1 month ago
Agreed! If SSH isn't allowed, no connection.
upvoted 0 times
...
Nakita
1 month ago
I think option C is the best choice. Security groups control inbound traffic.
upvoted 0 times
...
Rhea
1 month ago
Is it really just a security group issue? Sounds too simple!
upvoted 0 times
...
Shawnna
2 months ago
I thought public IPs were accessible by default?
upvoted 0 times
...
Nicolette
2 months ago
Wait, why would you need to modify outbound rules? Seems off.
upvoted 0 times
...
Elinore
2 months ago
Definitely option C! That's the way to go.
upvoted 0 times
...
Tesha
2 months ago
You need to allow inbound SSH traffic for sure.
upvoted 0 times
...
Willodean
2 months ago
I’m a bit confused about the outbound rules. I thought they were less important for connecting to an instance, so I’m leaning towards option C as well.
upvoted 0 times
...
Cathrine
4 months ago
I practiced a similar question where modifying security groups was the key. I think option C is definitely the right choice.
upvoted 0 times
...
Myong
4 months ago
I'm not entirely sure, but I feel like the network ACLs could be involved here too. Maybe option B?
upvoted 0 times
...
Lauryn
4 months ago
I remember something about security groups being crucial for inbound traffic. I think option C makes the most sense.
upvoted 0 times
...

Save Cancel