CompTIA Cloud+ (CV0-004)TroubleshootingMedium
A cloud engineer is troubleshooting a multi-tier application where the web tier instances are unable to connect to the database tier instances. Both tiers are in the same Virtual Private Cloud (VPC) but in different subnets. Pinging between instances in the same subnet works, but pinging across subnets fails. Security groups are configured to allow traffic between the respective tiers. What is the MOST likely cause of this connectivity issue?
- AThe Network Access Control Lists (NACLs) are blocking inter-subnet traffic.
- BThe routing tables for the subnets are missing routes to each other's CIDR blocks.
- CThe DHCP Option Set is misconfigured for the VPC.
- DThe database instances do not have a public IP address.
Show answer & explanationAnswer & explanation
Correct answer: B. The routing tables for the subnets are missing routes to each other's CIDR blocks.
If instances can communicate within their own subnet but not across different subnets within the same VPC, and security groups are configured correctly, it strongly suggests that the routing tables associated with those subnets are missing the necessary routes to direct traffic between them.
Why the other options are wrong
- A. While NACLs could block traffic, the problem states 'pinging across subnets fails', which points more directly to routing rather than a specific port/protocol block by NACLs if security groups are already allowing the traffic.
- C. DHCP Option Sets provide network configuration like DNS and domain names, not routing between subnets.
- D. Public IP addresses are not required for communication within the same VPC.
VPC Routing Tables
Rules that determine where network traffic from a subnet or gateway is directed, specifying targets for various IP address ranges.
- Each subnet must be associated with a route table.
- Contains local routes for intra-VPC communication.
- Can include routes to Internet Gateways, VPNs, or peering connections.
Memory trick: Routes are Roads for Subnet Neighbors.