CompTIA Cloud+ (CV0-004)TroubleshootingMedium

A cloud engineer is troubleshooting an application that intermittently fails to connect to an external third-party API. The application is running in a private subnet and uses a NAT Gateway to access the internet. Network flow logs show successful connections to other external services, but repeated connection timeouts to this specific API endpoint. What is the MOST likely cause?

  1. AThe application's DNS resolver is failing to resolve the API endpoint's hostname.
  2. BThe third-party API has IP address restrictions that do not include the NAT Gateway's public IP.
  3. CThe security group attached to the application instances is blocking outbound traffic to the API.
  4. DThe NAT Gateway is experiencing intermittent performance degradation.
Show answer & explanation

Correct answer: B. The third-party API has IP address restrictions that do not include the NAT Gateway's public IP.

Since other external services are reachable and the issue is specific to one API, the most likely cause is that the third-party API is configured to only allow connections from specific IP addresses, and the NAT Gateway's dynamic public IP (or a static one not whitelisted) is not among them.

Why the other options are wrong

  • A. DNS resolution issues would typically prevent any connection attempts or result in 'hostname not found' errors, not connection timeouts after successful resolution for other services.
  • C. If the security group was blocking outbound traffic, the connection would fail consistently, not intermittently, and to all endpoints, not just one specific API.
  • D. If the NAT Gateway was degrading, all external connections would likely be affected, not just one specific API.

Third-Party API IP Whitelisting

A security measure where an external API restricts access to a predefined list of trusted source IP addresses, often requiring cloud NAT Gateway or egress IP addresses to be explicitly added.

  • Restricts API access to specific IP ranges.
  • Commonly causes 'connection refused' or 'timeout' errors if not whitelisted.
  • Cloud applications using NAT Gateways need their public IP(s) whitelisted.

Memory trick: The API gatekeeper only knows friendly faces (IPs).

More Troubleshooting questions