CompTIA Cloud+ (CV0-004)TroubleshootingHard

A cloud administrator is configuring a new Virtual Private Cloud (VPC) peering connection between two VPCs in different regions to allow direct communication between services. After establishing the peering connection, instances in VPC A can ping instances in VPC B, but instances in VPC B cannot ping instances in VPC A. Both VPCs have correctly configured route tables pointing to the peering connection for the remote CIDR blocks, and security groups allow ICMP traffic. What is the MOST likely cause of the one-way communication issue?

  1. AThe route tables in VPC A contain an incorrect entry for VPC B's CIDR block.
  2. BThe peering connection itself is not bidirectional, requiring two separate connections.
  3. CThe security groups in VPC A are explicitly denying outbound ICMP traffic to VPC B.
  4. DThe Network Access Control Lists (NACLs) in VPC B are implicitly denying inbound ICMP traffic from VPC A.
Show answer & explanation

Correct answer: D. The Network Access Control Lists (NACLs) in VPC B are implicitly denying inbound ICMP traffic from VPC A.

NACLs are stateless, meaning if an outbound rule allows traffic, the corresponding inbound rule must also explicitly allow the return traffic. If VPC A can ping VPC B, VPC A's outbound NACL is fine. If VPC B cannot ping VPC A, but route tables and security groups are correct, it's highly probable that VPC A's *inbound* NACL is implicitly denying the return ICMP traffic from VPC B.

Why the other options are wrong

  • A. If VPC A's route table was incorrect, VPC A would not be able to ping VPC B reliably or at all.
  • B. VPC peering connections are inherently bidirectional by design; a single connection allows traffic flow in both directions once routes and security are configured.
  • C. If security groups in VPC A were denying *outbound* ICMP, then VPC A would not be able to ping VPC B in the first place.

VPC NACL Statelessness

Network Access Control Lists (NACLs) are stateless firewalls operating at the subnet level, requiring explicit rules for both inbound and outbound traffic, even for return traffic of an established connection.

  • Requires separate allow rules for inbound and outbound traffic.
  • Does not automatically allow return traffic for connections.
  • Default NACLs implicitly deny all inbound and outbound traffic if no allow rules are present.

Memory trick: NACLs are like a bouncer who forgets faces: you need a pass to get in AND a new pass to get out.

More Troubleshooting questions