A SysOps administrator is troubleshooting intermittent connectivity issues for an EC2 instance in a private subnet. The instance should be able to access an Amazon S3 bucket for data storage. The administrator suspects network configuration issues. Which of the following is the MOST appropriate sequence of steps the administrator should take to diagnose the connectivity problem?
- ACheck NACLs, then Security Group rules, then Route Table for S3 endpoint, then confirm VPC Endpoint for S3.
- BCheck Route Table for S3 endpoint, then Network ACLs, then Security Group rules, then confirm VPC Endpoint for S3.
- CCheck Security Group rules, then Network ACLs, then Route Table for S3 endpoint, then VPC Endpoint for S3.
- DCheck VPC Endpoint for S3, then Route Table for S3 endpoint, then Security Group rules, then Network ACLs.
Show answer & explanationAnswer & explanation
Correct answer: C. Check Security Group rules, then Network ACLs, then Route Table for S3 endpoint, then VPC Endpoint for S3.
A logical troubleshooting flow starts with the most specific firewall (Security Groups) then broader subnet firewall (NACLs), then routing, and finally the specific service access method (VPC Endpoint). Security Groups are stateful and often the first point of failure for instance-level issues. NACLs are stateless and apply to the subnet. Route tables dictate traffic paths. VPC Endpoints ensure private access to S3.
Why the other options are wrong
- A. Starting with NACLs before Security Groups is less efficient as SGs are often the immediate cause for instance-level blocks.
- B. Starting with the route table before security rules can be less efficient as traffic might be blocked by SGs or NACLs even if routing is correct.
- D. Starting with VPC Endpoint is premature; basic network and security rules should be checked first.
AWS Network Troubleshooting Flow
A systematic approach to diagnosing network connectivity issues in AWS, typically starting from instance-level security, then subnet-level security, and then routing.
- Start with Security Groups (instance-level, stateful)
- Proceed to Network ACLs (subnet-level, stateless)
- Check Route Tables (traffic direction)
- Verify connectivity components (IGW, NAT Gateway, VPC Endpoints, VPN)
Memory trick: SG-NACL-Route-Connect: See Ghost, N-A-C-L, Route to Connect.