AWS Certified SysOps Administrator – AssociateMonitoring, Logging, and RemediationEasy

A SysOps administrator needs to troubleshoot network connectivity issues between an Amazon EC2 instance in a private subnet and an Amazon RDS database instance in a different private subnet within the same VPC. The application logs indicate connection timeouts. Which AWS service is best suited to quickly identify network path issues, such as missing security group rules or incorrect route table entries?

  1. AEmploy the VPC Reachability Analyzer to determine the network path and identify potential blocks.
  2. BUtilize AWS Systems Manager Session Manager to connect to the EC2 instance and run `ping` or `telnet` commands.
  3. CUse VPC Flow Logs to analyze all network traffic between the two instances for denied connections.
  4. DCheck the security group rules for both the EC2 instance and the RDS instance manually in the AWS Management Console.
Show answer & explanation

Correct answer: A. Employ the VPC Reachability Analyzer to determine the network path and identify potential blocks.

VPC Reachability Analyzer is specifically designed to perform network path analysis between specified AWS resources. It can quickly and definitively identify if a network path exists and, if not, pinpoint the exact configuration issue (e.g., security group, NACL, route table) preventing connectivity.

Why the other options are wrong

  • B. `ping` or `telnet` can confirm connectivity but don't explain *why* it's blocked, and require access to the instance.
  • C. VPC Flow Logs provide traffic records but require manual analysis and might not immediately pinpoint the root cause of a blocked path.
  • D. Manually checking rules can be tedious and prone to error, especially in complex environments. It doesn't analyze the entire path like Reachability Analyzer.

VPC Reachability Analyzer

VPC Reachability Analyzer is a network diagnostics tool that enables you to analyze and debug network reachability between two resources in your Amazon VPCs, identifying underlying configuration issues.

  • Analyzes network paths between specified AWS resources.
  • Identifies security group rules, network ACLs, route tables, and gateway issues.
  • Provides a definitive 'reachable' or 'unreachable' status with problem details.
  • Supports various resource types like EC2, ENI, ALB, VPN, Transit Gateway.

Memory trick: Reachability Analyzer, path's a tracer.

More Monitoring, Logging, and Remediation questions