exam questions

Exam ANS-C00 All Questions

View all questions & answers for the ANS-C00 exam

Exam ANS-C00 topic 1 question 83 discussion

Exam question from Amazon's ANS-C00
Question #: 83
Topic #: 1
[All ANS-C00 Questions]

A Network Engineer has enabled VPC Flow Logs to troubleshoot an ICMP reachability issue for an echo reply from an Amazon EC2 instance. The flow logs reveal an ACCEPT record for the request from the client to the EC2 instance, and a REJECT record for the response from the EC2 instance to the client.
What is the MOST likely reason for there to be a REJECT record?

  • A. The security group is denying inbound ICMP.
  • B. The network ACL is denying inbound ICMP.
  • C. The security group is denying outbound ICMP.
  • D. The network ACL is denying outbound ICMP.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
pechung1206
Highly Voted 3 years, 8 months ago
D. NACLs are stateless, you must state outbound rules. If ICMP is coming in, it's fairly obvious the Security Group, and inbound NACLs are allowing traffic in.
upvoted 17 times
...
sayed_2908
Most Recent 3 years, 6 months ago
Selected Answer: D
Ans: D. NACL is stateless thus return traffic need to be allowed.
upvoted 3 times
...
pamplemousse
3 years, 7 months ago
Easy one, D for sure.
upvoted 4 times
...
GV19
3 years, 7 months ago
D , NACL Outbound should allow ICMP ping.
upvoted 2 times
...
guruguru
3 years, 8 months ago
D. Security group is state full, since inbound is allow, outbound is allow too.
upvoted 4 times
...
[Removed]
3 years, 8 months ago
Agreed with D. How can it be B, when the reject is from the EC@ to the client, i.e. outbound
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...