To secure connectivity between a company’s VPC and its on-premises data center, a security engineer tested ICMP by sending a ping from an on-premises host (203.0.113.12) to an Amazon EC2 instance (172.31.16.139). The ping received no reply. Which action should be taken to allow the ping to succeed?
Choose an answer
Tap an option to check your answer.
Correct answer: Allow outbound ICMP traffic in the VPC network ACL (NACL)..
Why this is the answer
The ping failed because the return traffic from the EC2 instance to the on-premises host was blocked. Network ACLs (NACLs) are stateless, meaning both inbound and outbound rules must be explicitly allowed. While the security group likely allowed the inbound ping request and the EC2 instance processed it, the outbound ICMP reply from the EC2 instance was blocked by the NACL. Therefore, allowing outbound ICMP traffic in the VPC NACL will permit the ping reply to reach the on-premises host. Security groups are state
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed