Verify the security group on the server's ENI and that the instance is registered as an ALB target

Answer Correct answer: B, D — verify the security group on the server's ENI and that the instance is registered as a target in the ALB.

A security engineer has been asked to troubleshoot inbound connectivity to a web server. This single web server is not receiving inbound connections from the internet, whereas all other web servers are functioning properly. The architecture includes network ACLs, security groups, and a virtual security appliance. In addition, the development team has implemented Application Load Balancers (ALBs) to distribute the load across all web servers. It is a requirement that traffic between the web servers and the internet flow through the virtual security appliance. The security engineer has verified the following: 1. The rule set in the security groups is correct. 2. The rule set in the network ACLs is correct. 3. The rule set in the virtual appliance is correct. Which of the following are other valid items to troubleshoot in this scenario? (Choose two.)

  1. Verify that the 0.0.0.0/0 route in the route table for the web server subnet points to a NAT gateway.
  2. Verify which security group is applied to the particular web server’s elastic network interface (ENI). Correct Answer
  3. Verify that the 0.0.0.0/0 route in the route table for the web server subnet points to the virtual security appliance.
  4. Verify the registered targets in the ALB. Correct Answer
  5. Verify that the 0.0.0.0/0 route in the public subnet points to a NAT gateway.

Community Votes

BD
56%
CD
44%

56% of anonymous learners picked answer BD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Since all other servers work and the shared layers (NACL, appliance, SG rules) are verified, the failure is specific to this instance. B checks the SG actually bound to this ENI—an incorrect SG would drop its traffic. D checks ALB target registration—a deregistered instance receives nothing from the ALB. C (route to the appliance) applies to the whole subnet, so it would break all servers, not just one, making it a weaker single-server explanation. B and D are the valid per-instance checks.

One web server receives no inbound internet traffic while the others work, and the SG, NACL, and virtual-appliance rule sets are already confirmed correct. Because it is a single server (not the whole subnet), the cause is per-instance: confirm the correct security group is attached to this server's ENI (a wrong/missing SG would block its traffic) and confirm the instance is actually registered as a target in the ALB target group (if it is deregistered, the ALB will not forward traffic to it).

Focusing only on the route table (C)—it applies to the entire subnet, so if it pointed wrong, all servers would fail, not just this one; it does not explain a single-server outage. Overlooking the ENI's attached SG (B) or ALB target registration (D), which are the instance-specific controls most likely to differ for one server.

Community Discussion (4 comments)

nznzwell 👍 1 Selected: BD
The answer should B and D. C is not correct: the route in the routing table should point to the LB as the architecture should be like this: Internet -> Firewall -> Load Balancer -> EC2 Instances. Otherwise, how can the LB distributes traffic to EC2 notes when the network appliance sits in between?
IPLogic 👍 1 Selected: CD
The most likely causes for the inbound connectivity issue to the web server are related to routing and security group configurations. Here are the two most valid items to troubleshoot: C. Verify that the 0.0.0.0/0 route in the route table for the web server subnet points to the virtual security appliance. This ensures that traffic destined for the web server is routed correctly through the security appliance. D. Verify the registered targets in the ALB. If the web server is not registered as a target in the ALB, it will not receive any traffic from the internet.
HappyG 👍 3 Selected: CD
C. Verify that the 0.0.0.0/0 route in the route table for the web server subnet points to the virtual security appliance. Since the architecture specifies that traffic between the web servers and the internet must flow through a virtual security appliance, the route table for the web server subnet should direct traffic to this appliance. If the route is incorrect or missing, traffic will not be properly forwarded to the appliance and will be blocked, causing the web server to be unreachable. D. Verify the registered targets in the ALB. Even though the security groups, network ACLs, and virtual appliance configurations are correct, it's important to verify that the Application Load Balancer (ALB) correctly registers the target web server. If the target (your web server) is not registered or is in an unhealthy state, the ALB will not forward traffic to it, causing the web server to not receive incoming connections.
jdx000 👍 4 Selected: BD
B and D

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

With the shared controls (security group rules, NACLs, virtual-appliance rules) already verified and other servers healthy, the problem is isolated to this instance. Checking the security group actually attached to this server's ENI (B) catches a misbound or overly restrictive SG, and checking the ALB's registered targets (D) catches a deregistered instance that the load balancer will not forward to. These are the instance-specific items to troubleshoot.

Why the Other Options Are Wrong

C verifies the 0.0.0.0/0 route points to the virtual security appliance, but that route is subnet-wide—if it were wrong, every server in the subnet would fail, not just this one, so it does not explain a single-server outage. A (NAT gateway route) is irrelevant because inbound internet traffic does not use the subnet's egress route. B and D are the valid per-instance checks.

Community Comment Notes

Community split B,D (56) vs C,D (44). The B,D reasoning fits a single-server failure: verify the ENI's security group and ALB target registration, since the route-table (C) would affect all servers. B,D chosen as the instance-specific diagnosis.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide