nerdexam
Amazon

SOA-C02 · Question #214

A company has set up an IPsec tunnel between its AWS environment and its on-premises data center. The tunnel is reporting as UP, but the Amazon EC2 instances are not able to ping any on- premises…

The correct answer is A. Create a new inbound rule on the EC2 instances' security groups to allow ICMP traffic from the. https://docs.aws.amazon.com/vpc/latest/userguide/VPC_SecurityGroups.html

Submitted by yuki_2020· Mar 30, 2026Networking and Content Delivery

Question

A company has set up an IPsec tunnel between its AWS environment and its on-premises data center. The tunnel is reporting as UP, but the Amazon EC2 instances are not able to ping any on- premises resources. What should a SysOps administrator do to resolve this issue?

Options

  • ACreate a new inbound rule on the EC2 instances' security groups to allow ICMP traffic from the
  • BCreate a peering connection between the IPsec tunnel and the subnet of the EC2 instances.
  • CEnable route propagation for the virtual private gateway in the route table that is assigned to
  • DModify the VPC's DHCP options set. Add the IPsec tunnel to the VPN section.

How the community answered

(33 responses)
  • A
    82% (27)
  • B
    3% (1)
  • C
    12% (4)
  • D
    3% (1)

Explanation

https://docs.aws.amazon.com/vpc/latest/userguide/VPC_SecurityGroups.html

Topics

#VPN IPsec#security groups#ICMP#VPC troubleshooting

Community Discussion

No community discussion yet for this question.

Full SOA-C02 Practice