Solved

A Network Engineer Has Enabled VPC Flow Logs to Troubleshoot

Question 99

Multiple Choice

A Network Engineer has enabled VPC Flow Logs to troubleshoot an ICMP reachability issue for an echo reply from an Amazon EC2 instance. The flow logs reveal an ACCEPT record for the request from the client to the EC2 instance, and a REJECT record for the response from the EC2 instance to the client. What is the MOST likely reason for there to be a REJECT record?


A) The security group is denying inbound ICMP.
B) The network ACL is denying inbound ICMP.
C) The security group is denying outbound ICMP.
D) The network ACL is denying outbound ICMP.

Correct Answer:

verifed

Verified

Unlock this answer now
Get Access to more Verified Answers free of charge

Related Questions