← AWS SysOps SOA-C02: historical operations path
SOA-C02 retired September29,2025. Independent historical content without AWS affiliation, accreditation, or certification award. CloudOps SOA-C03 has its own syllabus. Editorial review without independent specialist verification or execution in an AWS account. Fictional scenarios do not represent internal BNP Paribas policies. AWS and other trademarks belong to their respective owners.
05 / 6 · 40 MIN

Networking, resolution, and content delivery

Follow request and response through each boundary.

Concept and mechanism

Network diagnosis starts with source, destination, protocol, port, and direction. Security groups are stateful; NACLs require considering the return path and rule order as well. An allowed rule in one control does not cancel a block in another. For an instance without a public IP to initiate external connections through public NAT, check the private route to NAT and its public path to the internet gateway. NAT is not a mechanism for automatically publishing an inbound service. An S3 gateway endpoint requires association with relevant route tables and retains authorization and network-control requirements applicable to the path.

Guided application

DNS and caches introduce time between a change and observed behavior. Lowering TTL at cutover does not revoke answers already stored with the previous TTL. Prepare the change and maintain compatibility during transition. In CloudFront, OAC for S3 requires a compatible regular origin; the website endpoint is a custom origin and does not support that mechanism. The policy should authorize intended access without making the origin public. Also distinguish origin control from end-user authentication. For static-file releases, versioned names help because edge invalidation does not necessarily remove the old object held by a browser or intermediate cache.

IN PRACTICE

The request leaves, but its TCP response is blocked by the NACL at the ephemeral port. Opening more security-group ports does not repair the rule actually rejecting the return.

Common pitfalls

Endpoint existence treated as routing in every subnet; DNS treated as instant update; OAC treated as user login.

Related topics: Signals, alarms, and operational diagnosis · Continuity and usable recovery · Changes, drift, and controlled automation

Take this idea with you

Validate the complete path and distinguish delivery, authorization, and caching.

Create account

Reference: VPC network ACL evaluation · SOA-C02 archived guide v2.3; retired2025-09-29