Skip to content

AWS troubleshooting: access denied, EC2 connections and health checks

Work through the problems AWS's own troubleshooting pages document most: reading an access denied message to find the policy type that blocked a request, S3 403 errors (Block Public Access, ACLs, KMS keys), EC2 SSH errors and the network path behind 'Connection timed out', Session Manager nodes that don't appear, status checks, and CloudWatch alarm states.

Level
Intermediate
Length
About 50 minutes
Contents
3 lessons · 1 video · final exam
Status
Published · updated 2 Oct 2026
  • Amazon Web Services (AWS)

Skills you'll practise

  • Read an AWS access denied message and name the policy type to check first (explicit versus implicit deny)
  • List the S3-specific causes of a 403 error, including Block Public Access, Object Ownership and KMS key permissions
  • Match common EC2 SSH errors to their documented causes and fixes
  • Check the security group, route table, network ACL and public address behind a 'Connection timed out' error
  • Use ssm-cli get-diagnostics output to explain why an instance isn't a managed node
  • Distinguish system, instance and attached EBS status check failures, and read alarm states and 'M out of N' settings

Course outline

  1. 1.AWS troubleshooting from the documentationVideo · 2 min
  2. 2.Reading 'access denied': IAM and S3Lesson · 17 min
  3. 3.When you can't connect to an EC2 instanceLesson · 18 min
  4. 4.Instance health and alarmsLesson · 15 min
  5. 5.AWS troubleshooting: access denied, EC2 connections and health checks: knowledge checkKnowledge check · 18 questions
  6. 6.Final exam11 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.