AWS Certified Cloud Practitioner (CLF-C02)Cloud Technology and ServicesMedium
A company hosts private EC2 instances in a VPC that need to download software updates from the internet but must remain unreachable from inbound internet traffic. Which component should they add to the VPC architecture?
- AA security group allowing all inbound traffic on port 443
- BA VPC peering connection to another VPC
- CAn internet gateway attached directly to the private subnet
- DA NAT gateway in a public subnet with a route from the private subnet
Show answer & explanationAnswer & explanation
Correct answer: D. A NAT gateway in a public subnet with a route from the private subnet
A NAT gateway placed in a public subnet allows instances in a private subnet to initiate outbound traffic to the internet (e.g., for updates) while preventing unsolicited inbound connections from the internet.
Why the other options are wrong
- A. Allowing all inbound traffic on port 443 would expose the instances to the internet, violating the requirement.
- B. VPC peering connects two VPCs privately and does not provide internet access.
- C. Attaching an internet gateway directly to a private subnet would expose instances to inbound internet traffic, defeating the privacy requirement.
NAT Gateway
A managed AWS service placed in a public subnet that allows instances in private subnets to initiate outbound internet traffic without accepting unsolicited inbound connections.
- Deployed in a public subnet
- Provides outbound-only internet access
- Requires a route table entry from the private subnet
Memory trick: NAT = No Access Traveling in, only out