AWS Certified Cloud Practitioner (CLF-C02)Cloud Technology and ServicesMedium

A company hosts private EC2 instances in a VPC that need to download software updates from the internet but must remain unreachable from inbound internet traffic. Which component should they add to the VPC architecture?

  1. AA security group allowing all inbound traffic on port 443
  2. BA VPC peering connection to another VPC
  3. CAn internet gateway attached directly to the private subnet
  4. DA NAT gateway in a public subnet with a route from the private subnet
Show answer & explanation

Correct answer: D. A NAT gateway in a public subnet with a route from the private subnet

A NAT gateway placed in a public subnet allows instances in a private subnet to initiate outbound traffic to the internet (e.g., for updates) while preventing unsolicited inbound connections from the internet.

Why the other options are wrong

  • A. Allowing all inbound traffic on port 443 would expose the instances to the internet, violating the requirement.
  • B. VPC peering connects two VPCs privately and does not provide internet access.
  • C. Attaching an internet gateway directly to a private subnet would expose instances to inbound internet traffic, defeating the privacy requirement.

NAT Gateway

A managed AWS service placed in a public subnet that allows instances in private subnets to initiate outbound internet traffic without accepting unsolicited inbound connections.

  • Deployed in a public subnet
  • Provides outbound-only internet access
  • Requires a route table entry from the private subnet

Memory trick: NAT = No Access Traveling in, only out

More Cloud Technology and Services questions