CompTIA Cloud Essentials+ (CLO-002)Cloud ConceptsHard
A cloud administrator is configuring network access for a new application deployed in a Virtual Private Cloud (VPC). The application needs to communicate with an external third-party API over the public internet, but all outbound traffic from the application's subnet must first pass through a specific security appliance for inspection. Which VPC networking component should the administrator implement to enforce this traffic flow?
- AVPC Endpoint
- BDirect Connect
- CNAT Gateway
- DInternet Gateway
Show answer & explanationAnswer & explanation
Correct answer: C. NAT Gateway
A NAT Gateway allows instances in a private subnet to connect to services outside the VPC (like the public internet) while preventing external services from initiating connections to those instances. By routing outbound traffic through a NAT Gateway, which can then be configured to send traffic via a security appliance, the administrator can enforce inspection for all outbound public internet traffic.
Why the other options are wrong
- A. A VPC Endpoint provides private connectivity to specific AWS services without traversing the internet, not for general internet access or inspection.
- B. Direct Connect establishes a private connection between on-premises and VPC, not for outbound internet traffic from a private subnet through an appliance.
- D. An Internet Gateway allows direct public internet access, but doesn't facilitate routing through a specific security appliance from a private subnet.
NAT Gateway
A Network Address Translation service that allows instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating connections to those instances.
- Enables outbound internet connectivity for private subnets.
- Provides a single public IP address for multiple private instances.
- Crucial for security and controlled internet access.
Memory trick: VPC Network: Gateways for outside, Endpoints for private services.