CompTIA Cloud Essentials+ (CLO-002)Management and Technical OperationsMedium
A cloud administrator needs to ensure that specific resources, such as databases and internal APIs, are never exposed directly to the public internet, even if accidentally misconfigured. They should only be accessible from within the private network of the Virtual Private Cloud (VPC). Which networking component is crucial for enforcing this isolation?
- AInternet Gateway
- BPrivate Subnet
- CPublic Subnet
- DNAT Gateway
Show answer & explanationAnswer & explanation
Correct answer: B. Private Subnet
A private subnet is a subnet whose route table does not contain a route to an Internet Gateway. Resources launched into a private subnet are, by definition, isolated from direct public internet access, ensuring they are only accessible from within the VPC.
Why the other options are wrong
- A. An Internet Gateway enables communication between a VPC and the internet, which would expose resources if directly routed.
- C. A public subnet is directly routed to an Internet Gateway, making resources within it publicly accessible.
- D. A NAT Gateway allows resources in a private subnet to initiate outbound connections to the internet but prevents inbound connections from the internet.
Private Subnet
A subnet within a Virtual Private Cloud (VPC) that does not have a direct route to an Internet Gateway, thus isolating its resources from direct public internet access.
- Resources are only accessible from within the VPC or via a VPN/Direct Connect.
- Used for databases, application servers, and other sensitive resources.
- Can still initiate outbound internet connections via a NAT Gateway.
Memory trick: Private means Protected from Public.