CompTIA Cloud Essentials+ (CLO-002)Cloud ConceptsMedium

A cloud administrator is configuring network connectivity for a new set of virtual machines (VMs) that need to access the internet for updates and external API calls, but should not be directly accessible from the internet. Which networking component should be used to facilitate outbound internet access while preventing inbound connections?

  1. ALoad Balancer
  2. BDirect Connect
  3. CNAT Gateway
  4. DVirtual Private Gateway
Show answer & explanation

Correct answer: C. NAT Gateway

A NAT (Network Address Translation) Gateway allows instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating a connection with those instances. This provides secure outbound-only internet access.

Why the other options are wrong

  • A. A Load Balancer distributes incoming traffic across multiple instances and is not primarily for outbound internet access or preventing inbound connections.
  • B. Direct Connect establishes a dedicated private network connection between an on-premises data center and a cloud provider, not for general internet access for VMs.
  • D. A Virtual Private Gateway is used to establish VPN connections between an on-premises network and a VPC, not for general internet access for instances.

NAT Gateway

A network address translation service that enables instances in a private subnet to connect to the internet or other external services, while preventing external services from initiating a connection to those instances.

  • Provides outbound internet access for private subnets.
  • Prevents unsolicited inbound connections.
  • Enhances security for internal instances.

Memory trick: LOAD VIRTUAL NAT DIRECTS traffic.

More Cloud Concepts questions