CompTIA Cloud+ (CV0-004)DeploymentHard
A cloud engineer is setting up a new virtual network in a public cloud. The requirement is to create a private subnet that hosts backend application servers and a public subnet for web servers. The backend servers should only be accessible from the web servers and should not have direct internet access, while the web servers need to be accessible from the internet. Which network component is essential to enable outbound internet access for resources in the private subnet without allowing inbound connections from the internet?
- AVirtual Private Network (VPN) Gateway
- BDirect Connect
- CNAT Gateway
- DInternet Gateway
Show answer & explanationAnswer & explanation
Correct answer: C. NAT Gateway
A NAT (Network Address Translation) Gateway allows instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating connections with those instances. This fulfills the requirement for backend servers to have outbound internet access (e.g., for updates) without being directly exposed to the internet.
Why the other options are wrong
- A. A VPN Gateway connects an on-premises network to the cloud VPC, not primarily for private subnet internet access.
- B. Direct Connect establishes a dedicated private connection between an on-premises data center and the cloud, not for private subnet internet access.
- D. An Internet Gateway allows both inbound and outbound internet access to public subnets, but not for private subnets without a NAT device.
NAT Gateway
A managed Network Address Translation (NAT) service that allows instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating connections with those instances.
- Provides outbound internet access for private subnets.
- Hides private IP addresses behind a public IP.
- Managed service, highly available.
Memory trick: Gateways Guide Network Traffic Safely.