CompTIA Cloud+ (CV0-004)TroubleshootingHard

A cloud administrator is setting up a new virtual network for a highly sensitive application. The requirement is to ensure that no internet traffic, neither inbound nor outbound, can ever reach the application's subnet. However, the application still needs to access some internal cloud provider services (e.g., object storage, database service) within the same region. Which of the following network configurations would BEST achieve this requirement?

  1. ADeploy the application in a private subnet with a VPC Endpoint for internal cloud services and no Internet Gateway.
  2. BDeploy the application in a private subnet with a NAT Gateway and a security group denying all inbound internet traffic.
  3. CDeploy the application in a private subnet with an Internet Gateway attached to the VPC and a NACL denying all public traffic.
  4. DDeploy the application in a public subnet with a security group that denies all inbound and outbound internet traffic.
Show answer & explanation

Correct answer: A. Deploy the application in a private subnet with a VPC Endpoint for internal cloud services and no Internet Gateway.

To prevent all internet traffic (inbound/outbound) while allowing access to internal cloud services, the application must be in a private subnet with no Internet Gateway. VPC Endpoints provide private, secure access to specific cloud services without traversing the public internet, fulfilling the internal access requirement.

Why the other options are wrong

  • B. A NAT Gateway is for *outbound* internet access from private subnets. This violates the 'no outbound internet traffic' requirement.
  • C. An Internet Gateway attached to the VPC makes the VPC capable of internet access, violating the 'no internet traffic' requirement, even if NACLs attempt to block it (NACLs are stateless and can be complex to manage for full denial).
  • D. A public subnet, by definition, has a route to an Internet Gateway, making it inherently internet-accessible, even with restrictive security groups.

VPC Endpoint

A private connection between your VPC and supported cloud services, allowing traffic to flow privately without traversing the public internet.

  • Enhances security by keeping traffic within the cloud network.
  • Can be interface endpoints (ENIs) or gateway endpoints (route table targets).
  • Used for services like S3, DynamoDB, SQS, SNS, etc.

Memory trick: Private Subnet, No Gateway, Endpoints Only.

More Troubleshooting questions