CompTIA Cloud+ (CV0-004)Cloud ArchitectureMedium

A cloud engineer is configuring a Virtual Private Cloud (VPC) for a multi-tier application. The web servers need to be accessible from the internet, while the database servers must remain private and only accessible by the web servers. Which networking component is used to connect the public-facing subnets to the internet and allow inbound internet traffic?

  1. AVPC Endpoint
  2. BNAT Gateway
  3. CVPN Gateway
  4. DInternet Gateway
Show answer & explanation

Correct answer: D. Internet Gateway

An Internet Gateway is a horizontally scaled, redundant, and highly available VPC component that allows communication between instances in your VPC and the internet. It is essential for public-facing subnets to receive inbound traffic from the internet.

Why the other options are wrong

  • A. A VPC Endpoint allows private connections from your VPC to supported AWS services without traversing the internet.
  • B. A NAT Gateway allows instances in private subnets to initiate outbound connections to the internet but prevents inbound connections from the internet.
  • C. A VPN Gateway connects your VPC to your on-premises network over a Virtual Private Network (VPN) connection, not directly to the internet for public access.

Internet Gateway (IGW)

A VPC component that allows communication between instances in your Virtual Private Cloud (VPC) and the internet. It enables instances to send and receive traffic from the internet.

  • Enables internet connectivity for VPC instances
  • Attached to the VPC, not a specific subnet
  • Required for public subnets to communicate with the internet
  • Acts as a target in public subnet route tables

Memory trick: Internet Gateway for public, NAT Gateway for private's out.

More Cloud Architecture questions