CompTIA Cloud+ (CV0-004)Cloud ArchitectureMedium

A cloud engineer is configuring network connectivity for a Virtual Private Cloud (VPC) to allow resources within the VPC to securely access services on the public internet without having public IP addresses. Which component is essential for this functionality?

  1. ANAT Gateway
  2. BVPN Gateway
  3. CVPC Endpoint
  4. DTransit Gateway
Show answer & explanation

Correct answer: A. NAT Gateway

A NAT Gateway allows instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating connections to those instances, fulfilling the requirement for secure outbound access without public IPs.

Why the other options are wrong

  • B. VPN Gateway connects a VPC to an on-premises network over a secure tunnel.
  • C. VPC Endpoints allow private connectivity to specific AWS services, not general internet access.
  • D. Transit Gateway connects multiple VPCs and on-premises networks together.

NAT Gateway

A managed Network Address Translation (NAT) service that allows instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating connections to those instances.

  • Provides outbound internet connectivity for private subnets.
  • Instances in private subnets do not need public IP addresses.
  • Highly available and managed by the cloud provider.

Memory trick: NAT Gateway is your 'NATural' way for 'private' instances to 'talk' to the 'Internet'.

More Cloud Architecture questions