CompTIA Cloud+ (CV0-004)Cloud ArchitectureEasy

A cloud administrator is configuring a new Virtual Private Cloud (VPC) and needs to ensure that instances within a private subnet can initiate outbound connections to the internet for updates and patches, but cannot receive unsolicited inbound connections from the internet. Which of the following networking components is essential to achieve this requirement?

  1. ANAT Gateway
  2. BInternet Gateway (IGW)
  3. CDirect Connect
  4. DVPC Endpoint
Show answer & explanation

Correct answer: A. NAT Gateway

A NAT Gateway allows instances in a private subnet to connect to the internet for outbound traffic while preventing unsolicited inbound traffic from the internet, maintaining security.

Why the other options are wrong

  • B. An Internet Gateway (IGW) allows direct bidirectional internet access for public subnets.
  • C. Direct Connect establishes a dedicated private network connection between an on-premises datacenter and a VPC.
  • D. A VPC Endpoint allows private connectivity to AWS services without traversing the internet.

NAT Gateway

A Network Address Translation (NAT) Gateway allows instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating connections to those instances.

  • Enables outbound internet access for private subnets
  • Prevents unsolicited inbound internet access
  • Requires an Elastic IP address
  • Operates similarly to a NAT device in an on-premises network

Memory trick: NAT is the guard for private subnets, letting outbound traffic out but keeping inbound threats out.

More Cloud Architecture questions