CompTIA Cloud+ (CV0-004)Cloud ArchitectureMedium

A cloud administrator is configuring a Virtual Private Cloud (VPC) and needs to ensure that instances in a private subnet can initiate outbound connections to the internet for updates, but prevent unsolicited inbound connections from the internet. Which AWS networking component should be deployed in the public subnet to facilitate this communication pattern?

  1. AVirtual Private Gateway (VPG)
  2. BNAT Gateway
  3. CInternet Gateway (IGW)
  4. DVPC Endpoint
Show answer & explanation

Correct answer: B. NAT Gateway

A NAT Gateway allows instances in a private subnet to connect to the internet while preventing incoming unsolicited connections. It is deployed in a public subnet and routes traffic from private subnets to the internet gateway.

Why the other options are wrong

  • A. A Virtual Private Gateway is used for VPN connections between a VPC and an on-premises network.
  • C. An Internet Gateway allows both inbound and outbound internet access for public subnets, not suitable for private subnets needing outbound-only access.
  • D. A VPC Endpoint allows private connectivity to supported AWS services without using an Internet Gateway or NAT device.

NAT Gateway

A Network Address Translation (NAT) service that enables instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating a connection with those instances.

  • Deployed in a public subnet.
  • Requires an Elastic IP address.
  • Routes traffic from private subnets to an Internet Gateway.

Memory trick: NAT Gateway is the bouncer for your private club: you can leave, but nobody uninvited gets in.

More Cloud Architecture questions