AWS Certified SysOps Administrator – AssociateNetworking and Content DeliveryEasy
A SysOps administrator is configuring a new VPC and needs to ensure that EC2 instances in a private subnet can initiate outbound connections to the internet for software updates and patches, but external hosts cannot initiate inbound connections to these instances. Which AWS networking component should be deployed in a public subnet to allow this?
- AInternet Gateway (IGW)
- BVPC Endpoint
- CNAT Gateway
- DVirtual Private Gateway (VGW)
Show answer & explanationAnswer & explanation
Correct answer: C. NAT Gateway
A NAT Gateway allows instances in a private subnet to connect to the internet while preventing the internet from initiating connections to those instances. It is deployed in a public subnet and routes traffic through an Internet Gateway.
Why the other options are wrong
- A. An Internet Gateway allows both inbound and outbound internet traffic for instances in public subnets, which doesn't meet the 'no inbound' requirement for private instances.
- B. VPC Endpoints allow private access to AWS services without traversing the internet, not general internet access.
- D. A Virtual Private Gateway is used for VPN connections to on-premises networks, not for private instances to access the internet.
NAT Gateway
A Network Address Translation (NAT) service that enables instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating a connection with those instances.
- Deployed in a public subnet
- Requires an Elastic IP address
- Routes traffic through an Internet Gateway
- Highly available within an Availability Zone
Memory trick: NAT Gateway: No Admittance, but we can call out!