AWS Certified Advanced Networking – Specialty (ANS-C01)Network ImplementationMedium

A company is deploying a new service in a VPC with a CIDR block of 10.0.0.0/20. They need to create a private subnet that can host exactly 20 EC2 instances, with room for 50% growth. Which of the following CIDR blocks is the smallest and most appropriate for this subnet?

  1. A10.0.0.0/27
  2. B10.0.0.0/26
  3. C10.0.0.0/25
  4. D10.0.0.0/24
Show answer & explanation

Correct answer: B. 10.0.0.0/26

20 instances + 50% growth = 30 instances. AWS reserves 5 IPs. So, 30 + 5 = 35 total IPs needed. A /26 CIDR block provides 64 total IPs (59 usable), which is the smallest block that accommodates 35 IPs. A /27 provides only 27 usable IPs, which is insufficient.

Why the other options are wrong

  • A. A /27 block provides 32 total IPs (27 usable), which is less than the required 35 IPs (20 + 50% growth + 5 reserved).
  • C. A /25 block provides 128 total IPs (123 usable), which is more than needed and less efficient than a /26.
  • D. A /24 block provides 256 total IPs (251 usable), which is significantly more than needed and inefficient for this requirement.

Subnet Sizing (Growth)

When sizing subnets, calculate current IP needs, add a buffer for expected growth, and account for AWS-reserved IP addresses (5 per subnet).

  • Total IPs = 2^(32-CIDR_mask)
  • Usable IPs = Total IPs - 5 (AWS reserved)
  • Plan for current needs + future growth
  • Choose the smallest CIDR block that fits the calculated usable IPs

Memory trick: Instances + Growth + Reserved = Total, then find the smallest CIDR math.

More Network Implementation questions