AWS Certified Advanced Networking – Specialty (ANS-C01)Network ImplementationEasy
A security audit reveals that several EC2 instances in a private subnet are directly accessing the internet for software updates, which is a security concern. The company policy requires all outbound internet traffic from private subnets to be inspected and logged. Which networking component should be deployed to allow private instances to securely initiate outbound internet connections while enabling centralized inspection and logging?
- AVPC Endpoint Service.
- BEgress-only Internet Gateway.
- CNAT Gateway.
- DInternet Gateway.
Show answer & explanationAnswer & explanation
Correct answer: C. NAT Gateway.
A NAT Gateway allows instances in a private subnet to connect to the internet or other AWS services but prevents the internet from initiating a connection with those instances. By routing all outbound traffic through the NAT Gateway, it acts as a single point for inspection and logging, fulfilling the security requirement.
Why the other options are wrong
- A. VPC Endpoint Services provide private connectivity to AWS services without traversing the internet, not for general internet access.
- B. An Egress-only Internet Gateway is specifically for IPv6 traffic from private subnets to the internet; it does not apply to IPv4 and does not inherently provide centralized inspection capabilities beyond basic logging.
- D. An Internet Gateway allows direct bidirectional internet access for instances in public subnets, which is not suitable for private subnets requiring outbound-only access and inspection.
NAT Gateway
A NAT Gateway enables instances in private subnets to connect to the internet or other AWS services, while preventing the internet from initiating connections with those instances.
- Deployed in a public subnet.
- Requires an Elastic IP address.
- Traffic from private subnets is routed through it to the internet.
Memory trick: NAT Gateway: The one-way door to the internet for your private secrets.