AWS Certified Advanced Networking – Specialty (ANS-C01)Network ImplementationEasy

A network architect is designing a new VPC for a multi-tier application. The application consists of web servers in a public subnet and database servers in a private subnet. The database servers need to communicate with an external third-party API over the internet, but they must not be directly exposed to the internet. Which AWS networking component should the architect deploy in the public subnet to enable secure outbound internet access for the database servers?

  1. AInternet Gateway
  2. BNAT Gateway
  3. CVirtual Private Gateway
  4. DVPC Endpoint
Show answer & explanation

Correct answer: B. NAT Gateway

A NAT Gateway allows instances in a private subnet to connect to the internet (or other AWS services) while preventing the internet from initiating connections to those instances. It is deployed in a public subnet and associated with an Elastic IP address.

Why the other options are wrong

  • A. An Internet Gateway (IGW) allows direct internet access to instances in a public subnet, exposing them to inbound connections, which is not desired for private database servers.
  • C. A Virtual Private Gateway (VGW) is used for VPN or Direct Connect connections to on-premises networks, not for outbound internet access from private subnets.
  • D. VPC Endpoints provide private connectivity to specific AWS services (like S3, DynamoDB) or VPC endpoint services, not general outbound internet access.

NAT Gateway

An AWS managed service that enables instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating connections to those instances.

  • Deployed in a public subnet
  • Requires an Elastic IP address
  • Provides high availability and bandwidth
  • Replaces NAT instances for most use cases

Memory trick: NAT Gateway: 'N'o 'A'ccess 'T'o internal, but 'N'etwork 'A'ccess 'T'hrough it.

More Network Implementation questions