AWS Certified Advanced Networking – Specialty (ANS-C01)Network ImplementationEasy

A network engineer is configuring a new AWS VPC (10.10.0.0/20) for a development environment. The VPC will host several EC2 instances that need to access the internet for software updates and external APIs, but no inbound internet traffic should reach these instances. Which is the most secure and cost-effective solution for outbound internet access?

  1. AAssign public IP addresses to all EC2 instances.
  2. BImplement an Internet Gateway with a security group allowing all outbound traffic.
  3. CUse a custom NAT instance on an EC2 machine.
  4. DDeploy a single NAT Gateway in a public subnet.
Show answer & explanation

Correct answer: D. Deploy a single NAT Gateway in a public subnet.

A NAT Gateway provides a secure and highly available way for instances in private subnets to initiate outbound connections to the internet while preventing inbound connections. It's more cost-effective and managed than a custom NAT instance.

Why the other options are wrong

  • A. Assigning public IPs allows inbound internet access, which violates the security requirement.
  • B. An Internet Gateway alone doesn't prevent inbound traffic to instances in private subnets; instances would still need public IPs or a NAT device.
  • C. A custom NAT instance is less highly available, requires more management overhead, and is generally more expensive than a NAT Gateway.

NAT Gateway

A Network Address Translation (NAT) Gateway enables instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating a connection with those instances.

  • Managed AWS service, highly available
  • Deployed in a public subnet
  • Requires an Elastic IP address
  • Instances in private subnets route internet traffic through the NAT Gateway

Memory trick: NAT Gateway is the one-way gate for private instances to the internet.

More Network Implementation questions