AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityMedium

A company is deploying a new web application on Amazon EC2 instances within a Virtual Private Cloud (VPC). The application requires outbound internet access to retrieve updates and interact with third-party APIs. However, the security team mandates that the EC2 instances themselves must reside in private subnets and should not have direct public IP addresses. All outbound internet traffic must be routed through a centralized point for inspection and auditing. How should this be configured to meet the security requirements?

  1. ADeploy EC2 instances in private subnets and use a VPC Endpoint for outbound internet access.
  2. BDeploy EC2 instances in private subnets and assign Elastic IPs to each instance for outbound internet access.
  3. CDeploy EC2 instances in public subnets and attach an Internet Gateway to the VPC.
  4. DDeploy EC2 instances in private subnets, configure a NAT Gateway in a public subnet, and route private subnet traffic through the NAT Gateway.
Show answer & explanation

Correct answer: D. Deploy EC2 instances in private subnets, configure a NAT Gateway in a public subnet, and route private subnet traffic through the NAT Gateway.

Placing EC2 instances in private subnets ensures they don't have direct public IP addresses. A NAT Gateway in a public subnet allows instances in private subnets to initiate outbound connections to the internet while preventing unsolicited inbound connections, fulfilling the requirement for a centralized outbound point.

Why the other options are wrong

  • A. VPC Endpoints are for private access to AWS services (like S3, DynamoDB), not for general outbound internet access.
  • B. Assigning Elastic IPs to instances effectively gives them public IP addresses, violating the private subnet requirement.
  • C. Deploying instances in public subnets gives them direct public IP addresses, violating the requirement.

NAT Gateway

A NAT Gateway enables instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating a connection with those instances.

  • Allows outbound internet from private subnets.
  • Resides in a public subnet.
  • Requires an Elastic IP address.
  • Provides a centralized point for outbound traffic.

Memory trick: NAT Gateway Nurtures Network Access for Private Subnets.

More Domain 3: Infrastructure Security questions