A client is deploying a new web application on Amazon EC2 instances within a Virtual Private Cloud (VPC). The application instances reside in private subnets and require outbound internet access to download software updates and access third-party APIs. However, the client's security policy strictly forbids any inbound internet access to these instances. Which AWS networking component should the security architect deploy to enable secure outbound internet access while preventing inbound connections?
- AA VPN connection to an on-premises network that then routes to the internet.
- BAn Internet Gateway attached directly to the private subnets.
- CA NAT Gateway deployed in a public subnet with routes from the private subnets.
- DA VPC endpoint for each external API and an Internet Gateway for software updates.
Show answer & explanationAnswer & explanation
Correct answer: C. A NAT Gateway deployed in a public subnet with routes from the private subnets.
A NAT Gateway allows instances in a private subnet to connect to the internet or other AWS services, but it prevents the internet from initiating a connection with those instances. Deploying it in a public subnet and configuring routes from the private subnets to the NAT Gateway fulfills the requirement for outbound internet access without inbound exposure.
Why the other options are wrong
- A. While possible, routing through an on-premises VPN for internet access adds latency and complexity, and it's not the most direct or efficient solution for internet access from AWS private subnets.
- B. Attaching an Internet Gateway directly to private subnets would make them publicly accessible, violating the 'no inbound internet access' policy.
- D. VPC endpoints are for specific AWS services, not general internet access. Using an Internet Gateway for updates would still expose the instances if directly attached to private subnets.
NAT Gateway
A Network Address Translation (NAT) service that enables instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating a connection with those instances. It is deployed in a public subnet.
- Provides outbound internet access for instances in private subnets.
- Prevents inbound internet access to instances in private subnets.
- Requires an Elastic IP address and must be deployed in a public subnet.
- Highly available and managed service.
Memory trick: NAT Gateway is like a 'one-way door' to the internet from your private subnet.