AWS Certified Developer – Associate (DVA-C02)Development with AWS ServicesMedium

A developer is implementing a feature where an AWS Lambda function needs to make HTTP requests to an external API over the internet. The Lambda function is configured to run within a private VPC subnet for security reasons, without direct internet access. What is the MOST appropriate and secure way to allow the Lambda function to access the external API?

  1. ADeploy a NAT Gateway in a public subnet and configure a route table.
  2. BConfigure the Lambda function with a public IP address.
  3. CAttach an Internet Gateway to the VPC.
  4. DUse a VPC Endpoint for the external API.
Show answer & explanation

Correct answer: A. Deploy a NAT Gateway in a public subnet and configure a route table.

When a Lambda function is in a private subnet, it needs a NAT Gateway in a public subnet to route outbound internet traffic. The private subnet's route table must be configured to send internet-bound traffic through the NAT Gateway, which then uses the Internet Gateway for external connectivity. This provides secure outbound access without exposing the Lambda function directly to the internet.

Why the other options are wrong

  • B. Lambda functions cannot be directly configured with public IP addresses when associated with a VPC. They reside in ENIs within subnets.
  • C. An Internet Gateway (IGW) allows internet access to/from public subnets, but it doesn't provide internet access for instances in private subnets without a NAT Gateway.
  • D. VPC Endpoints are used for accessing AWS services privately within the VPC, not for external public APIs on the internet.

NAT Gateway for Lambda in VPC

A NAT Gateway allows instances (like Lambda ENIs) in a private subnet to connect to the internet or other AWS services outside the VPC, while preventing the internet from initiating connections to those instances. It must be deployed in a public subnet.

  • Enables outbound internet access for private subnets.
  • Must be deployed in a public subnet.
  • Requires a route table entry in the private subnet.
  • Provides high availability and bandwidth.
  • Charged hourly and by data processed.

Memory trick: NAT Gateway 'Navigates' private Lambda to the 'Net'.

More Development with AWS Services questions