AWS Certified SysOps Administrator – AssociateReliability and Business ContinuityHard

A company's production environment runs on Amazon EC2 instances in a private subnet. These instances need to securely download software updates from public repositories on the internet. The security team mandates that no direct internet access is allowed for these instances, and all outbound traffic must be inspected. Which solution allows the instances to download updates while meeting security requirements?

  1. ASet up a proxy server on an EC2 instance in a public subnet, and configure a NAT Gateway for its internet access.
  2. BConfigure a NAT Gateway in a public subnet and route traffic through it.
  3. CDeploy an Internet Gateway and attach it directly to the private subnet.
  4. DImplement a VPC Endpoint for every public repository.
Show answer & explanation

Correct answer: A. Set up a proxy server on an EC2 instance in a public subnet, and configure a NAT Gateway for its internet access.

A proxy server (e.g., Squid) on an EC2 instance in a public subnet, with its traffic routed through a NAT Gateway, allows outbound internet access for instances in private subnets. All traffic passes through the proxy, enabling inspection and filtering, which meets the security requirement for outbound traffic inspection.

Why the other options are wrong

  • B. A NAT Gateway provides outbound internet access but does not inherently allow for traffic inspection/filtering without additional components.
  • C. An Internet Gateway directly attached to a private subnet would make it a public subnet, violating the 'no direct internet access' rule.
  • D. VPC Endpoints are for specific AWS services, not general public internet repositories.

Outbound Internet Access with Inspection

To allow instances in private subnets to access the internet while enforcing traffic inspection, a common pattern involves routing traffic through a proxy server deployed in a public subnet, which then uses a NAT Gateway for internet connectivity.

  • Private instances route traffic to the proxy server's private IP.
  • The proxy server (e.g., Squid) is in a public subnet and has a route to a NAT Gateway.
  • All outbound traffic passes through the proxy, allowing for inspection, logging, and filtering.
  • NAT Gateway provides the actual internet connectivity for the proxy and handles return traffic.

Memory trick: Private needs internet? Proxy and NAT, that's the ticket!

More Reliability and Business Continuity questions