AWS Certified SysOps Administrator – AssociateReliability and Business ContinuityHard

A client is running a critical application on Amazon EC2 instances within a private subnet. To ensure high availability, the EC2 instances are distributed across multiple Availability Zones and managed by an Auto Scaling group. The application needs to communicate with a third-party API over the internet. To minimize latency and improve resilience for outbound internet access, which networking component should the SysOps Administrator configure?

  1. AA VPC Endpoint for the third-party API.
  2. BA single NAT Gateway in a public subnet.
  3. CAn Internet Gateway attached to the VPC.
  4. DMultiple NAT Gateways, each in a separate public subnet within different Availability Zones.
Show answer & explanation

Correct answer: D. Multiple NAT Gateways, each in a separate public subnet within different Availability Zones.

To ensure high availability and resilience for outbound internet access from private subnets, it is best practice to deploy a NAT Gateway in each Availability Zone where EC2 instances reside. This prevents a single NAT Gateway failure or an AZ outage from disrupting internet access for the entire application.

Why the other options are wrong

  • A. A VPC Endpoint is for accessing AWS services privately, not for accessing third-party APIs over the public internet.
  • B. A single NAT Gateway creates a single point of failure. If that AZ or NAT Gateway fails, internet access for all private subnets is lost.
  • C. An Internet Gateway is necessary for public internet access but does not provide outbound internet access for instances in private subnets directly, nor does it address NAT Gateway resilience.

Highly Available NAT Gateway

To ensure highly available outbound internet access for instances in private subnets, deploy a NAT Gateway in each Availability Zone with a route table entry pointing to it from the private subnets in that AZ.

  • NAT Gateways allow private instances to initiate outbound connections.
  • A single NAT Gateway is an AZ-level resource and can be a single point of failure.
  • Deploying multiple NAT Gateways across AZs improves resilience.
  • Each NAT Gateway requires a public subnet and an Elastic IP.

Memory trick: Many doors to the internet, never get stuck inside.

More Reliability and Business Continuity questions