AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesMedium

A global consulting firm is migrating its internal knowledge base application to AWS. The application uses a multi-tier architecture with an Application Load Balancer (ALB) distributing traffic to Amazon EC2 instances in private subnets. The EC2 instances need to fetch updates from the internet (e.g., OS patches, package updates) but must not be directly accessible from the internet. Which solution should be implemented to allow outbound internet access while maintaining security?

  1. AAttach an Internet Gateway to the private subnets.
  2. BConfigure a NAT Gateway in a public subnet and route private subnet traffic through it.
  3. CAssign Elastic IP addresses to the EC2 instances in the private subnets.
  4. DUse a VPC Endpoint to access the internet directly from private subnets.
Show answer & explanation

Correct answer: B. Configure a NAT Gateway in a public subnet and route private subnet traffic through it.

A NAT Gateway (Network Address Translation Gateway) allows instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating a connection with those instances. By placing the NAT Gateway in a public subnet and configuring routing from the private subnets to it, outbound internet access is enabled without exposing the EC2 instances directly.

Why the other options are wrong

  • A. An Internet Gateway directly attached to private subnets would make the instances publicly accessible, violating the requirement.
  • C. Assigning Elastic IP addresses to instances in private subnets would make them publicly accessible, which is explicitly forbidden.
  • D. VPC Endpoints allow private connections to specific AWS services (e.g., S3, DynamoDB) within AWS, not general internet access.

NAT Gateway

A Network Address Translation (NAT) service that enables instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating a connection with those instances.

  • Deployed in a public subnet.
  • Requires a route table entry from private subnets.
  • Allows outbound internet access for private instances.
  • Not directly accessible from the internet.

Memory trick: NAT Gateway is the 'N'ice 'A'llowance for 'T'raffic from private to public.

More Design Secure Architectures questions