AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesHard
A company is migrating a legacy application to AWS. The application uses a traditional relational database that needs to reside in a private subnet and only be accessible from application servers in another private subnet. The application servers occasionally need to download software updates and security patches from the internet. However, no inbound internet access should be allowed to the application or database servers. Which networking component is required to enable outbound internet access for the application servers while maintaining strict inbound isolation?
- AInternet Gateway
- BPublic IP addresses on the application servers
- CNAT Gateway
- DVPC Endpoint
Show answer & explanationAnswer & explanation
Correct answer: C. NAT Gateway
A NAT Gateway enables instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating a connection with those instances. This perfectly matches the requirement for outbound internet access for application servers while maintaining strict inbound isolation.
Why the other options are wrong
- A. An Internet Gateway allows both inbound and outbound internet access to instances in a public subnet, which violates the 'no inbound internet access' for private subnets.
- B. Assigning public IP addresses to application servers would expose them directly to the internet, violating the 'no inbound internet access' requirement.
- D. A VPC Endpoint allows private connectivity to AWS services without traversing the internet, but it does not provide general outbound internet access for downloading software updates from arbitrary internet locations.
NAT Gateway
A Network Address Translation (NAT) Gateway allows instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating a connection with those instances.
- Enables outbound internet access from private subnets.
- Prevents inbound internet connections to private subnet instances.
- Highly available and managed by AWS.
Memory trick: NAT Gateway: No Inbound, All Outbound for Private Zones.