AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesHard

A global consulting firm is migrating its internal knowledge base application to AWS. The application runs on EC2 instances in a private subnet. These instances need to download software updates regularly from vendor websites on the internet. However, the security policy strictly prohibits any inbound internet connections to these EC2 instances. Which AWS networking component should be implemented to allow the EC2 instances to initiate outbound connections to the internet while preventing any unsolicited inbound traffic?

  1. AInternet Gateway attached to the VPC
  2. BEgress-only Internet Gateway attached to the private subnet
  3. CNAT Gateway deployed in a public subnet with a route from the private subnet
  4. DAssigning public IPv4 addresses to the EC2 instances in the private subnet
Show answer & explanation

Correct answer: C. NAT Gateway deployed in a public subnet with a route from the private subnet

A NAT Gateway in a public subnet, with a route from the private subnet, allows instances in the private subnet to initiate outbound connections to the internet while preventing unsolicited inbound connections. This precisely meets the requirements for outbound-only internet access and strict inbound isolation for IPv4 traffic.

Why the other options are wrong

  • A. An Internet Gateway (IGW) allows both inbound and outbound traffic to/from public subnets, which violates the 'no inbound internet connections' requirement for instances in a private subnet.
  • B. An Egress-only Internet Gateway is exclusively for IPv6 traffic. The scenario implies IPv4, and even for IPv6, it's typically used for direct-to-internet access from private subnets, not via a NAT for IPv4.
  • D. Assigning public IPv4 addresses to EC2 instances, even in a private subnet (which is not standard practice for private subnets), would typically expose them to inbound internet connections unless very strict security groups/NACLs are in place, which goes against the principle of using a private subnet for isolation and still doesn't provide the NAT functionality.

NAT Gateway

A Network Address Translation (NAT) Gateway allows instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating a connection with those instances.

  • Enables outbound internet access from private subnets.
  • Prevents inbound internet connections from the internet.
  • Requires deployment in a public subnet and a route table entry from the private subnet.

Memory trick: NAT Gateway: No Inbound, All Outbound for Private Zones.

More Design Secure Architectures questions