AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesEasy

A global consulting firm is migrating its internal knowledge base application to AWS. The application runs on Amazon EC2 instances in private subnets and needs to access external APIs on the internet for data enrichment. However, these EC2 instances should not be directly accessible from the internet. Which solution should the Solutions Architect implement to allow outbound internet access while maintaining security?

  1. AAssign public IP addresses to the EC2 instances in the private subnets.
  2. BDeploy a NAT Gateway in a public subnet and configure routes from private subnets.
  3. CUse a VPC Endpoint for each external API accessed by the application.
  4. DConfigure an Internet Gateway and attach it to the VPC.
Show answer & explanation

Correct answer: B. Deploy a NAT Gateway in a public subnet and configure routes from private subnets.

A NAT Gateway allows instances in private subnets to initiate outbound connections to the internet (for external APIs and data enrichment) while preventing any direct inbound connections from the internet, thus maintaining security by keeping the instances private.

Why the other options are wrong

  • A. Assigning public IP addresses to EC2 instances in private subnets would make them directly accessible from the internet, violating the security requirement.
  • C. VPC Endpoints provide private connectivity to *AWS services* only, not general internet APIs or external services.
  • D. An Internet Gateway allows direct internet access for public subnets; it does not provide outbound-only access for instances in private subnets without exposing them.

NAT Gateway

A Network Address Translation (NAT) Gateway allows instances in a private subnet to connect to the internet or other AWS services outside the VPC, but prevents external services from initiating connections with those instances, enhancing security.

  • Enables outbound internet connectivity for private subnets.
  • Prevents inbound internet-initiated connections to private subnets.
  • Requires deployment in a public subnet with an Elastic IP.
  • Commonly used for software updates, external API calls, and patching.

Memory trick: NAT Gateway: No Inbound, All Outbound.

More Design Secure Architectures questions