AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesEasy

A company is migrating a legacy application to AWS. The application uses a traditional relational database that needs to be accessible from private subnets within a VPC. The application servers in the private subnets also need to download software updates from the internet but should not be directly exposed to public inbound traffic. Which networking component should be used to enable outbound internet connectivity for the private subnets?

  1. AVPN Connection
  2. BVPC Endpoint
  3. CInternet Gateway
  4. DNAT Gateway
Show answer & explanation

Correct answer: D. NAT Gateway

A NAT Gateway allows instances in private subnets to initiate outbound connections to the internet while preventing unsolicited inbound connections from the internet. This perfectly matches the requirement for private subnet instances to access updates without public exposure.

Why the other options are wrong

  • A. A VPN Connection securely connects your VPC to your on-premises network, not for providing outbound internet access to private subnets.
  • B. A VPC Endpoint allows private connectivity to AWS services without traversing the internet, but it does not provide general outbound internet access for software updates.
  • C. An Internet Gateway allows direct internet access for public subnets and is used for both inbound and outbound traffic, which would expose private subnet instances to the internet.

NAT Gateway

A Network Address Translation (NAT) Gateway allows instances in a private subnet to connect to services outside your VPC (e.g., the internet) but prevents external services from initiating a connection with those instances.

  • Allows outbound internet access from private subnets.
  • Prevents inbound internet access to private subnets.
  • Deployed in a public subnet.
  • Requires an Elastic IP address.

Memory trick: NAT Gateway: No Access In, Traffic Out.

More Design Secure Architectures questions