AWS Certified SysOps Administrator – AssociateNetworking and Content DeliveryEasy
A SysOps administrator is configuring a new VPC and needs to ensure that EC2 instances in private subnets can initiate outbound connections to the internet for software updates, but prevent unsolicited inbound connections. Which AWS networking component should be deployed to achieve this requirement?
- AVPN Gateway (VGW)
- BInternet Gateway (IGW)
- CVPC Endpoint
- DNAT Gateway (NAT GW)
Show answer & explanationAnswer & explanation
Correct answer: D. NAT Gateway (NAT GW)
A NAT Gateway allows instances in private subnets to connect to the internet or other AWS services, but prevents the internet from initiating connections with those instances. This perfectly matches the requirement for outbound-only internet access while blocking unsolicited inbound connections.
Why the other options are wrong
- A. A VPN Gateway (VGW) is used to establish secure connections between your VPC and an on-premises network, not to enable internet access for private subnets.
- B. An Internet Gateway (IGW) allows both outbound and unsolicited inbound internet traffic, which does not meet the security requirement.
- C. VPC Endpoints provide private connectivity to AWS services without traversing the internet, but they do not enable general internet access for software updates.
NAT Gateway
A Network Address Translation (NAT) Gateway allows instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating connections with those instances.
- Provides outbound internet connectivity for private subnets.
- Blocks unsolicited inbound connections from the internet.
- Highly available by default within an Availability Zone.
- Requires an Elastic IP address and must be in a public subnet.
Memory trick: NAT is your 'No Access To' inbound, 'Net Access Through' outbound friend.