AWS Certified Advanced Networking – Specialty (ANS-C01)Network ImplementationEasy
A solutions architect needs to design a network for a new application that will host multiple microservices. Each microservice needs to be isolated from the others and have its own dedicated subnet. The application requires highly available internet access for outbound connections from these private subnets. Which AWS networking component should the architect use to provide a scalable and highly available outbound internet connection for these private subnets?
- ANAT Gateway
- BVPC Gateway Endpoint
- CVPC Peering
- DInternet Gateway
Show answer & explanationAnswer & explanation
Correct answer: A. NAT Gateway
NAT Gateway is designed to provide highly available outbound internet access for instances in private subnets, allowing them to initiate connections to the internet while preventing unsolicited inbound connections.
Why the other options are wrong
- B. VPC Gateway Endpoints provide private connectivity to specific AWS services (like S3 or DynamoDB) without traversing the internet, not general internet access.
- C. VPC Peering connects two VPCs privately, allowing resources in one VPC to communicate with resources in another, but it does not provide internet access.
- D. An Internet Gateway allows direct internet access for instances in public subnets and is not suitable for private subnets that require isolation from unsolicited inbound connections.
NAT Gateway
A Network Address Translation (NAT) Gateway allows instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating connections with those instances.
- Provides outbound internet connectivity for private subnets.
- Managed AWS service, highly available and scalable.
- Requires an Elastic IP address.
- Placed in a public subnet.
Memory trick: NAT Gateway is the 'No Access To' internet bridge for private subnets.