Courseiva
Security and Compliance →mediumMultiple Choice

CLF-C02 Security and Compliance Practice Question

Which AWS networking feature prevents resources in a private subnet from directly receiving inbound connections from the internet, while still allowing them to initiate outbound connections?

⚠ Common exam trap

Test-takers frequently confuse a NAT Gateway with an Internet Gateway, assuming both provide internet access, but the key distinction is that an Internet Gateway allows bidirectional inbound connections, while a NAT Gateway specifically prevents unsolicited inbound connections from the internet.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NAT Gateway

A NAT Gateway enables instances in a private subnet to initiate outbound connections to the internet (e.g., for software updates) while preventing any unsolicited inbound connections from the internet. It achieves this by translating the private IP of the instance to the NAT Gateway's Elastic IP for outbound traffic, and only forwarding return traffic that matches an established outbound session.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Internet Gateway

    Why it's wrong here

    An internet gateway is a VPC component that provides a target for internet-routable traffic and enables communication between a VPC and the public internet. Resources in public subnets with public IPs can use it for both inbound and outbound connectivity, but the internet gateway does not perform source-network address translation on behalf of private instances. A private subnet instance has only a private IP and no route through an internet gateway, so this component by itself cannot enable outbound internet access while blocking unsolicited inbound access; that is the NAT gateway's purpose.

  • ✓

    NAT Gateway

    Why this is correct

    A NAT gateway is a managed AWS service deployed in a public subnet with an Elastic IP address. It is placed in private subnet route tables as the destination for 0.0.0.0/0, so instances there can initiate outbound traffic to the internet. The NAT gateway translates their private source IPs to its Elastic IP for outbound packets, and for return traffic it forwards responses back; unsolicited inbound connections from the internet are dropped because there is no port forwarding or inbound mapping. This makes a NAT gateway the correct answer for one-way internet access.

  • ✗

    Security Groups

    Why it's wrong here

    Security groups are instance-level stateful firewalls that evaluate traffic against allow rules you define. They can block inbound traffic to an instance, but they do not perform any IP address translation, so an instance in a private subnet with a private IP cannot use a security group alone to reach the internet. The one-way NAT that gives private instances outbound connectivity while preventing unsolicited inbound is specifically the NAT gateway's job.

  • ✗

    Network ACLs

    Why it's wrong here

    Network ACLs are stateless, subnet-level filters that inspect packets as they enter or leave a subnet. Because they are stateless, you must configure separate inbound and outbound rules, and they can certainly drop unwanted traffic at the subnet boundary. However, a network ACL does not translate private source IPs into public IPs, so it cannot supply outbound internet access to private subnet resources; it only filters traffic that already has a routing path. Any outbound connection still requires a public IP or a NAT device.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This CLF-C02 question is part of Courseiva's 993-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.