Courseiva
Cloud Technology and ServicesmediumMultiple ChoiceObjective-mapped

CLF-C02 Cloud Technology and Services Practice Question

A company launches EC2 instances in a public subnet of their VPC. For these instances to communicate directly with the internet — both to receive inbound requests and to make outbound requests — which VPC component must be attached to the VPC and referenced in the subnet's route table?

⚠ Common exam trap

Many exam-takers confuse a NAT Gateway with an Internet Gateway, mistakenly thinking a NAT Gateway alone can provide bidirectional internet access, when in fact a NAT Gateway only supports outbound traffic and requires an IGW for internet connectivity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Internet Gateway

An Internet Gateway (IGW) is a horizontally scaled, redundant VPC component that enables communication between a VPC and the internet. For EC2 instances in a public subnet to both receive inbound requests and make outbound requests, the IGW must be attached to the VPC and a route in the subnet's route table must point 0.0.0.0/0 (or a specific public IP range) to the IGW. Without the IGW, the instances have no path to the internet, even if they have public IP addresses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • NAT Gateway

    Why it's wrong here

    A NAT Gateway enables instances in private subnets to initiate outbound internet connections, but it does not accept inbound connections from the internet, as it only tracks outbound flows. In a public subnet, the required gateway for bidirectional traffic is an Internet Gateway, and a NAT Gateway would not make instances publicly reachable. Therefore, it is not the correct answer.

  • VPC Peering connection

    Why it's wrong here

    A VPC peering connection links two VPCs using AWS's private backbone, allowing private IP traffic between them without traversing the public internet. It does not provide a route to the internet for either VPC, and peering has no transitive routing or an Internet Gateway component. Consequently, it cannot give instances in a public subnet internet access.

  • Internet Gateway

    Why this is correct

    An Internet Gateway enables instances in public subnets to communicate bidirectionally with the internet. The subnet's route table must direct 0.0.0.0/0 traffic to the IGW for instances with public IPs to be reachable from the internet.

  • Virtual Private Gateway

    Why it's wrong here

    A Virtual Private Gateway (VGW) is the AWS-side endpoint for site-to-site VPN connections, terminating IPsec tunnels between your VPC and an on-premises network. It does not provide general internet access for VPC instances; it only routes traffic to a corporate network over an encrypted tunnel. Since the question asks about enabling internet access for a public subnet, a VGW is irrelevant.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 988 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.