Courseiva

DOP-C02 Incident and Event Response Practice Question

A DevOps engineer is troubleshooting an issue where an EC2 instance in a private subnet cannot reach the internet. The instance has a route to a NAT gateway. Which TWO of the following should the engineer check? (Choose TWO.)

⚠ Common exam trap

DOP-C02 often tests the misconception that a NAT gateway must be in the same subnet as the instance, or that the instance needs a public IP — both are false, and candidates who confuse NAT gateway placement with instance placement pick the wrong options.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The route table of the private subnet has a route to the NAT gateway

Option B is correct because the private subnet's route table must contain a specific route (typically 0.0.0.0/0) pointing to the NAT gateway; without this route, traffic from the instance will never be forwarded to the NAT gateway even if one exists. Option E is correct because security groups are stateful and must have an outbound rule permitting the traffic (e.g., HTTPS/443 or HTTP/80) to the internet; a restrictive outbound rule will silently drop the packets before they leave the instance. Option A is incorrect because a NAT gateway must reside in a public subnet, not the same private subnet as the instance, and it is associated via the route table rather than subnet co-location. Option C is incorrect because an internet gateway attaches to a VPC, not to a subnet, and private subnets should not have a direct route to an internet gateway. Option D is incorrect because instances in private subnets should not have public IP addresses; outbound internet access via a NAT gateway does not require the instance to have a public IP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The NAT gateway is in the same subnet as the instance

    Why it's wrong here

    A NAT gateway is a managed service that must reside in a public subnet, which has a route to an internet gateway. If the NAT gateway were placed in the same private subnet as the instance, it would have no direct path to the internet and would be unable to forward traffic, so this configuration is incorrect and not the cause of a properly functioning setup.

  • ✓

    The route table of the private subnet has a route to the NAT gateway

    Why this is correct

    For a private subnet to reach the internet via a NAT gateway, its route table must contain a route with a destination of 0.0.0.0/0 and a target of the NAT gateway's ID. This route tells the instance's traffic to be forwarded to the NAT gateway, which then performs source NAT using its Elastic IP. Without this specific route, the instance's outbound packets have no defined next hop to the internet, causing connectivity to fail.

  • ✗

    The internet gateway is attached to the private subnet

    Why it's wrong here

    An internet gateway (IGW) is a VPC-level resource that is attached to the entire VPC, not to individual subnets. Subnets are associated with route tables that either direct traffic to the IGW (making them public) or route through NAT (making them private). A private subnet must not have a route directly to the IGW because that would bypass the NAT gateway and prevent the intended network address translation, so this statement is inherently wrong.

  • ✗

    The instance has a public IP address

    Why it's wrong here

    Private instances do not need public IP addresses because they are designed to be accessed only from within the VPC or via a bastion host, and they initiate outbound internet connections through a NAT gateway. Assigning a public IP would make the instance reachable from the internet (if the security group allows it), which is contrary to a privacy-focused architecture. Even with a public IP, the instance would still rely on the routing table to reach the internet, so this is not a valid explanation for the issue.

  • ✓

    The security group allows outbound traffic to the internet

    Why this is correct

    The security group acts as a virtual firewall for the instance and is stateful, meaning that if it allows outbound traffic, the corresponding return traffic is automatically permitted. However, for new outbound connections—such as an instance fetching packages from the internet—the security group's outbound rules must explicitly permit the traffic (e.g., allow all outbound or specific ports). This is a necessary condition alongside a correct route table; without it, even properly routed packets will be silently dropped.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.