Courseiva

DOP-C02 Configuration Management and IaC Practice Question

A DevOps engineer is using AWS CloudFormation to provision a VPC that includes public and private subnets, an Internet Gateway, and NAT Gateways. The engineer wants to ensure that the private subnets have outbound internet access through the NAT Gateways. After deploying the stack, the engineer notices that instances in the private subnets cannot reach the internet. The engineer verifies that the route tables for the private subnets have a route to the NAT Gateway. What is the most likely cause of the issue?

⚠ Common exam trap

The trap here is assuming that as long as the private subnet route table points to the NAT Gateway, internet access works, without verifying that the NAT Gateway's own subnet has a route to the Internet Gateway.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The route in the private subnet's route table points to the NAT Gateway in the same Availability Zone, but the NAT Gateway is in a public subnet that lacks a route to the Internet Gateway.

A NAT Gateway must reside in a public subnet that has a route to an Internet Gateway. If the public subnet's route table lacks a route to the Internet Gateway, the NAT Gateway cannot route traffic to the internet. The engineer should verify that the public subnet's route table has a route to the Internet Gateway and that the NAT Gateway is correctly placed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The NAT Gateway is not associated with an Elastic IP address.

    Why it's wrong here

    A NAT Gateway requires an Elastic IP address, and CloudFormation will fail to create it if not provided. However, if the NAT Gateway was created successfully, it already has an Elastic IP. The issue is not the absence of an EIP but likely a routing or subnet configuration problem.

  • ✗

    The private subnets are missing an association with a network ACL that allows outbound traffic to the NAT Gateway.

    Why it's wrong here

    Network ACLs are stateless and must allow outbound and inbound traffic. However, the default network ACL allows all traffic. If a custom network ACL is used, it could block traffic, but the scenario does not mention custom NACLs. The more likely cause is a missing route in the public subnet.

  • ✓

    The route in the private subnet's route table points to the NAT Gateway in the same Availability Zone, but the NAT Gateway is in a public subnet that lacks a route to the Internet Gateway.

    Why this is correct

    For a NAT Gateway to provide internet access, its public subnet must have a route to an Internet Gateway. If the public subnet's route table does not have a route to the Internet Gateway, the NAT Gateway cannot forward traffic to the internet. This is a common misconfiguration in CloudFormation templates.

  • ✗

    The instances in the private subnets do not have a public IP address, so they cannot communicate with the NAT Gateway.

    Why it's wrong here

    Instances in private subnets do not need public IP addresses to use a NAT Gateway. The NAT Gateway translates the private IP to its own Elastic IP. The absence of a public IP on the instances is expected and not the cause of the connectivity issue.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.