Courseiva
Network Security, Compliance and GovernancemediumMultiple ChoiceObjective-mapped

ANS-C01 Network Security, Compliance and Governance Practice Question

A company has a VPC with public and private subnets. An EC2 instance in a private subnet needs to download patches from the internet. The company wants to ensure that all outbound traffic is logged and that only specific destinations are allowed. Which solution meets these requirements?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Deploy a NAT gateway in a public subnet and enable VPC Flow Logs

A NAT gateway in a public subnet allows outbound internet access from private instances, and VPC Flow Logs can capture traffic metadata. Option B is wrong because a proxy server in a public subnet requires additional configuration and is not the default AWS solution. Option C is wrong because a NAT instance can also work but requires manual management and does not inherently provide logging; Flow Logs still need to be enabled. Option D is wrong because an internet gateway alone does not provide private subnet access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Deploy a NAT gateway in a public subnet and enable VPC Flow Logs

    Why this is correct

    NAT gateway provides outbound internet access and VPC Flow Logs capture traffic metadata for logging.

  • Deploy a proxy server in a public subnet and configure the EC2 instance to use it

    Why it's wrong here

    Proxies can work but add complexity; NAT gateway is the standard.

  • Deploy a NAT instance in a public subnet and enable VPC Flow Logs

    Why it's wrong here

    Deploying a NAT instance provides outbound internet connectivity for private subnets, and VPC Flow Logs addresses the logging requirement. However, a NAT instance itself does not natively offer the granular, scalable mechanism to enforce allowing *only specific destinations* for outbound traffic. While `iptables` could be configured on the instance, this is not the managed AWS solution implied for robust destination filtering. This option would be a suitable choice if the primary need was simply outbound internet access and logging, without the specific requirement for sophisticated, managed destination-based traffic restriction.

  • Attach an internet gateway to the VPC and assign a public IP to the EC2 instance

    Why it's wrong here

    This would make the instance public, which is not desired.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This ANS-C01 question is part of Courseiva's 1,621-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.