ANS-C01 Network Implementation Practice Question
A company has a VPC with public and private subnets. They have a NAT gateway in a public subnet for outbound internet access from private instances. Which TWO of the following are required for the NAT gateway to function correctly?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A route in the public subnet's route table to an internet gateway
A NAT gateway must be placed in a public subnet and requires an Elastic IP address (E) to enable outbound internet traffic with a source IP that can be routed back. Additionally, the public subnet where the NAT gateway resides must have a route in its route table that points to an internet gateway (C) for the NAT gateway to reach the internet. Security groups are not attached to NAT gateways (they use security groups for attached instances, but NAT gateways themselves are not security group–aware). Network ACLs control traffic at the subnet level but are not a requirement specific to NAT gateway functionality; they can be configured as needed. Deploying the NAT gateway in a private subnet (A) would prevent it from accessing the internet because private subnets do not have direct routes to an internet gateway. Therefore, only options C and E are required.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The NAT gateway is deployed in a private subnet
Why it's wrong here
NAT gateway must be in a public subnet.
- ✗
A security group attached to the NAT gateway
Why it's wrong here
NAT gateways do not support security groups.
- ✓
A route in the public subnet's route table to an internet gateway
Why this is correct
The NAT gateway must be in a public subnet with internet access.
- ✗
A network ACL attached to the NAT gateway's subnet that allows inbound traffic from the internet
Why it's wrong here
NAT gateway only initiates outbound traffic; inbound from internet is not required.
- ✓
An Elastic IP address assigned to the NAT gateway
Why this is correct
NAT gateway needs an Elastic IP to translate private IPs to a public IP.
Visual reference
Go deeper
Related to this question
About these practice questions
This ANS-C01 question is part of Courseiva's 1,621-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on ANS-C01
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company has a VPC with two subnets: a public subnet with a NAT Gateway and a private subnet. An EC2 instance in the private subnet needs to download patches from the internet. The instance has a security group that allows all outbound traffic. The private subnet's route table has a default route (0.0.0.0/0) pointing to the NAT Gateway. However, the instance cannot reach the internet. What is the most likely issue?
medium- A.The security group does not allow inbound traffic from the internet.
- ✓ B.The NAT Gateway is deployed in a private subnet.
- C.The network ACL on the private subnet blocks outbound traffic.
- D.The instance's DNS resolution is not configured correctly.
Why B: The NAT Gateway must be deployed in a public subnet with an Internet Gateway (IGW) attached to its route table to translate private IP addresses to the IGW's public IP. If the NAT Gateway is in a private subnet, it has no route to the internet, so traffic from the private EC2 instance reaches the NAT Gateway but cannot be forwarded to the internet. This is the most likely issue because the route table correctly points to the NAT Gateway, but the gateway itself lacks internet connectivity.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.