ANS-C01 Network Implementation Practice Question
A company has deployed a VPC with a public subnet and a private subnet in each of two Availability Zones. They have an Application Load Balancer (ALB) in the public subnets and EC2 instances in the private subnets. The EC2 instances need to access an external API over HTTPS. What is the MOST secure way to provide this access?
⚠ Common exam trap
A common mix-up: candidates confuse VPC endpoints (PrivateLink) with NAT Gateways, assuming a VPC endpoint can be used for any external API, but VPC endpoints only work for services that explicitly support AWS PrivateLink or are AWS services, not arbitrary public HTTPS APIs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a NAT Gateway in each public subnet and add a default route in the private subnet route tables pointing to the NAT Gateway.
A NAT Gateway in each public subnet provides a managed, highly available path for EC2 instances in private subnets to initiate outbound HTTPS connections to the internet while preventing inbound connections from reaching them. Adding a default route (0.0.0.0/0) in the private subnet route tables pointing to the NAT Gateway ensures traffic destined for the external API is forwarded through the NAT Gateway, which performs source network address translation (SNAT) using its Elastic IP. This is the most secure method because it avoids exposing the EC2 instances directly to the internet and leverages AWS-managed infrastructure for scalability and fault tolerance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy a NAT Gateway in each public subnet and add a default route in the private subnet route tables pointing to the NAT Gateway.
Why this is correct
NAT Gateway provides outbound-only internet access securely.
- ✗
Create a VPC endpoint for the external API service.
Why it's wrong here
VPC endpoints only work for AWS services.
- ✗
Assign public IP addresses to the EC2 instances and allow outbound traffic in the security group.
Why it's wrong here
Public IPs expose instances to inbound traffic.
- ✗
Set up a VPN connection to an on-premises network that has internet access.
Why it's wrong here
Overly complex and not directly needed.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,621 original ANS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
5 more ways this is tested on ANS-C01
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company has deployed a VPC with public and private subnets. The private subnets need outbound internet access for software updates. Which service should be used to provide this access without exposing the instances to inbound traffic?
easy- A.Attach an Internet Gateway to the VPC and add a default route to it from the private subnets.
- B.Set up a VPN connection to an on-premises network that has internet access.
- C.Use a Direct Connect connection to route traffic through an on-premises internet gateway.
- ✓ D.Deploy a NAT Gateway in a public subnet and add a default route to it from the private subnets.
Why D: A NAT Gateway, deployed in a public subnet with an Elastic IP, allows instances in private subnets to initiate outbound traffic to the internet (e.g., for software updates) while preventing any unsolicited inbound connections from the internet. The private subnet’s route table directs default traffic (0.0.0.0/0) to the NAT Gateway, which performs source network address translation (SNAT) to the gateway’s Elastic IP, enabling outbound-only access.
Variation 2. A company is deploying a fleet of EC2 instances in private subnets. The instances need to download patches from the internet. The company wants to minimize cost and avoid managing NAT instances. The VPC has an internet gateway (IGW) attached. What should the company do?
medium- A.Attach the IGW to the private subnet route table.
- ✓ B.Deploy a NAT Gateway in a public subnet and update the private subnet route tables.
- C.Create a VPC endpoint for internet access.
- D.Launch a NAT instance and configure routing.
Why B: A NAT Gateway, deployed in a public subnet with an Elastic IP, allows instances in private subnets to initiate outbound traffic to the internet (e.g., for patch downloads) while preventing inbound connections from the internet. This solution is fully managed by AWS, eliminating the need to manage a NAT instance, and it is cost-effective compared to maintaining a dedicated instance. The private subnet route table must have a default route (0.0.0.0/0) pointing to the NAT Gateway ID.
Variation 3. A company is deploying a VPC with public and private subnets. The private subnets need outbound internet access for updates, but must not be directly reachable from the internet. Which AWS service should be used to achieve this?
easy- A.AWS Site-to-Site VPN
- B.AWS Direct Connect
- C.Internet Gateway
- ✓ D.NAT Gateway
Why D: A NAT Gateway enables instances in private subnets to initiate outbound IPv4 traffic to the internet (e.g., for software updates) while preventing unsolicited inbound connections from the internet. It translates the private source IP to the NAT Gateway's Elastic IP address, so responses return to the gateway, which then forwards them to the private instance. This meets the requirement of outbound-only internet access without direct internet reachability.
Variation 4. A company is deploying a VPC with public and private subnets. They want to allow instances in a private subnet to access the internet for software updates while preventing inbound internet traffic. Which configuration should be used?
easy- A.Create a VPC endpoint for internet access
- B.Use a transit gateway with a NAT instance
- C.Attach an internet gateway to the VPC and add a route in the private subnet to the internet gateway for 0.0.0.0/0
- ✓ D.Attach an internet gateway to the VPC, and create a NAT gateway in a public subnet. Add a route in the private subnet route table to the NAT gateway for 0.0.0.0/0
Why D: A NAT gateway, deployed in a public subnet with an Internet Gateway (IGW) attached, allows instances in private subnets to initiate outbound IPv4 traffic to the internet (e.g., for software updates) while the IGW's one-way translation prevents unsolicited inbound traffic from reaching the private instances. The private subnet's route table must include a default route (0.0.0.0/0) pointing to the NAT gateway's elastic network interface.
Variation 5. A company is designing a VPC with public and private subnets. They want EC2 instances in private subnets to be able to access the internet for software updates. Which AWS service should they use?
easy- A.AWS Direct Connect
- B.Internet Gateway (IGW)
- C.VPC Peering connection
- ✓ D.NAT Gateway
Why D: A NAT Gateway enables EC2 instances in private subnets to initiate outbound traffic to the internet (e.g., for software updates) while preventing the internet from initiating inbound connections to those instances. It translates the private IP addresses of the instances to the NAT Gateway's Elastic IP address using source network address translation (SNAT), allowing them to reach public endpoints.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.