Courseiva
Network Management and OperationsmediumMultiple ChoiceObjective-mapped

ANS-C01 Network Management and Operations Practice Question

A company uses a VPC with multiple subnets in different Availability Zones. The VPC has a NAT Gateway in a public subnet of us-east-1a, and a second NAT Gateway in us-east-1b for high availability. Each private subnet in us-east-1a routes 0.0.0.0/0 to the NAT Gateway in us-east-1a, and private subnets in us-east-1b route to the NAT Gateway in us-east-1b. The company's EC2 instances in private subnets need to access an external service using IPv6. The VPC is not configured for IPv6. The network engineer needs to enable IPv6 connectivity for these instances. Which solution is the most cost-effective and scalable?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Add an IPv6 CIDR block to the VPC, assign IPv6 addresses to private subnets, and add a route for ::/0 to an egress-only internet gateway.

Since the VPC is not IPv6-enabled, adding an IPv6 CIDR block assigns IPv6 addresses to subnets. For outbound-only IPv6 access from private subnets, an egress-only internet gateway (EIGW) is the appropriate and most cost-effective solution because it allows outbound traffic to the internet while preventing inbound connections, similar to a NAT gateway for IPv4. A route for ::/0 to the EIGW from the private subnets achieves the goal. Option A is incorrect because NAT64 translates IPv6 to IPv4, but the target service uses IPv6, so no translation is needed. Option C is incorrect because an internet gateway would permit inbound traffic and instances would need public IPv6 addresses, which is not stated and is less secure. Option D is incorrect because NAT Gateways do not support IPv6.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Add an IPv6 CIDR block to the VPC and configure a NAT64 gateway to translate IPv6 to IPv4.

    Why it's wrong here

    NAT64 is for IPv6-only clients accessing IPv4 services, not the other way.

  • Add an IPv6 CIDR block to the VPC, assign IPv6 addresses to private subnets, and add a route for ::/0 to an egress-only internet gateway.

    Why this is correct

    Egress-only IGW allows outbound IPv6 traffic from private subnets.

  • Attach an internet gateway to the VPC and add a route for ::/0 to the internet gateway in the private subnets.

    Why it's wrong here

    Internet gateway requires instances to have public IPv6 addresses, which is not typical for private subnets.

  • Add an IPv6 CIDR block to the VPC and use the existing NAT Gateways with IPv6.

    Why it's wrong here

    NAT Gateways do not support IPv6.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 1,621 original ANS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.