ANS-C01 Network Management and Operations Practice Question
A company uses a VPC with multiple subnets in different Availability Zones. The VPC has a NAT Gateway in a public subnet of us-east-1a, and a second NAT Gateway in us-east-1b for high availability. Each private subnet in us-east-1a routes 0.0.0.0/0 to the NAT Gateway in us-east-1a, and private subnets in us-east-1b route to the NAT Gateway in us-east-1b. The company's EC2 instances in private subnets need to access an external service using IPv6. The VPC is not configured for IPv6. The network engineer needs to enable IPv6 connectivity for these instances. Which solution is the most cost-effective and scalable?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add an IPv6 CIDR block to the VPC, assign IPv6 addresses to private subnets, and add a route for ::/0 to an egress-only internet gateway.
Since the VPC is not IPv6-enabled, adding an IPv6 CIDR block assigns IPv6 addresses to subnets. For outbound-only IPv6 access from private subnets, an egress-only internet gateway (EIGW) is the appropriate and most cost-effective solution because it allows outbound traffic to the internet while preventing inbound connections, similar to a NAT gateway for IPv4. A route for ::/0 to the EIGW from the private subnets achieves the goal. Option A is incorrect because NAT64 translates IPv6 to IPv4, but the target service uses IPv6, so no translation is needed. Option C is incorrect because an internet gateway would permit inbound traffic and instances would need public IPv6 addresses, which is not stated and is less secure. Option D is incorrect because NAT Gateways do not support IPv6.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add an IPv6 CIDR block to the VPC and configure a NAT64 gateway to translate IPv6 to IPv4.
Why it's wrong here
NAT64 is for IPv6-only clients accessing IPv4 services, not the other way.
- ✓
Add an IPv6 CIDR block to the VPC, assign IPv6 addresses to private subnets, and add a route for ::/0 to an egress-only internet gateway.
Why this is correct
Egress-only IGW allows outbound IPv6 traffic from private subnets.
- ✗
Attach an internet gateway to the VPC and add a route for ::/0 to the internet gateway in the private subnets.
Why it's wrong here
Internet gateway requires instances to have public IPv6 addresses, which is not typical for private subnets.
- ✗
Add an IPv6 CIDR block to the VPC and use the existing NAT Gateways with IPv6.
Why it's wrong here
NAT Gateways do not support IPv6.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,621 original ANS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.