Courseiva
Network ImplementationhardMultiple ChoiceObjective-mapped

Why Private Subnet Instances in One Availability Zone Cannot Access the Internet Through a NAT Gateway

A company has a VPC with CIDR 10.0.0.0/16. They have two Availability Zones (us-east-1a and us-east-1b). In each AZ, there is a public subnet (10.0.1.0/24 and 10.0.2.0/24) and a private subnet (10.0.3.0/24 and 10.0.4.0/24). A NAT Gateway is deployed in the public subnet of us-east-1a. The private route tables for both private subnets have a default route pointing to the NAT Gateway. An application team has deployed EC2 instances in the private subnets. They report that instances in us-east-1b cannot access the internet, while instances in us-east-1a can. The NAT Gateway is healthy and has an Elastic IP attached. The route tables for the public subnets have a default route to the Internet Gateway. What is the most likely cause of the issue?

Quick Answer

The answer is that the route table for the public subnet in us-east-1b does not have a default route to the Internet Gateway. This is the most likely cause because while the private subnet instances in us-east-1b can route traffic to the NAT Gateway in us-east-1a across Availability Zones, the NAT Gateway itself must then forward that traffic to the Internet Gateway—but it can only do so if the public subnet where it resides has a proper egress route. When troubleshooting NAT gateway connectivity issues cross availability zone, remember that the NAT Gateway’s own subnet must have a 0.0.0.0/0 route to the Internet Gateway, regardless of which AZ the private instances are in. On the AWS Certified Advanced Networking Specialty ANS-C01 exam, this scenario tests your understanding that NAT Gateways are AZ-resilient but not AZ-agnostic; a common trap is assuming the private subnet route alone is sufficient. Memory tip: “The NAT needs a road to the IGW—check the public subnet route table, not just the private one.”

⚠ Common exam trap

Candidates often assume a NAT Gateway in one AZ can serve private instances in another AZ without any issues, but cross-AZ data transfer charges apply, which can be a concern for cost, but not connectivity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The NAT Gateway has reached the maximum number of concurrent connections

The most likely cause is that the NAT Gateway has reached its maximum number of concurrent connections. When connection limits are exceeded, new outbound connections from instances in any private subnet may fail, leading to internet access issues. This explains why instances in us-east-1a (which may have established connections earlier) can still access the internet, while instances in us-east-1b cannot. Option A is incorrect because the NAT Gateway is correctly placed in a public subnet. Option B is incorrect because the route table of the public subnet in us-east-1b does not affect traffic from private instances; they route directly to the NAT Gateway in us-east-1a. Option D is incorrect because cross-AZ data transfer charges are a cost concern and do not block network traffic. Therefore, the most plausible technical cause is option C.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The NAT Gateway is deployed in a private subnet

    Why it's wrong here

    The NAT Gateway is deployed in a public subnet, not a private subnet.

  • The route table for the public subnet in us-east-1b does not have a default route to the Internet Gateway

    Why it's wrong here

    The public subnet's route table in us-east-1b is irrelevant because the NAT Gateway resides in the public subnet of us-east-1a, which has its own route to the Internet Gateway.

  • The NAT Gateway has reached the maximum number of concurrent connections

    Why this is correct

    Correct. NAT Gateway connection limits can prevent new connections, causing internet access failures for instances that have not already established a session.

  • The NAT Gateway is in a different Availability Zone than the private subnet instances, causing cross-AZ data transfer charges

    Why it's wrong here

    Cross-AZ data transfer charges are a billing consideration and do not directly impair connectivity.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This ANS-C01 question is part of Courseiva's 1,621-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on ANS-C01

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company has a VPC with a CIDR of 10.0.0.0/16. They have two Availability Zones, each with a public subnet (10.0.1.0/24 and 10.0.2.0/24) and a private subnet (10.0.3.0/24 and 10.0.4.0/24). They have an internet-facing ALB in the public subnets and EC2 instances in the private subnets. The EC2 instances need to download updates from the internet. They deploy a NAT Gateway in each public subnet and add routes in the private subnet route tables pointing to the respective NAT Gateway in the same AZ. However, the EC2 instances in AZ2 cannot access the internet, while those in AZ1 can. What is the most likely cause?

medium
  • A.The security group of the EC2 instances in AZ2 is blocking outbound traffic.
  • B.The NAT Gateway in AZ2 does not have an Elastic IP address assigned.
  • C.The private subnet in AZ2 is routing traffic to the NAT Gateway in AZ1, which is in a different Availability Zone and incurs cross-AZ charges but should still work.
  • D.The route table for the private subnet in AZ2 is missing a route to the NAT Gateway.

Why B: The NAT Gateway in AZ2 does not have an Elastic IP address assigned. A NAT Gateway requires an Elastic IP to enable outbound internet traffic. Without it, the NAT Gateway cannot route traffic to the internet, causing the EC2 instances in AZ2 to fail to download updates. Option A is incorrect because security group rules are account-level and would affect both AZs equally. Option C is incorrect because the route table in AZ2 is configured to point to the NAT Gateway in the same AZ, not cross-AZ. Option D is incorrect because the route table for the private subnet in AZ2 does have a route to the NAT Gateway, but the NAT Gateway itself is missing the Elastic IP.

Variation 2. A company is deploying a VPC with public and private subnets in two Availability Zones. The public subnets contain NAT gateways for outbound internet access from the private subnets. The private subnets host web servers that need to make API calls to an external service over the internet. After implementation, the web servers cannot reach the internet. Which configuration is the most likely cause?

medium
  • A.The NAT gateway is placed in a private subnet and does not have a route to the internet gateway.
  • B.The route table for the private subnets is not associated with the VPC's main route table.
  • C.The private subnets have a default route (0.0.0.0/0) pointing to an internet gateway instead of the NAT gateway.
  • D.The public subnets have a default route pointing to the NAT gateway instead of the internet gateway.

Why A: A NAT gateway must be placed in a public subnet with a route to an internet gateway (IGW) to translate private IP addresses for outbound traffic. If the NAT gateway is in a private subnet, it cannot reach the IGW, so the private web servers' traffic destined for the internet (via the 0.0.0.0/0 route pointing to the NAT gateway) will fail, as the NAT gateway itself has no path to the internet.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.