SCS-C02 Infrastructure Security Practice Question
A company has a VPC with public and private subnets. An EC2 instance in a private subnet needs to download patches from the internet. Which combination of components provides a highly available, managed solution? (Select TWO.)
⚠ Common exam trap
Many candidates think a single NAT gateway is sufficient for high availability, but AWS requires one NAT gateway per Availability Zone to survive an AZ failure, and they may also confuse a VPC endpoint for S3 as a general internet access solution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a route to the private subnet's route table pointing 0.0.0.0/0 to the NAT gateway.
A NAT gateway enables outbound internet access for instances in a private subnet while preventing inbound connections from the internet. It is a managed AWS service that automatically scales and is highly available within a single Availability Zone. By adding a route for 0.0.0.0/0 to the NAT gateway in the private subnet's route table, traffic destined for the internet is forwarded to the NAT gateway, which then uses an internet gateway to reach the internet.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add a route to the private subnet's route table pointing 0.0.0.0/0 to the NAT gateway.
Why this is correct
Adding a route to the private subnet's route table with destination 0.0.0.0/0 and target the NAT gateway is the precise mechanism that enables outbound internet access from private instances. The NAT gateway itself resides in a public subnet and relies on its own route to the internet gateway, but private subnets require this explicit route to direct traffic to the NAT gateway. Without this route, private instances have no path to the internet, making this the correct action to satisfy the requirement.
- ✗
Launch a NAT instance in a public subnet.
Why it's wrong here
A NAT instance is an EC2 instance configured to forward traffic, requiring you to disable Source/Destination checks, patch the operating system, and add a public IP or Elastic IP. It is a self-managed solution with limited bandwidth (depending on instance type) and introduces a single point of failure unless you implement custom `keepalived` or route table failover scripts. Because the question asks for a managed and highly available approach, a NAT instance is not the best answer even though it could technically provide connectivity if properly configured.
- ✗
Create a VPC endpoint for Amazon S3.
Why it's wrong here
A VPC endpoint for Amazon S3 provides private connectivity only to S3 service (via a gateway endpoint or interface endpoint), not to the general internet. It cannot be used as a default route for all outbound traffic; it only covers the IPv4 prefix list for S3. Therefore, it does not allow private instances to reach other internet destinations, making it an incomplete solution for the stated requirement.
- ✓
Create a NAT gateway in each Availability Zone.
Why this is correct
Creating a NAT gateway in each Availability Zone is the recommended pattern for high availability because each Availability Zone's private subnet can have a dedicated route to the NAT gateway in that same zone. This design avoids cross-Availability Zone data transfer costs and ensures that if one Availability Zone fails, workloads in the remaining zones still have outbound internet path. A single NAT gateway would create a regional single point of failure, so per-AZ NAT gateways are a correct and robust architecture.
- ✗
Attach an internet gateway to the VPC.
Why it's wrong here
Attaching an internet gateway to a VPC enables internet connectivity only for resources that have public IP addresses and a route table entry pointing 0.0.0.0/0 to the gateway. Instances in private subnets do not have public IP addresses and their route tables do not contain a default route to the internet gateway, so they remain unable to reach the internet. The internet gateway acts as a target for public-facing traffic, but private instances require a NAT gateway to initiate outbound connections without being directly reachable from the internet.
Visual reference
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.