Courseiva
Infrastructure Security →hardMultiple Select

SCS-C02 Infrastructure Security Practice Question

A security engineer is designing a secure VPC architecture for a web application that must be accessible from the internet. The application runs on EC2 instances in private subnets. Which THREE components are required to provide secure internet connectivity?

⚠ Common exam trap

Candidates often confuse the Virtual Private Gateway (VGW) or Transit Gateway as alternatives for internet connectivity, but neither provides NAT or direct internet access; they are designed for hybrid networking and inter-VPC routing, respectively.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Public subnets with routes to the IGW

A is correct because public subnets require routes to the Internet Gateway (IGW) in their route tables to allow traffic from the internet to reach resources in those subnets. For the web application's EC2 instances in private subnets to initiate outbound internet connectivity (e.g., for software updates), a NAT Gateway must be placed in a public subnet with a route to the IGW, and the private subnet's route table must point 0.0.0.0/0 traffic to the NAT Gateway. The IGW attached to the VPC is the foundational component that enables bidirectional internet traffic for the VPC, but it must be explicitly associated with route tables of public subnets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Public subnets with routes to the IGW

    Why this is correct

    A public subnet is defined by having a route table entry with a destination of 0.0.0.0/0 pointing to an Internet Gateway (IGW). This default route enables resources with public IPs to directly send and receive traffic from the internet. While the IGW is the actual gateway, the route in the public subnet is the configuration that makes the subnet public. Therefore, public subnets with routes to the IGW are a critical part of the architecture for internet-facing components.

  • ✓

    NAT Gateway in a public subnet

    Why this is correct

    A NAT Gateway is a managed service deployed in a public subnet to allow instances in private subnets to initiate outbound internet connections while blocking unsolicited inbound traffic. It requires a public subnet to have an Elastic IP and a route from the private subnets' route table to the NAT Gateway's network interface. This provides internet access for private resources without the need for each instance to have a public IP, making it a correct component for private subnet egress.

  • ✗

    Virtual Private Gateway (VGW)

    Why it's wrong here

    A Virtual Private Gateway (VGW) is the AWS-side endpoint for IPsec VPN connections or AWS Direct Connect, used to securely connect an on-premises network to a VPC. It operates at the network layer to extend corporate networks into AWS, but it does not provide general internet access for VPC resources. Since the requirement is for internet connectivity rather than hybrid connectivity, the VGW is not a valid component for this purpose.

  • ✗

    Transit Gateway

    Why it's wrong here

    A Transit Gateway is a central hub used to interconnect multiple VPCs and on-premises networks via VPN or Direct Connect, simplifying network topology at scale. It does not provide internet connectivity itself; you still need an IGW and NAT Gateway for internet egress, even when using a Transit Gateway. A Transit Gateway could be involved in centralized egress, but it is not the component that enables internet access, making it incorrect in this context.

  • ✓

    Internet Gateway (IGW) attached to the VPC

    Why this is correct

    An Internet Gateway (IGW) is a horizontally scaled, redundant VPC component that provides a target for internet-routable traffic and performs NAT for instances with public IPs. It is required for any VPC to have direct internet connectivity, both for public subnet resources and for NAT Gateways to relay traffic. Simply attaching an IGW to a VPC is essential, and while route tables must also point to it, the IGW itself is the correct gateway for enabling internet access.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.