Enable Outbound Internet Access While Blocking Inbound Traffic with NAT Gateway
A security engineer is designing a VPC with public and private subnets. The application servers in the private subnets need to access the internet for software updates, but must not be directly reachable from the internet. Which TWO actions satisfy these requirements?
Quick Answer
The answer is deploying a NAT gateway in a public subnet. This satisfies the requirement because a NAT gateway, placed in a public subnet with an Elastic IP and a route to an internet gateway, allows instances in private subnets to initiate outbound internet connections—such as for software updates—while the gateway’s stateful firewall automatically drops any unsolicited inbound traffic from the internet. The private subnet’s route table must have a default route (0.0.0.0/0) pointing to the NAT gateway’s private IP to forward outbound traffic. On the AWS Certified Security Specialty SCS-C02 exam, this scenario tests your understanding of how to enable outbound internet from private subnets using NAT gateway without exposing resources to inbound attacks. A common trap is confusing a NAT gateway with a NAT instance or assuming a public subnet is required for the private instances themselves. Memory tip: think “NAT out, never in”—the gateway only translates outbound requests, never unsolicited inbound ones.
⚠ Common exam trap
Many candidates confuse a NAT gateway with an internet gateway, mistakenly thinking that adding an internet gateway to a private subnet's route table provides outbound-only access, when in fact it enables bidirectional internet connectivity and requires public IPs on the instances.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a route in the private subnet's route table pointing to the NAT gateway.
Option B is correct because the private subnet's route table must contain a route (typically 0.0.0.0/0) targeting the NAT gateway so that outbound internet-bound traffic from private instances is forwarded through the NAT. Option E is correct because the NAT gateway itself must reside in a public subnet with a route to an internet gateway, allowing it to translate private instances' traffic to the internet while preventing inbound connections to those instances. Together, B and E provide outbound-only internet access for the private application servers. Option A is wrong because allowing inbound 0.0.0.0/0 on the private subnet's security group would make the servers reachable from the internet, violating the requirement. Option C is wrong because attaching an internet gateway to a private subnet's route table would make the subnet public and expose the instances directly. Option D is wrong because a VPC gateway endpoint for Amazon S3 only provides private access to S3, not general internet access for software updates.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the private subnet's security group to allow inbound traffic from 0.0.0.0/0.
Why it's wrong here
Allowing 0.0.0.0/0 inbound on the private subnet's security group permits unsolicited connections from the internet, contradicting the isolation requirement. That rule suits public-facing load balancers or bastion hosts. Outbound internet access is controlled by route tables and NAT, not inbound security group rules.
- ✓
Add a route in the private subnet's route table pointing to the NAT gateway.
Why this is correct
A NAT gateway performs source network address translation for outbound traffic, letting private subnet instances initiate internet connections for updates while remaining unreachable inbound. The private route table's 0.0.0.0/0 route to the NAT gateway satisfies both requirements.
- ✗
Attach an internet gateway to the private subnet's route table.
Why it's wrong here
An internet gateway in a private subnet's route table makes those instances directly routable from the internet, defeating the private design. Internet gateways belong on public subnet route tables for bidirectional public traffic. Outbound-only access requires a NAT gateway instead.
- ✗
Create a VPC gateway endpoint for Amazon S3.
Why it's wrong here
A gateway endpoint only routes traffic to Amazon S3, so software updates from other internet sources remain unreachable. Gateway endpoints suit private access to S3 or DynamoDB without internet exposure. The requirement is general outbound internet access, which needs a NAT gateway.
- ✓
Deploy a NAT gateway in a public subnet.
Why this is correct
A NAT gateway placed in a public subnet performs source NAT for outbound traffic from private subnets, letting instances reach the internet for updates while remaining unreachable inbound. This satisfies the constraint that private-subnet servers initiate outbound connections without exposing themselves to inbound internet access.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SCS-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security engineer is configuring a new VPC with public and private subnets. The application servers in the private subnet need to download patches from the internet. Which component is required?
easy- A.VPC endpoint
- B.Direct Connect
- C.Internet gateway
- ✓ D.NAT gateway
Why D: A NAT gateway is required to allow instances in a private subnet to initiate outbound traffic to the internet (e.g., to download patches) while preventing the internet from initiating inbound connections to those instances. The NAT gateway resides in a public subnet with an attached Internet Gateway, and it translates the private IP addresses of the application servers to the NAT gateway's Elastic IP address for outbound traffic.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.