SCS-C02 Infrastructure Security Practice Question
A security engineer is designing a VPC with public and private subnets in two Availability Zones. The company requires that all outbound traffic from private subnets to the internet must go through a single, centrally managed NAT gateway. Which combination of resources and route table entries should be used?
⚠ Common exam trap
It's easy for candidates to assume a NAT gateway must be in a private subnet because it handles private traffic, but AWS requires NAT gateways to be in a public subnet with an IGW route to function correctly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A single NAT gateway in a public subnet, and a default route (0.0.0.0/0) in each private subnet route table pointing to that NAT gateway.
A single NAT gateway placed in a public subnet (with an Internet Gateway route) can be used by multiple private subnets across different Availability Zones. Each private subnet's route table must have a default route (0.0.0.0/0) pointing to the NAT Gateway's elastic network interface (ENI) or NAT Gateway ID, ensuring all outbound traffic from private instances is source-NATed through that single, centrally managed device.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A single NAT gateway in a public subnet, and a default route (0.0.0.0/0) in each private subnet route table pointing to that NAT gateway.
Why this is correct
A NAT gateway must reside in a public subnet with an internet gateway as the next-hop for 0.0.0.0/0 so it can perform source NAT for outbound traffic. Placing a single NAT gateway there and adding a 0.0.0.0/0 route in every private subnet route table pointing to that gateway ID centralizes internet egress while keeping instances private. This is the standard minimal design, though it is a single point of failure if that availability zone goes down.
- ✗
A single NAT gateway in a private subnet, and a default route in each private subnet pointing to the NAT gateway.
Why it's wrong here
NAT gateways are an AWS-managed service with an elastic network interface in the subnet where they are created; they cannot work unless that subnet is public and has a route to an internet gateway. If a NAT gateway is placed in a private subnet, it has no internet path, so even if private route tables point to it, outbound traffic will fail at the NAT stage. Additionally, a private subnet's default route pointing to a gateway inside the same subnet creates a routing dependency that cannot satisfy the gateway's need for an internet gateway.
- ✗
One NAT gateway per private subnet, each with a route to an internet gateway.
Why it's wrong here
This configuration mistakenly treats NAT gateways as subnet-specific appliances and claims they need a route to an internet gateway. NAT gateways do not have individual route tables; instead, the route to the internet gateway must be in the route table of the public subnet where the NAT gateway is launched. Creating one NAT gateway per private subnet is wasteful, does not improve availability or performance, and makes egress management fragmented rather than centralized.
- ✗
One NAT gateway per Availability Zone, with routes to the internet gateway.
Why it's wrong here
While one NAT gateway per Availability Zone is an AWS-recommended HA pattern, it is not the answer here because the question asks for centralized egress management; using multiple NAT gateways creates multiple independent egress points that require per-AZ route table entries and can produce asymmetric routing. Also, a NAT gateway cannot have a direct route to an internet gateway; that route belongs to the public subnet where the NAT gateway lives. The extra gateways increase cost and make inspecting egress traffic with central security controls more difficult.
Visual reference
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.