Courseiva
Infrastructure Security →mediumMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A security engineer manages a fleet of Amazon EC2 instances in a VPC. The instances must be able to reach the internet for software updates, but they must not be directly reachable from the internet. The VPC has a private subnet with a route to a NAT gateway in a public subnet. The engineer notices that instances in the private subnet cannot reach the internet, and the NAT gateway's CloudWatch metrics show zero active connections. Which of the following is the MOST likely cause?

⚠ Common exam trap

The trap here is assuming that a NAT gateway automatically enables internet access for private subnets without verifying the route table configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The private subnet's route table does not have a route to the NAT gateway.

The NAT gateway's zero active connections indicate that traffic from the private instances is not reaching it. The most common reason is a missing or incorrect route in the private subnet's route table directing internet-bound traffic to the NAT gateway. Without that route, instances have no path to the NAT gateway, so they cannot access the internet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The security group on the instances does not allow outbound traffic to the NAT gateway.

    Why it's wrong here

    Security groups are stateful and by default allow all outbound traffic. Even if outbound rules were restricted, the NAT gateway's metrics would still show connection attempts if traffic reached it. The zero active connections indicates traffic never reaches the NAT gateway, so a security group issue on the instances is not the primary cause.

  • ✓

    The private subnet's route table does not have a route to the NAT gateway.

    Why this is correct

    For a private subnet to use a NAT gateway, its route table must have a route with destination 0.0.0.0/0 pointing to the NAT gateway. If that route is missing or misconfigured, instances cannot send traffic to the NAT gateway, resulting in zero active connections. This is the most likely cause given the symptoms.

  • ✗

    The NAT gateway is not associated with an Elastic IP address.

    Why it's wrong here

    A NAT gateway requires an Elastic IP address to function, but if it were missing, the NAT gateway would fail to create or would be in a failed state. The scenario states the NAT gateway exists and has CloudWatch metrics, implying it was created successfully with an EIP. Thus, this is not the likely cause.

  • ✗

    The network ACL on the private subnet is blocking outbound traffic to the NAT gateway.

    Why it's wrong here

    A network ACL could block traffic, but the default network ACL allows all inbound and outbound traffic. If it were blocking, the NAT gateway would still see connection attempts if they reached it. However, the zero active connections suggests traffic never leaves the instances, pointing more to a routing issue than an ACL.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.