Drag or tap steps into the slots.
SCS-C02 Data Protection Practice Question
Drag and drop the steps to configure a VPC with private subnets and NAT gateway for outbound internet access in the correct order.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Create VPC, then create subnets, then create and attach Internet Gateway, then create NAT Gateway, then update route tables.
VPC creation, subnets, internet gateway, NAT gateway, and route table update are required for private subnet internet access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create VPC, then create subnets, then create and attach Internet Gateway, then create NAT Gateway, then update route tables.
Why this is correct
This order ensures that the VPC exists, subnets are available for resources, the Internet Gateway is attached to allow public access, the NAT Gateway is deployed in a public subnet, and finally route tables are configured to route private subnet traffic through the NAT Gateway for outbound internet access.
- ✗
Create VPC, then create subnets, then create NAT Gateway, then create and attach Internet Gateway, then update route tables.
Why it's wrong here
This is incorrect because the NAT Gateway requires a public subnet with a route to an Internet Gateway to function. If the Internet Gateway is created after the NAT Gateway, the NAT Gateway cannot be properly associated with a public subnet, leading to failure.
- ✗
Create VPC, then create subnets, then create and attach Internet Gateway, then update route tables, then create NAT Gateway.
Why it's wrong here
This is incorrect because updating route tables before creating the NAT Gateway results in a missing target for the private subnet route. The route tables need the NAT Gateway ID to be specified, which is not available until the NAT Gateway is created.
- ✗
Create VPC, then create NAT Gateway, then create subnets, then create and attach Internet Gateway, then update route tables.
Why it's wrong here
This order is invalid because a NAT Gateway cannot be provisioned without an existing subnet ID — AWS returns an error if the subnet does not exist, since the gateway is deployed as an elastic network interface inside that subnet. Even if creation were possible, the NAT Gateway must be placed in a public subnet that already has an attached Internet Gateway and a default (0.0.0.0/0) route to it, which is not present at this stage. The NAT Gateway would therefore be orphaned with no outbound path, and the later route table update for private subnets would reference a NAT device that cannot function.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.