Outbound Internet for Private Subnets — NAT Gateway Configuration
A security engineer is designing a VPC with public and private subnets. The private subnets will host databases that should not have direct internet access. Which three components are required to provide outbound internet access for these databases? (Choose THREE.)
Quick Answer
The answer is a NAT gateway in a public subnet, an internet gateway, and a route table in the private subnet with a default route pointing to the NAT gateway. This combination works because the NAT gateway, residing in a public subnet with an internet gateway attached, translates private IP addresses to its own public IP for outbound traffic, while the private subnet’s route table ensures all non-local traffic is forwarded to the NAT device. On the AWS Certified Security Specialty SCS-C02 exam, this scenario tests your understanding of how to enable outbound internet for private subnets without granting direct inbound access—a common requirement for secure database tiers. A frequent trap is confusing a VPC gateway endpoint (for S3 or DynamoDB) with general internet access, or assuming a NAT gateway alone suffices without the internet gateway. Remember the three-part chain: internet gateway → NAT gateway → private route table default route.
⚠ Common exam trap
Many candidates think a NAT gateway alone provides internet access, forgetting that the NAT gateway must be placed in a public subnet with a route to an internet gateway, and that the private subnet’s default route must point to the NAT gateway, not the IGW.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An internet gateway attached to the VPC.
Option B is correct because an internet gateway (IGW) attached to the VPC is the fundamental component that enables any communication between the VPC and the internet; the NAT gateway itself requires an IGW to forward traffic outbound. Option E is correct because a NAT gateway must be deployed in a public subnet (one whose route table points to the IGW) so it can translate private subnet traffic to the internet while preventing inbound connections to the databases. Option C is correct because the private subnet route tables must contain a default route (0.0.0.0/0) targeting the NAT gateway, which is how the databases' outbound packets are directed to the NAT for translation. Option A is not required because AWS WAF is a layer 7 web application firewall that protects web applications and does not enable or provide outbound internet access. Option D is not required because a VPC gateway endpoint for S3 only provides private connectivity to Amazon S3 and does not provide general outbound internet access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS WAF attached to the NAT gateway.
Why it's wrong here
AWS WAF filters HTTP traffic at the application layer and attaches to load balancers or CloudFront, not to a NAT gateway, so it provides no outbound routing. It is tempting as a security control, and would be correct when protecting public web applications from exploits.
- ✓
An internet gateway attached to the VPC.
Why this is correct
The internet gateway provides the VPC's path to the internet and is required for the NAT gateway to reach external destinations. Without it attached to the VPC, the NAT gateway cannot forward private-subnet traffic outbound, so the stem's outbound access fails.
- ✓
Route tables in the private subnets with a default route (0.0.0.0/0) pointing to the NAT gateway.
Why this is correct
The private subnet route table must carry a 0.0.0.0/0 route targeting the NAT gateway, otherwise instances have no path off-subnet. This satisfies the stem's outbound-only requirement, since the NAT gateway translates traffic without allowing inbound internet connections.
- ✗
A VPC gateway endpoint for S3.
Why it's wrong here
A gateway endpoint routes traffic privately to S3 without traversing the internet, so it cannot supply general outbound access for databases. It is tempting because it removes NAT dependency, and would be correct when the only requirement is private S3 connectivity.
- ✓
A NAT gateway in a public subnet.
Why this is correct
The NAT gateway performs source NAT for private-subnet traffic and must reside in a public subnet with an elastic IP. This satisfies the stem's constraint by giving databases outbound internet access while preventing inbound connections from the internet.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SCS-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security engineer is designing a VPC with public and private subnets. The private subnets must be able to download software updates from the internet. Which TWO components can provide this functionality without exposing the private instances to inbound internet traffic?
medium- ✓ A.NAT gateway
- B.Internet gateway
- C.VPC endpoint
- D.Egress-only internet gateway
- ✓ E.NAT instance
Why A: A NAT gateway is a managed AWS service that enables instances in a private subnet to initiate outbound traffic to the internet (e.g., for downloading software updates) while preventing the internet from initiating inbound connections to those instances. It translates the private IP addresses of the instances to the NAT gateway's Elastic IP address, allowing return traffic to be routed back correctly. This meets the requirement of outbound-only internet access without exposing private instances to inbound traffic.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.