SOA-C02 Networking and Content Delivery Practice Question
A company has a VPC with a public subnet and a private subnet. The private subnet hosts a database. Which TWO components are required to allow an EC2 instance in the public subnet to connect to the database?
⚠ Common exam trap
Watch out — candidates often confuse the purpose of a NAT Gateway (outbound internet) with the need for subnet-to-subnet traffic, or they assume an Internet Gateway is required for any cross-subnet communication within a VPC.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A network ACL rule on the private subnet allowing inbound traffic from the public subnet CIDR.
A security group rule on the database allowing inbound traffic from the EC2 instance's security group (Option E) is required because security groups act as a virtual firewall at the instance level, and by default they deny all inbound traffic. A network ACL rule on the private subnet allowing inbound traffic from the public subnet CIDR (Option B) is also required because network ACLs are stateless and control traffic at the subnet boundary; without an inbound allow rule, traffic from the public subnet would be dropped by the private subnet's ACL.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A NAT Gateway in the public subnet.
Why it's wrong here
A NAT Gateway in the public subnet enables outbound internet traffic from private instances, not inbound connectivity from a public subnet. The database in the private subnet requires a route for return traffic to the EC2 instance, which a NAT Gateway does not provide—it only translates source addresses for outbound flows. This option is tempting because NAT Gateways are commonly used to grant private resources internet access, but the scenario demands bidirectional communication between subnets, which is achieved via a VPC peering connection or a transit gateway, not network address translation.
- ✓
A network ACL rule on the private subnet allowing inbound traffic from the public subnet CIDR.
Why this is correct
Network ACLs are stateless and operate at the subnet boundary. To allow an EC2 instance in the public subnet to reach a database in the private subnet, the private subnet's NACL must have an inbound rule permitting traffic from the public subnet's CIDR on the database's port. Because NACLs are stateless, you also need a corresponding outbound rule on the private subnet NACL to allow the return traffic back to the EC2 instance, and reciprocal inbound/outbound rules on the public subnet NACL if it has restrictive rules.
- ✗
An Internet Gateway attached to the VPC.
Why it's wrong here
An Internet Gateway (IGW) is a VPC component that enables bidirectional communication between the VPC and the public internet. However, traffic between the public subnet and the private subnet stays entirely within the VPC and is routed by the VPC's local route table — no IGW is involved. Attaching an IGW to the VPC has no effect on internal traffic paths and does not, by itself, permit or filter traffic between subnets.
- ✗
A VPC Endpoint for the database service.
Why it's wrong here
VPC Endpoints provide private connectivity to supported AWS services (like S3 or DynamoDB) without traversing the internet. A VPC endpoint for a database service (e.g., RDS API) does not route data-plane traffic to a database instance; it only connects to the service's public API endpoints. EC2 instances connecting to a database in the same VPC use the local network path and need security group and NACL rules, not a VPC endpoint.
- ✓
A security group rule on the database allowing inbound traffic from the EC2 instance's security group.
Why this is correct
Security groups act as stateful virtual firewalls at the instance or ENI level. Adding an inbound rule on the database's security group that references the EC2 instance's security group as the source permits traffic from any instance associated with that source security group, regardless of its IP address. This is a precise and scalable way to allow database access because it automatically applies to all instances in the source SG and statefully allows return traffic without separate outbound rules.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.