Courseiva

SOA-C02 Networking and Content Delivery Practice Question

A company has a VPC with public and private subnets across three Availability Zones. The public subnets host NAT Gateways, and the private subnets host EC2 instances that need to access the internet. The SysOps administrator notices that EC2 instances in one private subnet cannot reach the internet, while others can. What is the MOST likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The route table for the private subnet does not have a default route to the NAT Gateway.

The most likely cause is that the route table associated with the private subnet does not have a default route (0.0.0.0/0) pointing to the NAT Gateway. Without this route, traffic destined for the internet has no path and fails. Option A is incorrect because secondary private IP addresses do not affect internet access. Option B is incorrect because NAT Gateways must be in a public subnet (not private) to have internet access. Option C is incorrect because network ACLs are stateless and would affect all instances equally, not just those in one subnet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The EC2 instances have a secondary private IP address that is not registered.

    Why it's wrong here

    A secondary private IP address is simply an additional IP on the Elastic Network Interface (ENI) and does not influence outbound internet routing. Whether the IP is registered with the OS or not, the instance's source IP for internet traffic remains the primary private IP unless explicitly configured. The lack of registration would cause local connectivity issues to that IP, but the root cause of no internet access lies in the absence of a default route to the NAT gateway, not in IP registration.

  • ✗

    The NAT Gateway is not in a public subnet.

    Why it's wrong here

    A NAT Gateway must indeed reside in a public subnet with an Internet Gateway route, but that placement is a prerequisite for the service itself, not a per-subnet configuration. All private subnets in the VPC would share the same NAT Gateway, so if it were incorrectly placed in a private subnet, no private subnet would have outbound internet access, not just the affected one. The scenario's single-subnet scope points instead to that subnet's route table lacking the 0.0.0.0/0 target of the NAT Gateway.

  • ✗

    The network ACL for the private subnet blocks outbound traffic.

    Why it's wrong here

    Network ACLs are stateless and apply to the entire subnet, so a rule blocking outbound traffic would prevent all instances in that subnet from initiating any external connection. If the affected subnet were the only one with internet problems, a NACL would need to be unique to that subnet, but the typical VPC setup uses the same NACL or a permissive default NACL. Moreover, NACL issues would affect all communication in and out of the subnet, not specifically the path to the internet, making a missing route a far more precise explanation.

  • ✓

    The route table for the private subnet does not have a default route to the NAT Gateway.

    Why this is correct

    The private subnet's route table must contain a default route (0.0.0.0/0) that targets the NAT Gateway for all outbound internet traffic. Without this route, packets destined for the internet have no next hop and are dropped, even though the NAT Gateway itself is correctly placed and functional. This configuration is per-subnet, which explains why only the affected private subnet lacks internet access while other subnets work normally.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.