SOA-C02 Networking and Content Delivery Practice Question
A company has a VPC with public and private subnets across two Availability Zones. An application running on EC2 instances in the private subnets needs to access the internet for updates. Which configuration should be used to provide internet access while minimizing administrative overhead?
⚠ Common exam trap
Watch out — candidates often confuse a NAT Gateway with a NAT instance, assuming both require similar administrative effort, or they mistakenly think assigning public IPs to private instances is sufficient for outbound-only internet access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a NAT Gateway in a public subnet and update private route tables to point to it.
A NAT Gateway, deployed in a public subnet with an Elastic IP, allows instances in private subnets to initiate outbound traffic to the internet (e.g., for updates) while preventing inbound traffic from the internet. This is a fully managed AWS service, so it requires no patching or scaling management, minimizing administrative overhead. The private subnet's route table must have a default route (0.0.0.0/0) pointing to the NAT Gateway's network interface.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assign public IP addresses to the private instances and update route tables accordingly.
Why it's wrong here
Assigning public IP addresses to instances in a private subnet directly exposes them to inbound internet traffic, defeating the security isolation that private subnets are designed to provide. Even with route table updates that use an internet gateway, the instances become effectively public, allowing unsolicited inbound connections and increasing attack surface. The correct approach keeps private instances private and uses a NAT device for outbound-only access.
- ✗
Set up AWS Direct Connect to an internet gateway.
Why it's wrong here
AWS Direct Connect provides a private dedicated network connection from on-premises to your VPC, not a path to the public internet via an internet gateway. An internet gateway is a VPC-side component that must route traffic directly through it, and Direct Connect cannot be attached or 'set up' to an internet gateway. At best, you could use a public virtual interface to reach AWS public services, but that does not give your private instances outbound internet access from within your VPC. This option misinterprets both Direct Connect and the role of an internet gateway.
- ✓
Deploy a NAT Gateway in a public subnet and update private route tables to point to it.
Why this is correct
A NAT gateway is a highly available, fully managed AWS service that allows instances in a private subnet to initiate outbound traffic to the internet while blocking unsolicited inbound connections. It must be placed in a public subnet with a route to an internet gateway, and the private subnet's route table should direct 0.0.0.0/0 traffic to the NAT gateway's network interface. This design is the standard for providing internet access to private resources securely, with no need to patch or manage the gateway yourself.
- ✗
Launch a NAT instance in the private subnet and configure routing.
Why it's wrong here
Launching a NAT instance in a private subnet is fundamentally flawed because a NAT instance requires a route to the internet itself, which is only possible if it resides in a public subnet with an internet gateway route. Without that, the NAT instance has no upstream internet path to forward traffic from other private instances, so the setup simply will not function. Even if placed correctly, a NAT instance is a single point of failure and becomes a management burden compared to the fully managed NAT gateway service.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.