NAT Gateway Placement for Private Subnet Internet Access
A company has a VPC with public and private subnets. An EC2 instance in a private subnet needs to download software patches from the internet. Which component should be used to provide internet access to the instance?
⚠ Common exam trap
A common mix-up: candidates confuse an Internet Gateway with a NAT Gateway, assuming the IGW can be used directly by private instances, but the IGW requires a public IP on the instance and a route to 0.0.0.0/0 via the IGW, which is only possible from a public subnet.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NAT Gateway in a public subnet
A NAT Gateway in a public subnet allows EC2 instances in private subnets to initiate outbound traffic to the internet (e.g., to download patches) while preventing unsolicited inbound connections. The NAT Gateway uses an Elastic IP and routes traffic from the private subnet through the internet gateway attached to the VPC, translating the private IP to the public IP of the NAT Gateway.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
NAT Gateway in a public subnet
Why this is correct
A NAT Gateway is a fully managed service that enables instances in private subnets to initiate outbound IPv4 traffic to the internet while preventing inbound connections from the internet. It must be deployed in a public subnet with a route table entry in each private subnet pointing 0.0.0.0/0 to the NAT Gateway's network interface. This is the correct solution because it provides reliable, scalable outbound internet access without assigning public IPs to private instances, and it automatically handles connection tracking and dynamic scaling.
- ✗
AWS Site-to-Site VPN
Why it's wrong here
An AWS Site-to-Site VPN creates an encrypted IPSec tunnel between your VPC and your on-premises network via a Virtual Private Gateway or Transit Gateway. It is designed to securely connect your VPC to a corporate data center, not to provide general internet access for instances in private subnets. Even with a VPN, private instances would still not have a route to the internet unless a NAT device is also introduced, so this option does not satisfy the requirement of obtaining outbound internet connectivity.
- ✗
Internet Gateway attached to the VPC
Why it's wrong here
An Internet Gateway (IGW) is a horizontally scaled, redundant component that allows communication between a VPC and the internet, but it only works for resources that have public IP addresses and whose route tables explicitly direct traffic to it. Instances in private subnets lack public IPs and typically have a route table with 0.0.0.0/0 pointed to a NAT Gateway, not to the IGW. Simply attaching an IGW to the VPC does not make it accessible from private subnets; it must be combined with a NAT device or public IP assignment, so it alone is insufficient for private subnet outbound access.
- ✗
VPC Endpoint for Amazon S3
Why it's wrong here
A VPC Endpoint for Amazon S3 enables private, secure connectivity between your VPC and S3 without traversing the public internet. It can be implemented as a gateway endpoint or an interface endpoint, but it only provides access to S3 (or other supported services), not general internet connectivity. For a private instance to reach S3, you would add a route for the S3 prefix list, but the instance still cannot access arbitrary websites or services on the internet, making this option incorrect for the stated goal.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on SOA-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company has a VPC with a public subnet and a private subnet. An EC2 instance in the private subnet needs to download patches from the internet. The company has a NAT gateway in the public subnet. Which of the following route table configurations is required for the private subnet to enable internet access through the NAT gateway?
hard- A.Add a route to 0.0.0.0/0 pointing to the internet gateway in the private subnet route table
- ✓ B.Add a route to 0.0.0.0/0 pointing to the NAT gateway in the private subnet route table
- C.Add a route to 0.0.0.0/0 pointing to the NAT gateway in the public subnet route table
- D.Add a route to the NAT gateway's private IP in the private subnet route table
Why B: A private subnet route table must have a default route (0.0.0.0/0) pointing to the NAT gateway's elastic network interface (ENI) to forward outbound internet traffic from private instances through the NAT gateway. The NAT gateway, residing in the public subnet, then uses its own route table with a route to the internet gateway (IGW) to reach the internet. Without this route, traffic from the private subnet would have no path to the internet.
Variation 2. Which THREE configurations are required to enable an EC2 instance in a private subnet to access the internet for software updates while preventing inbound internet traffic?
hard- ✓ A.Attach an Internet Gateway to the VPC.
- B.Assign an Elastic IP address to the EC2 instance.
- ✓ C.Add a route to the private subnet's route table with destination 0.0.0.0/0 pointing to the NAT Gateway.
- D.Deploy a bastion host in the private subnet.
- ✓ E.Place a NAT Gateway in a public subnet.
Why A: An Internet Gateway (IGW) is required for any VPC to enable internet connectivity. Without an IGW, traffic cannot leave or enter the VPC from the internet. For a private subnet EC2 instance to reach the internet for software updates, the VPC must have an IGW attached, and the NAT Gateway (placed in a public subnet) uses the IGW to forward outbound traffic while blocking inbound connections.
Variation 3. A company has a VPC with a public subnet and a private subnet. The private subnet contains an EC2 instance that must access the internet for software updates. Which TWO actions are required to enable this? (Choose TWO.)
medium- A.Add an Internet Gateway to the private subnet's route table.
- ✓ B.Deploy a NAT Gateway in a public subnet.
- C.Assign a public IP address to the EC2 instance.
- D.Attach an Internet Gateway to the NAT Gateway.
- ✓ E.Add a route in the private subnet's route table pointing to the NAT Gateway for 0.0.0.0/0.
Why B: A NAT Gateway in a public subnet provides outbound internet access for private instances while preventing inbound connections. The private subnet's route table must include a default route (0.0.0.0/0) pointing to the NAT Gateway, enabling traffic to be forwarded to the internet via the Internet Gateway attached to the VPC.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.