Courseiva

SOA-C02 Networking and Content Delivery Practice Question

A company has a VPC with public and private subnets in two Availability Zones. The private subnets need outbound internet access for EC2 instances to download updates. Which THREE components are required to achieve this? (Choose three.)

⚠ Common exam trap

Test-takers frequently confuse the Egress-Only Internet Gateway (IPv6 only) with the NAT Gateway (IPv4) or think a VPN connection can provide internet access, when in fact a NAT Gateway in a public subnet plus an Internet Gateway are required for IPv4 outbound connectivity from private subnets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Route table in the private subnets with a default route pointing to the NAT Gateway

A route table associated with private subnets must have a default route (0.0.0.0/0) pointing to a NAT Gateway to direct outbound internet traffic from EC2 instances through the NAT device. This allows instances in private subnets to initiate outbound connections to the internet (e.g., for software updates) while preventing unsolicited inbound connections from the internet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Route table in the private subnets with a default route pointing to the NAT Gateway

    Why this is correct

    The route table associated with the private subnets must contain a default route (0.0.0.0/0) pointing to the NAT Gateway's network interface. This ensures that any outbound IPv4 traffic from instances in those subnets is forwarded to the NAT Gateway for translation. Without this route, private instances would have no path to the internet, even though the NAT Gateway exists.

  • ✓

    Internet Gateway attached to the VPC

    Why this is correct

    An Internet Gateway (IGW) is a horizontally scaled, redundant component that provides a target for the VPC's public subnets' default routes and enables communication with the internet. For the NAT Gateway to function, it must have a route through an IGW because the NAT Gateway itself resides in a public subnet and uses the IGW as its next hop for outbound traffic. Without an IGW attached to the VPC, the NAT Gateway cannot reach the internet, so the entire design fails.

  • ✗

    Egress-only Internet Gateway

    Why it's wrong here

    An Egress-only Internet Gateway is designed exclusively for IPv6 traffic, allowing outbound-only connectivity from the VPC to the internet. Since the NAT Gateway operates on IPv4 and the scenario does not involve IPv6, this component has no role. It cannot replace the NAT Gateway or the IGW for IPv4 outbound access, and it would not provide the required path for private instances to reach the internet.

  • ✓

    NAT Gateway in a public subnet

    Why this is correct

    The NAT Gateway is a fully managed service that must be deployed in a public subnet, with an Elastic IP address and a route via the Internet Gateway. It translates the source IP of outbound traffic from private instances to its own public IP, thereby enabling those instances to initiate internet connections while remaining inaccessible from the internet. This placement in a public subnet is mandatory, as the NAT Gateway needs direct internet connectivity through the IGW.

  • ✗

    AWS Site-to-Site VPN connection

    Why it's wrong here

    A Site-to-Site VPN connection establishes an encrypted IPSec tunnel between the VPC and an on-premises network, typically used for hybrid cloud workloads. It provides secure access to remote private networks, not general internet egress. Even if configured, it would route traffic from private instances to on-premises resources, not to the internet, so it does not satisfy the requirement for outbound internet access.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.