SOA-C02 Networking and Content Delivery Practice Question
A company has a VPC with public and private subnets in two Availability Zones. An Application Load Balancer (ALB) in the public subnets routes traffic to EC2 instances in the private subnets. The EC2 instances need to access the internet for software updates. Which solution is MOST secure and cost-effective?
⚠ Common exam trap
Watch out — candidates often confuse NAT Gateways with Internet Gateways, assuming an IGW can be attached to private subnets, or they overlook that assigning public IPs to private instances breaks the subnet's isolation and security model.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a NAT Gateway in a public subnet and add a route in the private subnet route tables pointing 0.0.0.0/0 to the NAT Gateway.
A NAT Gateway in a public subnet allows EC2 instances in private subnets to initiate outbound connections to the internet (e.g., for software updates) while preventing inbound connections from the internet. This is the most secure and cost-effective solution because it uses a managed AWS service that scales automatically and incurs charges only for usage and hourly uptime, avoiding the need for a bastion host or VPN.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy a NAT Gateway in a public subnet and add a route in the private subnet route tables pointing 0.0.0.0/0 to the NAT Gateway.
Why this is correct
A NAT Gateway is a managed service placed in a public subnet with an Elastic IP, and by adding a route for 0.0.0.0/0 in the private subnet route tables that targets the NAT Gateway, instances receive outbound internet access for tasks like software updates while remaining completely unreachable from the internet. This is the secure and correct design because the NAT Gateway performs stateful address translation, only allowing responses to initiated outbound connections, and it scales automatically without requiring you to manage a separate instance.
- ✗
Set up a VPN connection to an on-premises network and route internet traffic through it.
Why it's wrong here
Routing internet-bound traffic through a VPN to an on-premises network introduces unnecessary latency, bandwidth costs, and a single point of failure for what is a simple outbound-only requirement. This approach is designed for hybrid connectivity, not for providing EC2 instances with direct internet access for software updates. It would be correct if the company needed to enforce all internet traffic through a centralised on-premises security inspection point, but the stem specifies no such need.
- ✗
Assign public IP addresses to the EC2 instances and route traffic directly.
Why it's wrong here
Assigning public IP addresses to EC2 instances in private subnets directly exposes them to inbound traffic from the internet, even if you also add an internet gateway route. This defeats the purpose of using private subnets, dramatically increases the attack surface, and is unnecessary for outbound-only communication; instances do not need a public IP to initiate outbound connections if a NAT Gateway provides translation. Furthermore, public IPs cannot be dynamically added without stopping the instance, and managing firewall rules to protect them becomes significantly more complex, making this a poor security choice.
- ✗
Attach an internet gateway to the private subnets and route 0.0.0.0/0 to it.
Why it's wrong here
An internet gateway is a VPC-level resource attached to the VPC itself, not to any specific subnet, and routing private subnet traffic directly to it creates a bidirectional path to the internet, exposing instances to unsolicited inbound connections. This configuration is fundamentally misconfigured for private subnets: they are defined by having no route to an internet gateway, and routing 0.0.0.0/0 to the IGW would make instances effectively public, undermining the required security boundary and failing to provide the outbound-only access pattern that a NAT Gateway offers.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.