Courseiva

SOA-C02 Networking and Content Delivery Practice Question

A company has a web application deployed in a VPC with both public and private subnets. The web servers are in public subnets and the database servers are in private subnets. The web servers need to access the internet for updates. Which configuration is required to provide internet access to the web servers while keeping the database servers private?

⚠ Common exam trap

Watch out — candidates often confuse the role of an Internet Gateway with a NAT Gateway, assuming that adding an IGW route to all subnets is necessary for outbound access, but this would break the isolation of private subnets by allowing direct inbound traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach an Internet Gateway to the VPC and add a route to it only in the route tables for the public subnets.

An Internet Gateway (IGW) is required for any subnet that needs direct internet access. By attaching an IGW to the VPC and adding a default route (0.0.0.0/0) pointing to the IGW only in the public subnet route tables, web servers in those subnets can reach the internet. Database servers in private subnets remain isolated because their route tables lack the IGW route, preventing direct inbound or outbound internet traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Place both web and database servers in private subnets and use a NAT Gateway for outbound internet access.

    Why it's wrong here

    Web servers must be reachable by internet clients via inbound HTTP/HTTPS requests, which requires a public IP address and a route to an Internet Gateway in their subnet. Placing web servers in a private subnet with only a NAT Gateway for outbound access means they can initiate outbound connections but cannot accept incoming user traffic. The database servers can remain private, but the web tier needs to be in a public subnet.

  • ✗

    Attach an Internet Gateway to the VPC and add a route to it in the route tables for both public and private subnets.

    Why it's wrong here

    Adding a default route to an Internet Gateway in the route tables of private subnets makes those subnets publicly routable, effectively exposing any resource in them to the internet. This violates the design intent of a private subnet, which should have no direct internet path to protect internal resources. Only public subnets should have such a route; private subnets should handle outbound traffic via a NAT Gateway and inbound connections not at all.

  • ✓

    Attach an Internet Gateway to the VPC and add a route to it only in the route tables for the public subnets.

    Why this is correct

    This is the standard and correct VPC design for a web application: the Internet Gateway is attached to the VPC and a 0.0.0.0/0 route pointing to it is placed only in the route tables of public subnets hosting the web servers. This allows the web servers to receive inbound user traffic and respond over the internet, while the database servers in private subnets have no route to the IGW, keeping them inaccessible from the internet. The VPC's routing architecture ensures proper traffic flow and security.

  • ✗

    Use a VPC Gateway Endpoint to provide internet access to the web servers.

    Why it's wrong here

    VPC Gateway Endpoints are used to privately connect your VPC to supported AWS services such as S3 and DynamoDB, and they do not provide general internet connectivity. They are not an alternative to an Internet Gateway: gateway endpoints are not a route to the public internet, and they cannot enable inbound HTTP/HTTPS traffic to web servers. To serve web traffic, you must attach an Internet Gateway and associate it with the web servers' route table.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.