Courseiva

SOA-C02 Reliability and Business Continuity Practice Question

A company has an Auto Scaling group that launches EC2 instances in private subnets. The instances need to download software patches from the internet. Which component must be added to the VPC to allow outbound internet traffic while keeping the instances private?

⚠ Common exam trap

Candidates often confuse an internet gateway with a NAT gateway, assuming attaching an internet gateway to the VPC alone will give private instances internet access, but private subnets need a NAT device to route traffic through the internet gateway.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A NAT gateway in a public subnet

A NAT gateway in a public subnet allows EC2 instances in private subnets to initiate outbound traffic to the internet (e.g., to download patches) while preventing unsolicited inbound connections. The NAT gateway translates the private IPs to its own Elastic IP and routes traffic through an internet gateway attached to the VPC, keeping instances private.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    An internet gateway attached to the VPC

    Why it's wrong here

    An internet gateway is a horizontally scaled VPC component that serves as a target for internet-bound traffic, but it cannot by itself enable outbound connectivity for instances in private subnets. For an IGW to work, the instance must have a public IPv4 address or be behind a NAT device. Since the instances described are in a private subnet without public IPs, an IGW alone provides no path to the internet.

  • ✗

    A VPC peering connection to a VPC with internet access

    Why it's wrong here

    A VPC peering connection enables private IP communication between two VPCs but does not create any transitive routing. The local VPC cannot route through a peer to that peer's internet gateway because the IGW of the peer VPC is not a route table target in the local VPC. Consequently, even if the peer VPC has full internet access, private instances in the first VPC cannot use that IGW for outbound connectivity.

  • ✗

    An egress-only internet gateway

    Why it's wrong here

    An egress-only internet gateway is designed exclusively for IPv6 traffic, allowing outbound communication from a VPC to the internet while denying all inbound traffic. It is the IPv6 counterpart to a NAT gateway, but it does not translate or support IPv4 traffic. Since the scenario involves EC2 instances using IPv4, an egress-only IGW cannot provide the required outbound internet access.

  • ✓

    A NAT gateway in a public subnet

    Why this is correct

    A NAT gateway operates in a public subnet with an Elastic IP and performs source network address translation for outbound IPv4 traffic. Private subnet instances route their default 0.0.0.0/0 traffic to the NAT gateway, which then forwards it to the internet while masking the private instance IPs. This is the standard AWS-managed method to give private instances outbound internet access without exposing them to inbound connections.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.