Courseiva

SOA-C02 Networking and Content Delivery Practice Question

A company runs a web application on Amazon EC2 instances in private subnets across multiple Availability Zones. The instances need to download software patches from the internet. The SysOps administrator requires a highly available, fully managed solution for outbound internet connectivity. Which solution should be implemented?

⚠ Common exam trap

Many exam-takers confuse NAT gateways with Internet Gateways, thinking that a single NAT gateway in one AZ provides high availability, but the correct design requires a NAT gateway in each AZ to avoid cross-AZ data transfer costs and single points of failure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy a NAT gateway in each Availability Zone and update the route tables for each private subnet to point to the NAT gateway in the same Availability Zone.

A NAT gateway in each Availability Zone provides highly available outbound internet connectivity for instances in private subnets. By placing a NAT gateway in each AZ and routing private subnet traffic to the NAT gateway in the same AZ, you eliminate a single point of failure and ensure that internet-bound traffic remains within the same AZ for low latency and fault tolerance. This is a fully managed AWS service that handles scaling and failover automatically.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Deploy a NAT gateway in each Availability Zone and update the route tables for each private subnet to point to the NAT gateway in the same Availability Zone.

    Why this is correct

    Deploying a NAT gateway in each Availability Zone and updating the private subnet route tables to point to the local NAT gateway is the correct pattern for highly available outbound internet access. Each NAT gateway is itself a managed, redundant resource within an AZ, and by pairing it with the private subnets in that same AZ, traffic from instances in one AZ keeps working even if another AZ fails. Crucially, NAT gateways are not a single point of failure, unlike a single NAT instance, and they automatically receive a public IP and can route traffic to the internet without requiring the private instances to have public IPs. This design satisfies both the availability requirement and the need for private instances to reach the internet for patch downloads.

  • ✗

    Attach an Internet Gateway to the VPC and add a default route (0.0.0.0/0) to the Internet Gateway in the private subnet route tables.

    Why it's wrong here

    Instances in private subnets do not have a public IP; adding a default route to an Internet Gateway will not work because the Internet Gateway requires instances to have public IPs or Elastic IPs for outbound traffic.

  • ✗

    Create a VPC endpoint for Amazon S3 and route traffic through it.

    Why it's wrong here

    A VPC endpoint for Amazon S3 (an interface or gateway endpoint) provides private connectivity only to the S3 service, using the AWS network and never traversing the public internet. It does not offer general internet access, so instances cannot use it to download operating system patches, package updates, or any other external content not hosted in S3. Even if patches were stored in S3, a VPC endpoint would not help with reaching arbitrary external repositories or service providers; it is scoped solely to S3 API calls. Therefore, routing traffic through an S3 VPC endpoint fails to satisfy the requirement for internet access and would not be a substitute for a NAT gateway.

  • ✗

    Set up an AWS Direct Connect connection and route all internet-bound traffic through it.

    Why it's wrong here

    AWS Direct Connect establishes a dedicated private network connection from your on-premises data center to AWS, but it does not natively provide internet access for your VPC resources. To use Direct Connect for internet-bound traffic, you would still need an internet gateway attached to the VPC, public IP addressing for instances, and a route design that sends traffic over the Direct Connect virtual interface to a separate internet connection — which is complex and not inherently available. Direct Connect is primarily for low-latency, private connectivity to AWS services, not for general egress to the public internet. Even if you configured internet access through your on-premises network, it would introduce a single dependency on that facility and would not be the highly available, AWS-managed solution that NAT gateways provide.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.