Courseiva

SOA-C02 Networking and Content Delivery Practice Question

A SysOps administrator is troubleshooting an issue where an EC2 instance in a private subnet cannot connect to the internet via a NAT Gateway. Which TWO components must be correctly configured for this to work? (Select TWO.)

⚠ Common exam trap

Many exam-takers confuse the placement requirement for a NAT Gateway with that of a NAT Instance, thinking a NAT Gateway can be in a private subnet, or they incorrectly assume the private subnet's NACL needs an inbound rule from the NAT Gateway instead of focusing on outbound rules and route tables.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The NAT Gateway must be placed in a public subnet with a route to an Internet Gateway.

The NAT Gateway must reside in a public subnet because it needs a direct route to an Internet Gateway (IGW) to translate private IP addresses to the NAT Gateway's Elastic IP for outbound internet traffic. Without this placement and route, the NAT Gateway cannot forward traffic to the internet, breaking connectivity for instances in private subnets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The network ACL for the private subnet must have a rule allowing inbound traffic from the NAT Gateway.

    Why it's wrong here

    Network ACLs (NACLs) are stateless and must allow traffic in both directions based on the session. For an instance in a private subnet to reach the internet via a NAT Gateway, the private subnet's NACL needs an outbound rule permitting traffic to the NAT Gateway's private IP (or 0.0.0.0/0) and an inbound rule for the ephemeral ports used by return traffic. Simply adding an inbound rule allowing traffic from the NAT Gateway does not help the outbound request and would not resolve a connectivity failure caused by missing outbound rules or routing.

  • ✓

    The NAT Gateway must be placed in a public subnet with a route to an Internet Gateway.

    Why this is correct

    The NAT Gateway must indeed be placed in a public subnet, meaning that the subnet's route table contains a 0.0.0.0/0 route pointing to an Internet Gateway. This placement is essential because the NAT Gateway needs its own internet reachability to forward traffic from private instances to the internet. Without this route, the NAT Gateway cannot communicate with the internet, and all outbound traffic it receives from private subnets will silently fail, making the NAT Gateway itself unreachable.

  • ✓

    The route table for the private subnet must have a default route (0.0.0.0/0) pointing to the NAT Gateway.

    Why this is correct

    Correctly, the route table associated with the private subnet must contain a default route (0.0.0.0/0) with the NAT Gateway as its target. This entry is what sends all internet-bound traffic from instances in the private subnet to the NAT Gateway for address translation. If this route is missing or points to an Internet Gateway instead, the traffic either has no next hop or bypasses the NAT, which breaks the intended outbound-only internet access.

  • ✗

    The EC2 instance must have a public IP address.

    Why it's wrong here

    This is not a requirement. Instances in a private subnet do not need a public IP address to access the internet because the NAT Gateway has a public Elastic IP and performs source NAT, replacing the instance's private IP with the gateway's public IP. Assigning a public IP to the instance would be inappropriate in this architecture; it could cause asymmetric routing or bypass the NAT entirely if the route table also points to the Internet Gateway. Therefore, the absence of a public IP is expected and is not part of the problem.

  • ✗

    The security group for the EC2 instance must allow inbound traffic on port 80.

    Why it's wrong here

    The security group issue here is about outbound traffic, not inbound. The instance is initiating connections to the internet, so the security group must have an outbound rule that allows traffic to the destination (e.g., 0.0.0.0/0 on port 80). Inbound rules apply to traffic arriving at the instance, and because security groups are stateful, the return traffic for the initiated outbound requests is automatically permitted regardless of inbound rules. Thus, lacking an inbound rule for port 80 does not block outbound internet access.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.