SOA-C02 Networking and Content Delivery Practice Question
A SysOps administrator needs to allow an EC2 instance in a private subnet to download patches from the internet. Which AWS service should be used to achieve this securely?
⚠ Common exam trap
The trap is confusing inbound vs. outbound connectivity — candidates pick IGW because they think 'internet access' means IGW, but IGWs are for public subnets and inbound reachability, while NAT is for private-subnet egress.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
NAT Gateway
A NAT Gateway is a managed AWS service deployed in a public subnet that allows instances in private subnets to initiate outbound connections to the internet (such as downloading patches) while preventing inbound connections from the internet. It provides the secure, one-way egress path the scenario requires.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Internet Gateway (IGW)
Why it's wrong here
An Internet Gateway (IGW) is a horizontally scaled, redundant VPC component that provides bidirectional communication between a VPC and the internet. It is typically attached to a VPC and used in route tables for public subnets, where instances have public IP addresses and can be reached directly from the internet. In a private subnet, an IGW route is not used, and an IGW itself does not perform network address translation—it simply exposes instances with public IPs to inbound traffic. Using an IGW here would defeat the purpose of keeping the EC2 instance private by allowing unsolicited inbound connections.
- ✓
NAT Gateway
Why this is correct
A NAT Gateway is a fully managed AWS service that enables instances in a private subnet to initiate outbound connections to the internet (for example, to download patches or access external APIs) while preventing unsolicited inbound connections from the internet. It is deployed in a public subnet with an Elastic IP address, and the private subnet's route table points a default route (0.0.0.0/0) to the NAT Gateway. The NAT Gateway translates the private source IP of outbound traffic to its Elastic IP and uses connection tracking to drop inbound packets that are not part of an established outbound flow. This makes it the correct choice for providing outbound-only internet access to a private EC2 instance.
- ✗
AWS VPN
Why it's wrong here
An AWS Site-to-Site VPN creates an encrypted IPsec tunnel between a VPC and an on-premises network, typically using a virtual private gateway or transit gateway. It is designed for hybrid cloud connectivity—extending a corporate network into the AWS cloud—not for providing general internet egress to instances. A VPN route would send traffic to the on-premises network (for example, 10.0.0.0/8) rather than to the public internet, and it does not perform NAT or allow outbound internet access for private instances. Therefore, using a VPN does not satisfy the requirement to give the EC2 instance internet access.
- ✗
VPC Peering
Why it's wrong here
VPC Peering is a networking connection between two VPCs that allows them to communicate using private IPv4 or IPv6 addresses as if they were part of the same network. Peering is non-transitive, meaning traffic cannot hop through a peered VPC to reach another network or the internet. It does not include any internet gateway, NAT, or routing to public destinations. While VPC peering can connect the EC2 instance to resources in another VPC, it cannot provide internet egress, so it is not a solution for allowing outbound internet access.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.