Courseiva

SOA-C02 Networking and Content Delivery Practice Question

A SysOps administrator needs to create a VPC with both public and private subnets. The public subnet will host a NAT gateway and a bastion host. The private subnet will host application servers that need outbound internet access for updates. Which routing configuration should the administrator implement?

⚠ Common exam trap

SOA-C02 often tests whether candidates correctly place the NAT gateway in the public subnet and point the private subnet's default route at the NAT gateway — distractors swap the IGW and NAT gateway targets to catch memorized-but-unverified answers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Public subnet route table: 0.0.0.0/0 -> Internet Gateway; Private subnet route table: 0.0.0.0/0 -> NAT Gateway.

The public subnet needs a route to the Internet Gateway so the NAT gateway and bastion host are reachable from the internet. The private subnet needs a route to the NAT gateway (which itself lives in the public subnet) so application servers can initiate outbound internet traffic without being directly reachable inbound.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Public subnet route table: 0.0.0.0/0 -> Internet Gateway; Private subnet route table: 0.0.0.0/0 -> Internet Gateway via the NAT Gateway.

    Why it's wrong here

    A route table entry can only specify a single target, and the target must be a gateway, NAT gateway, or other valid endpoint; it cannot be a chain like 'Internet Gateway via the NAT Gateway.' The internet gateway is a distinct resource, and AWS does not support transitive routing through a NAT gateway to an internet gateway in one route. To provide outbound access, the private subnet's default route must point directly to the NAT gateway, which then uses the public subnet's route to the internet gateway.

  • ✗

    Public subnet route table: 0.0.0.0/0 -> Internet Gateway; Private subnet route table: 0.0.0.0/0 -> Internet Gateway.

    Why it's wrong here

    Directing the private subnet's default route to the internet gateway would give every instance in that subnet a public IP address and direct internet access, completely bypassing the NAT gateway and eliminating the privacy that a private subnet is designed to provide. This configuration would allow inbound traffic from the internet to reach those instances, which is not acceptable for a private subnet. Instances in a private subnet should only reach the internet through a NAT gateway, which enables outbound communication while blocking unsolicited inbound connections.

  • ✗

    Public subnet route table: 0.0.0.0/0 -> NAT Gateway; Private subnet route table: 0.0.0.0/0 -> Internet Gateway.

    Why it's wrong here

    The public subnet must route to the internet gateway so resources like the NAT gateway can communicate with the internet, not to the NAT gateway itself—doing so would create a routing loop because the NAT gateway resides in the public subnet and would have nowhere to send traffic. Meanwhile, the private subnet must point to the NAT gateway as its default target, not the internet gateway, because sending private traffic directly to the internet gateway would expose it publicly and negate the need for NAT. Reversing these routes breaks the intended network architecture and leaves private instances directly internet-accessible.

  • ✓

    Public subnet route table: 0.0.0.0/0 -> Internet Gateway; Private subnet route table: 0.0.0.0/0 -> NAT Gateway.

    Why this is correct

    This is the correct setup for a VPC with public and private subnets. The public subnet route table sends all outbound traffic (0.0.0.0/0) to the internet gateway, allowing resources like a bastion host or NAT gateway to reach the internet directly. The private subnet route table sends all outbound traffic to the NAT gateway, which resides in the public subnet and performs source network address translation (SNAT) to forward traffic to the internet while keeping instances in the private subnet unreachable from the internet. This preserves the security of private instances while still enabling them to download updates or access external services.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.