Courseiva

SOA-C02 Networking and Content Delivery Practice Question

A SysOps administrator needs to design a VPC with public and private subnets for a web application. Which TWO components are required to allow instances in the private subnet to access the internet?

⚠ Common exam trap

Candidates often think an Internet Gateway alone is sufficient for private subnet internet access, but they overlook the need for a NAT device to translate private IPs, as the IGW only works with public IPs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NAT gateway in a public subnet

A NAT gateway in a public subnet is required because it allows instances in a private subnet to initiate outbound traffic to the internet (e.g., for software updates) while preventing unsolicited inbound connections. The NAT gateway must be placed in a public subnet with an Internet Gateway (IGW) route to translate private IPs to the gateway's Elastic IP. Without the NAT gateway, private instances have no path to the internet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    NAT gateway in a public subnet

    Why this is correct

    A NAT gateway is a managed Network Address Translation service that enables instances in a private subnet to initiate outbound IPv4 traffic to the internet and receive replies, while preventing unsolicited inbound connections from the internet. It must be placed in a public subnet with a route to an Internet Gateway and an associated Elastic IP, so it can translate private-source IPs to the public IP. This is the core component that gives private instances internet access in a VPC design with public and private subnets.

  • ✓

    Route table entry in the private subnet routing 0.0.0.0/0 to the NAT gateway

    Why this is correct

    This route entry in the private subnet's route table directs all internet-bound traffic (0.0.0.0/0) to the NAT gateway's network interface, allowing the gateway to perform the address translation. Without this specific route, even if the NAT gateway is deployed in a public subnet, private instances have no path to the internet. It is a necessary part of the solution, complementing the NAT gateway itself.

  • ✗

    VPC endpoint for S3

    Why it's wrong here

    A VPC endpoint (gateway or interface) provides a private, secure connection to supported AWS services, such as S3 or DynamoDB, without traversing the public internet. However, it only allows access to that specific AWS service, not general outbound internet access to arbitrary external hosts. Since the requirement is to give private instances full internet access, an S3 endpoint would be insufficient and is not the correct design component.

  • ✗

    Internet gateway attached to the VPC

    Why it's wrong here

    An Internet Gateway is a horizontally scaled component that enables connectivity between the VPC and the public internet, but it only works for resources with public IP addresses located in subnets whose route table points to the gateway. Private subnets typically route to the NAT gateway instead of the IGW, so instances there do not have a direct route to the internet. While the IGW is a prerequisite to make a NAT gateway functional, attaching it alone does not provide internet access to private instances.

  • ✗

    Virtual private gateway

    Why it's wrong here

    A Virtual Private Gateway is the Amazon-side endpoint for an IPsec VPN connection or AWS Direct Connect, used to connect an on-premises network to the VPC. It does not provide any general internet access; its purpose is private connectivity to a remote corporate network. Since the design here is about outbound internet access from private subnets, a VGW is irrelevant and would potentially misroute traffic if associated with a route table.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.