Courseiva

SOA-C02 Networking and Content Delivery Practice Question

A company has a VPC with a public subnet and a private subnet. An Amazon EC2 instance in the private subnet needs to download security patches from the internet, but the instance must not be directly accessible from the internet. The SysOps administrator configured a NAT gateway in the public subnet and added a route in the private subnet's route table pointing 0.0.0.0/0 to the NAT gateway. The instance's security group allows all outbound traffic. However, the instance still cannot reach the internet. What is the most likely missing configuration?

⚠ Common exam trap

It's easy for candidates to assume configuring the private subnet's route table to point to the NAT gateway is sufficient, forgetting that the NAT gateway itself needs a route to the internet via an internet gateway in its own subnet.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a route in the public subnet's route table that directs 0.0.0.0/0 traffic to an internet gateway

The NAT gateway is in the public subnet, but for it to route traffic to the internet, the public subnet must have a route table entry that directs 0.0.0.0/0 traffic to an internet gateway (IGW). Without this route, the NAT gateway cannot forward outbound traffic to the IGW, so the private instance's traffic is dropped. Option C correctly identifies this missing route.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Attach an Elastic IP to the NAT gateway

    Why it's wrong here

    An Elastic IP is a mandatory parameter at NAT gateway creation time; if the NAT gateway exists, it already has one attached to its public-facing interface, so attaching another is impossible and unnecessary. The EIP facilitates address translation for internet-bound traffic, but it does not affect routing from the public subnet to the internet gateway. The observed failure is a missing route from the public subnet to the IGW, not a missing EIP.

  • ✗

    Enable DNS resolution in the VPC

    Why it's wrong here

    Enabling DNS resolution (the enableDnsSupport attribute) only tells instances to use the VPC's Route 53 Resolver for DNS queries; it has no bearing on IP routing or connectivity to the NAT gateway. Even if DNS resolution were disabled, instances could still reach the internet by IP address, and the NAT gateway would still attempt to forward traffic. The actual issue is that the public subnet lacks a default route to the internet gateway, which prevents the NAT gateway from completing outbound communication, regardless of DNS settings.

  • ✓

    Add a route in the public subnet's route table that directs 0.0.0.0/0 traffic to an internet gateway

    Why this is correct

    A NAT gateway must be launched in a public subnet, and that subnet's route table needs a destination of 0.0.0.0/0 pointing to an internet gateway, not to another gateway or target. Without this route, the NAT gateway's network interface cannot send translated packets to the IGW or receive return packets, so all traffic from private instances times out. Adding this route is the correct fix because it establishes the final hop between the NAT gateway and the internet.

  • ✗

    Modify the network ACL of the private subnet to allow inbound ephemeral ports from the NAT gateway's private IP

    Why it's wrong here

    Network ACLs are stateless and default to allowing all inbound and outbound traffic; unless someone added explicit deny rules for ephemeral ports, they are not the source of the problem. Even if the private subnet NACL were too restrictive, it would only affect traffic between the private instances and the NAT gateway's private IP, not the NAT gateway's ability to reach the IGW from the public subnet. The failure occurs in the public subnet's route table, so modifying the private subnet NACL is both unnecessary and ineffective.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.