SOA-C02 Networking and Content Delivery Practice Question
A company has a VPC with public and private subnets. The private subnets host application servers that need to make outbound HTTPS connections to the internet. The SysOps administrator must implement a solution that provides outbound internet connectivity while preventing inbound connections from the internet. Additionally, the solution must allow the company to control which domains the application servers can access. Which solution should the administrator implement?
⚠ Common exam trap
Watch out — candidates often assume a NAT Gateway with security group rules can control domain access, but security groups cannot filter by domain name—only by IP address—so the proxy-based NAT instance is required for domain-level restriction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a NAT instance with proxy software and use route tables to direct traffic from private subnets to the NAT instance.
A NAT instance with proxy software (e.g., Squid) allows outbound HTTPS connections from private subnets while blocking inbound connections, and the proxy software can enforce domain-level access control via allow/deny lists. This meets the requirement to restrict which domains the application servers can access, which a standard NAT Gateway cannot do because it only translates IP addresses and cannot filter by domain name.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a NAT Gateway and use security group outbound rules to restrict destinations.
Why it's wrong here
Security groups are stateful firewalls that evaluate rules based on IP addresses, ports, and protocols—they cannot match DNS names or URLs, so they are fundamentally incapable of restricting outbound traffic by domain. Moreover, a NAT Gateway is a fully managed AWS service that does not support attaching security groups directly to it; you could attach a security group to the private instances, but that group's outbound rules still only allow or deny CIDR ranges, not domain names. Thus, while a NAT Gateway provides basic IPv4 outbound connectivity, it offers no mechanism to enforce domain-based allow lists, making this combination insufficient for the stated requirement.
- ✓
Configure a NAT instance with proxy software and use route tables to direct traffic from private subnets to the NAT instance.
Why this is correct
A NAT instance is an Amazon EC2 instance that performs source network address translation for instances in private subnets, and it can be configured with proxy software such as Squid to enable domain-level access control. By running a proxy, the NAT instance can terminate HTTP/HTTPS requests, inspect the requested DNS names, and apply allow/deny policies based on those names—something security groups and NAT Gateways cannot do. You direct traffic from private subnets to the NAT instance by adding a route in the private route tables that points 0.0.0.0/0 to the instance ID; the proxy software then provides the required domain filtering while still blocking unsolicited inbound connections.
- ✗
Configure an egress-only Internet Gateway and route private subnet traffic to it.
Why it's wrong here
An egress-only Internet Gateway (EIGW) is a VPC component designed exclusively for IPv6 traffic that originates from resources in a VPC and is destined for the internet; it does not support IPv4 at all. Even if your workload were IPv6-only, the EIGW simply forwards outbound packets and provides no capability to inspect, filter, or restrict destinations by domain name or URL—it is effectively a transparent path for all outbound IPv6 traffic. Therefore, this option not only fails to address IPv4 connectivity but also lacks the domain-based control explicitly required, so it is incorrect.
- ✗
Configure a VPC endpoint for HTTPS and route private subnet traffic to it.
Why it's wrong here
A VPC endpoint provides private, high-bandwidth connectivity only to supported AWS services or to your own services via AWS PrivateLink; it cannot be used to reach general internet destinations. For example, an HTTPS interface endpoint connects only to specific AWS services (like API Gateway or a service you expose behind a Network Load Balancer), not to arbitrary public websites, so it does not provide outbound internet access to the VPC as a whole. Consequently, routing private subnet traffic to a VPC endpoint would not enable instances to browse generic internet domains, and it offers no domain-level filtering, making this option invalid.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.