Courseiva

Configuring Private Subnet Internet Access with NAT Gateway

A company is designing a VPC with public and private subnets. The private subnets need internet access for patching, but must not be directly reachable from the internet. Which TWO components should be used together?

Quick Answer

The answer is a NAT Gateway in a public subnet paired with a private route table that routes 0.0.0.0/0 traffic to that NAT Gateway. This design works because the NAT Gateway, residing in a public subnet with an Internet Gateway, translates private IPs to its own Elastic IP for outbound traffic, while the private subnet’s route table ensures return traffic flows back through the NAT Gateway, preventing any direct inbound connections. On the AWS Certified SysOps Administrator Associate SOA-C02 exam, this scenario tests your understanding of how to provide private subnet internet access using NAT Gateway design without exposing resources—a common trap is confusing a NAT Gateway with an Internet Gateway, which would make the subnet public. Remember the key distinction: an Internet Gateway enables bidirectional access, while a NAT Gateway only allows outbound-initiated traffic. For a quick memory tip, think “NAT in public, route in private” to keep the architecture straight.

⚠ Common exam trap

The trap is assuming that attaching an Internet Gateway to the VPC automatically gives private subnets internet access — candidates must remember that private subnets require a NAT Gateway (in a public subnet) plus a route to it, and that the IGW alone is insufficient.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Private subnet route table with a route to the NAT Gateway

Option E is correct because a NAT Gateway must be deployed in a public subnet (with an Elastic IP) so it can route traffic out through the Internet Gateway on behalf of private instances. Option D is correct because the private subnet's route table must have a route (typically 0.0.0.0/0) pointing to that NAT Gateway, which allows instances in the private subnet to initiate outbound traffic for patching while remaining unreachable from the internet. Together, the NAT Gateway in the public subnet and the private route table entry provide one-way outbound internet access. Option A is incorrect because VPC Peering connects two VPCs and does not provide internet access. Option B is incorrect because routing a private subnet directly to an Internet Gateway would make it a public subnet and expose it to inbound internet traffic. Option C is incorrect because an Internet Gateway alone, attached to the VPC, does not give private subnets outbound access without a NAT device and the corresponding route.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VPC Peering connection

    Why it's wrong here

    VPC peering connects two VPCs privately and provides no route to the internet, so private subnets gain no patching connectivity. Peering is chosen when linking VPCs for cross-VPC resource access, whereas outbound-only internet access requires a NAT gateway with an internet gateway.

  • ✗

    Private subnet route table with a route to the Internet Gateway

    Why it's wrong here

    A route to an Internet Gateway makes the private subnet public, since that gateway performs one-to-one NAT for instances with public IPs. Private subnets require a NAT Gateway or NAT instance in a public subnet for outbound-only access. Internet Gateway routes suit genuinely public subnets hosting internet-facing resources.

  • ✗

    Internet Gateway attached to the VPC

    Why it's wrong here

    An Internet Gateway alone provides no outbound path for private subnets, which lack public IP addresses and have no route to it. It is the correct attachment for public subnets, enabling inbound and outbound internet traffic for resources with public addresses, but it cannot translate private addresses.

  • ✓

    Private subnet route table with a route to the NAT Gateway

    Why this is correct

    The private subnet's route table must direct 0.0.0.0/0 traffic to the NAT Gateway, keeping instances unaddressable from the internet while enabling outbound patching. Without this route, private instances have no path to the NAT Gateway, so the no-inbound-reachability constraint fails.

  • ✓

    NAT Gateway in a public subnet

    Why this is correct

    The NAT Gateway resides in a public subnet with an Elastic IP, performing source NAT so private instances reach the internet for patching while remaining unaddressable inbound. It satisfies the constraint by providing outbound-only internet access, and pairs with the private route table.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SOA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company has a VPC with an Internet Gateway and a NAT Gateway. They launch an EC2 instance in a private subnet. The instance needs to download updates from the internet, but the security team wants to prevent any inbound traffic from the internet. Which route table configuration is correct for the private subnet?

medium
  • A.10.0.0.0/16 -> local; 0.0.0.0/0 -> VPC Peering
  • B.0.0.0.0/0 -> Internet Gateway
  • ✓ C.0.0.0.0/0 -> NAT Gateway
  • D.No default route; only local routes.

Why C: A private subnet requires a default route (0.0.0.0/0) to a NAT Gateway for outbound internet access while blocking inbound traffic. Option A is incorrect because a route to a VPC Peering connection does not provide internet access and is not relevant for internet updates. Option B is incorrect because a default route to an Internet Gateway would allow both inbound and outbound internet traffic, violating the security requirement. Option D is incorrect because without a default route, instances cannot reach the internet at all.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.