SOA-C02 Networking and Content Delivery Practice Question
Which THREE configurations are required to enable an EC2 instance in a private subnet to access the internet for software updates while preventing inbound internet traffic?
⚠ Common exam trap
Many exam-takers think a NAT Gateway alone is sufficient, forgetting that an Internet Gateway must be attached to the VPC for the NAT Gateway to route traffic to the internet, or they mistakenly believe an Elastic IP on the instance itself is needed for outbound access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach an Internet Gateway to the VPC.
An Internet Gateway (IGW) is required for any VPC to enable internet connectivity. Without an IGW, traffic cannot leave or enter the VPC from the internet. For a private subnet EC2 instance to reach the internet for software updates, the VPC must have an IGW attached, and the NAT Gateway (placed in a public subnet) uses the IGW to forward outbound traffic while blocking inbound connections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Attach an Internet Gateway to the VPC.
Why this is correct
The Internet Gateway (IGW) is the VPC-wide component that enables bidirectional communication between the VPC and the internet. A NAT gateway must be provisioned inside a public subnet whose route table includes a 0.0.0.0/0 route to this IGW; without the IGW, the NAT gateway cannot resolve an external destination or forward return traffic. In short, the IGW is the essential upstream path that makes the NAT gateway's outbound translation functional.
- ✗
Assign an Elastic IP address to the EC2 instance.
Why it's wrong here
Assigning an Elastic IP (EIP) to the EC2 instance would give it a public, static IP address and directly attach it to the internet through the VPC's Internet Gateway. That configuration is the opposite of what is wanted for a private instance — it would allow inbound connections from the internet and expose the instance, defeating the purpose of the private subnet. Furthermore, the instance does not need its own EIP; the NAT gateway will use a separate EIP for outbound address translation.
- ✓
Add a route to the private subnet's route table with destination 0.0.0.0/0 pointing to the NAT Gateway.
Why this is correct
To allow instances in a private subnet to reach the internet, their subnet's route table must contain a default route (destination 0.0.0.0/0) pointing to the NAT Gateway's network interface. Without this route, the private instance's outbound packets are only delivered to destinations within the VPC CIDR, and any attempt to reach an external IP will fail with a routing error. This route is what directs traffic from the private instance to the NAT gateway, which then performs source address translation and sends it to the IGW.
- ✗
Deploy a bastion host in the private subnet.
Why it's wrong here
A bastion host (or jump box) is used for administrative inbound access, typically SSH or RDP, to instances located in private subnets. Placing a bastion host in the private subnet would still require it to have a route to the internet for tooling, but more importantly it does not enable general outbound internet access for other private instances — it only provides a secure entry point for management traffic. The correct component for outbound internet is a NAT gateway, not a bastion host.
- ✓
Place a NAT Gateway in a public subnet.
Why this is correct
The NAT Gateway must reside in a public subnet — a subnet that has a direct route to an Internet Gateway and uses an Elastic IP address. This placement allows the NAT gateway to receive outbound packets from private instances, translate their source IP addresses to its own EIP, and forward the traffic through the IGW to the internet. If the NAT gateway were placed in a private subnet, it would have no path to the IGW and thus could not perform its function.
Visual reference
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.