AWS Certified Solutions Architect Associate SAA-C03 Practice Question
A Solutions Architect is designing a network infrastructure for an application that must maintain high availability. The VPC has a public and a private subnet. Instances in the private subnet must communicate with the Internet to receive updates. These instances should not be accessible from the Internet. Which routing action should the Architect take to meet these requirements?
Attach an Internet Gateway to the private subnet's route table to enable direct communication with the Internet.
Create a NAT Gateway in the public subnet and update the private subnet's route table to route Internet-bound traffic to the NAT Gateway.
Attach a virtual private gateway to the private subnet's route table to enable instances to communicate with the Internet securely.
Create a Network Access Control List (ACL) with rules to allow outbound Internet traffic and deny inbound traffic for the private subnet.