AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A CloudOps engineer has deployed EC2 instances in two private subnets of a dual-stack VPC. Each instance has both IPv4 and IPv6 addresses. Compliance mandates that the workloads download package updates only over IPv6 while remaining unreachable from the public internet. The solution must be highly available and incur the lowest possible cost. Which action should the engineer take?
Provision a NAT Gateway in each Availability Zone and add a ::/0 IPv6 route from the private subnets to the NAT Gateways.
Create interface VPC endpoints for the required package repositories and restrict all other outbound traffic with network ACLs.
Create an egress-only internet gateway, attach it to the VPC, and add a ::/0 route in each private subnet's route table.
Attach an internet gateway to the VPC and rely on security group rules to allow only outbound IPv6 traffic from the instances.
An egress-only internet gateway provides outbound-only IPv6 connectivity for resources inside a VPC. Because it does not allow unsolicited inbound traffic, the instances remain unreachable from the internet while still reaching public repositories over IPv6. There is no hourly charge for the gateway, only standard data-transfer fees, so it is the most cost-effective managed option. NAT Gateways and NAT instances do not support IPv6, an internet gateway would make the subnets publicly routable, and interface VPC endpoints cannot reach arbitrary external package repositories.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is an egress-only internet gateway suitable for IPv6 traffic?
Open an interactive chat with Bash
Why can't NAT Gateways be used for IPv6 traffic?
Open an interactive chat with Bash
What makes the egress-only internet gateway cost-effective?
Open an interactive chat with Bash
What is an egress-only internet gateway in AWS?
Open an interactive chat with Bash
Why is a NAT Gateway not suitable for IPv6 traffic?
Open an interactive chat with Bash
How does an internet gateway differ from an egress-only internet gateway?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .