AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

A company created a VPC with two private subnets that have only IPv6 CIDR blocks. EC2 instances in these subnets must download operating-system updates from public repositories on the internet, but company policy forbids any unsolicited inbound connections from the internet to those instances. Which solution satisfies the requirements in the most cost-effective way?

  • Create an egress-only internet gateway, attach it to the VPC, and add a ::/0 route in each subnet's route table that targets the gateway.

  • Create an interface VPC endpoint for AWS Systems Manager and block all other outbound IPv6 traffic with network ACLs.

  • Create a NAT gateway in a public subnet, enable DNS64 for the private subnets, and add a 64:ff9b::/96 route in each subnet's route table that targets the NAT gateway.

  • Attach a standard internet gateway to the VPC and rely on outbound-only rules in each subnet's security group to block inbound traffic.

AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot