AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A company created a VPC with two private subnets that have only IPv6 CIDR blocks. EC2 instances in these subnets must download operating-system updates from public repositories on the internet, but company policy forbids any unsolicited inbound connections from the internet to those instances. Which solution satisfies the requirements in the most cost-effective way?
Create an egress-only internet gateway, attach it to the VPC, and add a ::/0 route in each subnet's route table that targets the gateway.
Create an interface VPC endpoint for AWS Systems Manager and block all other outbound IPv6 traffic with network ACLs.
Create a NAT gateway in a public subnet, enable DNS64 for the private subnets, and add a 64:ff9b::/96 route in each subnet's route table that targets the NAT gateway.
Attach a standard internet gateway to the VPC and rely on outbound-only rules in each subnet's security group to block inbound traffic.
An egress-only internet gateway (EIGW) is purpose-built for outbound-only IPv6 connectivity. It is stateful, so return traffic is automatically allowed while unsolicited inbound IPv6 packets are dropped, meeting the security requirement without extra rules. EIGWs have no hourly charge, so they are cheaper than alternatives. A NAT gateway could also work by using NAT64 together with DNS64, but it adds hourly and data-processing costs. A standard internet gateway would expose the instances to inbound IPv6 traffic unless every subnet or instance is locked down with security groups; the policy prefers the gateway itself to block such traffic. Interface VPC endpoints provide private access to specific AWS services only and cannot reach public package mirrors.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an egress-only internet gateway (EIGW)?
Open an interactive chat with Bash
Why is a NAT gateway not the cost-effective solution here?
Open an interactive chat with Bash
What is the difference between standard internet gateways and egress-only internet gateways?
Open an interactive chat with Bash
What is an egress-only internet gateway (EIGW)?
Open an interactive chat with Bash
How does IPv6 communication differ from IPv4 in this scenario?
Open an interactive chat with Bash
Why is a NAT gateway with DNS64 not the most cost-effective option here?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .