AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A company runs a two-tier application in a VPC (CIDR 10.20.0.0/16). An internet gateway is attached. Web servers in a private subnet (10.20.101.0/24) need to download OS updates from the internet through a NAT gateway deployed in a public subnet. Security groups and network ACLs allow outbound HTTPS. The web servers still cannot reach the internet. What change will restore connectivity?
Add a 0.0.0.0/0 route in the private subnet's route table that targets the NAT gateway ID.
Enable auto-assign public IPv4 address on the private subnet and restart the web servers.
Create an interface VPC endpoint for Amazon S3 in the private subnet's route table.
Add an outbound 0.0.0.0/0 rule to the web servers' security group.
Instances located in a private subnet need a route that sends all non-local traffic (0.0.0.0/0) to a NAT gateway located in a public subnet that has a route to the internet gateway. Without this entry, packets intended for the internet are dropped because the route table only contains the local VPC route. Modifying security groups or assigning public IP addresses does not help; the traffic never leaves the subnet. A Gateway VPC endpoint is useful for specific AWS services, not general internet access.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a VPC and why are CIDR ranges important?
Open an interactive chat with Bash
What is the role of a NAT gateway in a VPC?
Open an interactive chat with Bash
How do route tables impact traffic flow in a VPC?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .