AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

A company runs workloads in two private subnets (Subnet-A in us-east-1a and Subnet-B in us-east-1b). The instances must reach public payment APIs, but no inbound internet traffic is allowed. A single NAT gateway placed in a public subnet in us-east-1a is used for egress. During a recent Availability Zone failure in us-east-1a, instances in Subnet-B lost internet connectivity. As the CloudOps engineer, you must improve resiliency while keeping network egress costs as low as possible. Which solution meets these requirements?

  • Replace the NAT gateway with a highly-available NAT instance solution using an Auto Scaling group that spans both AZs.

  • Attach an internet gateway to the VPC and assign public IPv4 addresses to all instances in both private subnets.

  • Deploy a second NAT gateway in a public subnet in us-east-1b and update Subnet-B's route table to use this new NAT gateway while keeping Subnet-A routed to the existing gateway.

  • Move the existing NAT gateway to a public subnet in a third AZ and point the route tables of both private subnets to this gateway.

AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot