AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A company uses two private subnets, one in each of two Availability Zones (AZ-A and AZ-B). All outbound internet traffic is routed through a single NAT gateway that is deployed in a public subnet in AZ-A. After an unplanned AZ-A outage, instances in AZ-B lost internet connectivity. The operations team must improve fault tolerance and reduce inter-AZ data processing charges while keeping administration effort low. What should the team do?
Replace the NAT gateway with auto-scaled NAT instances placed in each AZ and manage failover with a Network Load Balancer.
Move the existing NAT gateway to a shared services VPC in AZ-A and route both private subnets to it through VPC peering connections.
Attach an internet gateway directly to each private subnet and add a 0.0.0.0/0 route pointing to it.
Create a second NAT gateway in a public subnet in AZ-B and update the AZ-B private subnet's route table to use that gateway.
A NAT gateway is an AWS-managed, highly available service within a single AZ. If that AZ fails, the gateway becomes unavailable. Best practice is to create a separate NAT gateway in every AZ and configure each private subnet's route table to use the local gateway. This restores internet access during an AZ outage and prevents traffic from crossing AZ boundaries, eliminating inter-AZ data transfer fees. NAT instances add operational overhead and do not provide built-in redundancy; a single gateway cannot survive an AZ failure; and attaching an internet gateway directly to a private subnet is not possible because IGWs must be associated with the VPC as a whole and require public IP addresses on the instances.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a NAT gateway, and how does it work?
Open an interactive chat with Bash
Why does creating NAT gateways in each Availability Zone improve fault tolerance?
Open an interactive chat with Bash
What are the inter-AZ data processing charges, and how does this setup reduce them?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .