AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
An operations team is building a new VPC that uses only IPv6 addressing. All application tasks run in private subnets and must make outbound HTTPS requests to public internet APIs. No inbound internet traffic should ever reach the workloads. Which approach provides the required connectivity at the lowest cost while meeting the security goal?
Create a managed NAT gateway in a public subnet and add a ::/0 route from the private subnets to the NAT gateway.
Associate a standard internet gateway with the VPC and rely on network ACL rules to block all inbound traffic.
Peer the VPC to a centralized transit gateway that has DNS64 enabled and routes internet-bound traffic through a shared egress VPC.
Attach an egress-only internet gateway to the VPC and add a ::/0 route in each private subnet's route table that points to this gateway.
An egress-only internet gateway is stateful, allowing instances that have IPv6 addresses to initiate outbound connections to the internet while blocking any unsolicited inbound traffic. It is specifically designed for outbound-only IPv6 traffic and has no hourly charge, making it the most economical option. While a managed NAT gateway can handle IPv6 traffic, it incurs an hourly charge, making it a more expensive solution. A standard internet gateway would enable both inbound and outbound IPv6 traffic and would require additional security controls (like network ACLs) to meet the security goal. Using a transit gateway for simple internet egress adds unnecessary cost and complexity.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an egress-only internet gateway?
Open an interactive chat with Bash
How is a managed NAT gateway different from an egress-only internet gateway?
Open an interactive chat with Bash
Why is an internet gateway unsuitable for this use case?
Open an interactive chat with Bash
What is an egress-only internet gateway?
Open an interactive chat with Bash
How does an egress-only internet gateway differ from a managed NAT gateway?
Open an interactive chat with Bash
Why is a standard internet gateway not suitable for this use case?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .