AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
An Ops team will launch a new VPC (10.0.0.0/16) spanning two Availability Zones. Each AZ will host one public and one private subnet. Resources in private subnets must initiate outbound internet connections even if one AZ becomes unavailable, and networking costs should be kept as low as AWS best practices allow. Which subnet and NAT configuration meets these requirements?
Create one NAT gateway in a public subnet of Availability Zone A and associate both private subnet route tables with this gateway.
Deploy a NAT gateway in each public subnet and configure each private subnet's route table to use the NAT gateway located in the same Availability Zone.
Launch a single NAT instance in one public subnet and update both private subnet route tables to forward 0.0.0.0/0 traffic to that instance.
Provision two NAT gateways in a dedicated services subnet located in Availability Zone A and point all private subnets to those gateways for internet access.
Placing a NAT gateway in each Availability Zone and ensuring that the private subnet in that AZ routes traffic to the local gateway provides resiliency against an AZ outage; if one zone fails, the other zone's NAT gateway continues to operate. This design also avoids the cross-AZ data processing charges that occur when a subnet routes through a NAT gateway in another AZ. A single NAT gateway or NAT instance represents a single point of failure, and locating both gateways in one AZ undermines availability while still incurring cross-AZ traffic costs.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why does each AZ need its own NAT gateway?
Open an interactive chat with Bash
What are cross-AZ data processing charges?
Open an interactive chat with Bash
What is a NAT gateway and how does it differ from a NAT instance?
Open an interactive chat with Bash
What is a NAT gateway and its purpose in AWS?
Open an interactive chat with Bash
Why is it important to deploy a NAT gateway in each Availability Zone?
Open an interactive chat with Bash
What are cross-AZ data processing charges and why should they be avoided?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .