AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
Your company runs Linux workloads in two private subnets spread across Availability Zones A and B of a VPC. The instances need to download security patches from the public internet, but must never be reachable from the internet. The solution must stay operational if one AZ fails and should minimize day-to-day administration. What is the MOST appropriate networking configuration?
Launch a single NAT instance with source/destination check disabled in one public subnet and add a 0.0.0.0/0 route from all private subnets to the instance's ENI.
Attach an internet gateway to the VPC and add a 0.0.0.0/0 route in the private subnets that points to the internet gateway.
Create a NAT gateway in each public subnet, associate an Elastic IP with each gateway, and add a default route in each private subnet that targets the NAT gateway in the same AZ.
Deploy an egress-only internet gateway and add a ::/0 route in the private subnets while leaving out an IPv4 default route.
A managed NAT gateway placed in a public subnet provides outbound IPv4 connectivity for resources in private subnets while blocking unsolicited inbound traffic. Because a NAT gateway is an AZ-scoped resource, you create one in the public subnet of each Availability Zone and add a 0.0.0.0/0 route in each private subnet that targets the NAT gateway in the same AZ. This design is highly available across AZs and requires no maintenance. An internet gateway alone would expose the instances to inbound traffic. A single NAT instance creates a single-AZ fault domain and requires patching and scaling. An egress-only internet gateway supports only IPv6 traffic, so it does not meet the IPv4 update requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a NAT gateway and how does it work?
Open an interactive chat with Bash
Why is a NAT gateway more suitable than a NAT instance in this scenario?
Open an interactive chat with Bash
What is the difference between an Internet Gateway and a NAT Gateway?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .