AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

Your company runs Linux workloads in two private subnets spread across Availability Zones A and B of a VPC. The instances need to download security patches from the public internet, but must never be reachable from the internet. The solution must stay operational if one AZ fails and should minimize day-to-day administration. What is the MOST appropriate networking configuration?

  • Launch a single NAT instance with source/destination check disabled in one public subnet and add a 0.0.0.0/0 route from all private subnets to the instance's ENI.

  • Attach an internet gateway to the VPC and add a 0.0.0.0/0 route in the private subnets that points to the internet gateway.

  • Create a NAT gateway in each public subnet, associate an Elastic IP with each gateway, and add a default route in each private subnet that targets the NAT gateway in the same AZ.

  • Deploy an egress-only internet gateway and add a ::/0 route in the private subnets while leaving out an IPv4 default route.

AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot