exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C02 exam

Exam AWS Certified Solutions Architect - Associate SAA-C02 topic 1 question 477 discussion

An Amazon EC2 instance is located in a private subnet in a new VPC. This subnet does not have outbound internet access, but the EC2 instance needs the ability to download monthly security updates from an outside vendor.
What should a solutions architect do to meet these requirements?

  • A. Create an internet gateway, and attach it to the VPC. Configure the private subnet route table to use the internet gateway as the default route.
  • B. Create a NAT gateway, and place it in a public subnet. Configure the private subnet route table to use the NAT gateway as the default route.
  • C. Create a NAT instance, and place it in the same subnet where the EC2 instance is located. Configure the private subnet route table to use the NAT instance as the default route.
  • D. Create an internet gateway, and attach it to the VPC. Create a NAT instance, and place it in the same subnet where the EC2 instance is located. Configure the private subnet route table to use the internet gateway as the default route.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
10minute
Highly Voted 3 years, 7 months ago
B) CORRECT NAT Gateway in public subnets with editing private subnets route table so EC2 machines get only outbound internet connection
upvoted 27 times
Grandslam
3 years, 7 months ago
You still need an internet gateway to route out. Answer B does not mention an Internet Gateway...
upvoted 1 times
rlnd2000
3 years, 7 months ago
""Create a NAT gateway, and place it in a public subnet..."". => The only thing we need is a Public subnet to create the NAT, if we have a public subnet the internet gateway is in the VPC I think.
upvoted 1 times
Grandslam
3 years, 6 months ago
You have to specifically have an internet gateway with an associated route (usually the default route) pointing to it. Otherwise your NAT is for private use between VPC Only.
upvoted 1 times
Grandslam
3 years, 6 months ago
B is correct: When using an Nat gateway in public subnet without an internet gateway allows egress traffic to be established and NOT ingress traffic. Very interesting. Thanx! https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html Scenario: Access the internet from a private subnet You can use a public NAT gateway to enable instances in a private subnet to send outbound traffic to the internet, but the internet cannot establish connections to the instances.
upvoted 2 times
...
...
...
Phyo007
3 years, 5 months ago
Basically, if the subnet doesn't have an internet gateway, we can't call it a 'Public subnet'. So, we can assume that the internet gateway is already there.
upvoted 1 times
...
...
Grandslam
3 years, 7 months ago
"Internet Gateway is required to provide internet access to the NAT Gateway." https://aws.amazon.com/about-aws/whats-new/2021/06/aws-removes-nat-gateways-dependence-on-internet-gateway-for-private-communications/
upvoted 3 times
osel
3 years, 3 months ago
PrivateSubnet EC2 -> NAT GW -> IGW -> Public Internet
upvoted 5 times
fedeX
2 years, 8 months ago
So is D
upvoted 1 times
...
...
...
...
vvsandipvv
Highly Voted 3 years, 7 months ago
If A is correct then I will resign my job. its B
upvoted 13 times
Grandslam
3 years, 7 months ago
How do you route out to the internet without an internet gateway. This article states: "Internet Gateway is required to provide internet access to the NAT Gateway." https://aws.amazon.com/about-aws/whats-new/2021/06/aws-removes-nat-gateways-dependence-on-internet-gateway-for-private-communications/
upvoted 1 times
rlnd2000
3 years, 7 months ago
But we have a public subnet in the VPC, so... "Create a NAT gateway, and place it in a public subnet..."
upvoted 1 times
...
Phyo007
3 years, 5 months ago
Basically, if the subnet doesn't have an internet gateway, we can't call it a 'Public subnet'. So, it can be assume that the internet gateway is already there.
upvoted 2 times
...
...
...
Rahulbit34
Most Recent 2 years ago
With NAT gateway, you can access internet but no other application can access the instance.
upvoted 1 times
...
fedeX
2 years, 8 months ago
Why not D? Add IG to the public VPC network, connect the EC2 to a private NAT, NAT goes through IG and done.
upvoted 1 times
...
cloud_collector
2 years, 9 months ago
A is NOT correct I think. You can attach an internet gateway to a VPC with a private NAT gateway, but if you route traffic from the private NAT gateway to the internet gateway, the internet gateway drops the traffic. https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html
upvoted 1 times
...
L_Jackson
3 years, 3 months ago
Just by reading some of these comments. Yall need to study. NAT GATEWAY folks! BBBBBB
upvoted 2 times
...
osel
3 years, 3 months ago
Selected Answer: B
1) PrivateSubnet RouteTable can't have the default route to IGW, else it is not called a PrivateSubnet but a PublicSubnet. 2) NAT Instance must sit in the PublicSubnet, else how to receive inbound connection from the public internet to function as bastion host.
upvoted 1 times
...
cannottellname
3 years, 5 months ago
NAT Gateway people!!!!! https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html
upvoted 1 times
...
jennyka76
3 years, 6 months ago
A https://docs.aws.amazon.com/dms/latest/userguide/CHAP_Introduction.html
upvoted 1 times
...
learnerportal
3 years, 6 months ago
A subnet an Internet Gateway is a public subnet. NAT Gateway should be placed in a public subnet for outbound internet connection. Hence, it should be B.
upvoted 1 times
...
sayhisujeet
3 years, 7 months ago
Correct Ans B
upvoted 5 times
...
virginia167
3 years, 7 months ago
the answer is B
upvoted 7 times
...
CobraBoy
3 years, 7 months ago
B, https://medium.com/awesome-cloud/aws-vpc-difference-between-internet-gateway-and-nat-gateway-c9177e710af6#:~:text=Internet%20Gateway%20(IGW)%20allows%20instances,IPs%20to%20access%20the%20internet.
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago