Question 1 · choose 1
A dual-stack VPC has private subnets whose instances already reach the internet over IPv4 through a NAT gateway. The instances now also have IPv6 addresses and must download updates from IPv6 servers on the internet. Nothing on the internet may start an IPv6 connection to them. What should the network team add?
- AAn egress-only internet gateway, with a ::/0 route to it in the private subnets' route table
- BA gateway VPC endpoint for the update servers, with routes in the private subnets' route table
- CAn Elastic IP address associated with each instance in the private subnets
- DA peering connection to another VPC that has an internet gateway, with a ::/0 route to the peer
Show the answer and why
AAn egress-only internet gateway, with a ::/0 route to it in the private subnets' route table
Correct
An egress-only internet gateway allows outbound IPv6 traffic and prevents the internet from initiating IPv6 connections to the instances.
BA gateway VPC endpoint for the update servers, with routes in the private subnets' route table
Incorrect
Gateway endpoints exist only for Amazon S3 and DynamoDB. They cannot reach arbitrary servers on the internet.
CAn Elastic IP address associated with each instance in the private subnets
Incorrect
An Elastic IP address is a public IPv4 address. It adds nothing for IPv6 traffic and would expose the instances over IPv4.
DA peering connection to another VPC that has an internet gateway, with a ::/0 route to the peer
Incorrect
Resources in a peered VPC cannot use the other VPC's internet gateway; peering does not support edge-to-edge routing.
IPv6 addresses are public by default, so outbound-only IPv6 needs its own component: the egress-only internet gateway, the IPv6 counterpart of outbound-only access.
AWS documentation