Question 1 · choose 1
Application servers run in private subnets in two Availability Zones of a VPC that has an internet gateway attached. They must download operating system updates from the internet over IPv4, must not be reachable from the internet, and must keep outbound access if one Availability Zone fails. The security team does not allow any public subnet in this VPC. Which design meets these requirements?
- AA zonal NAT gateway in a public subnet of each zone, with each private subnet routing 0.0.0.0/0 to the gateway in its own zone
- BAn egress-only internet gateway, with both private subnets' route tables sending outbound traffic to it
- CA route from both private subnets to the internet gateway, with security groups that allow no inbound traffic
- DA regional NAT gateway for the VPC, with both private subnets' route tables sending 0.0.0.0/0 to it
Show the answer and why
AA zonal NAT gateway in a public subnet of each zone, with each private subnet routing 0.0.0.0/0 to the gateway in its own zone
Incorrect
One zonal NAT gateway per zone survives a zone failure, but each zonal public NAT gateway is hosted in a public subnet with a route to the internet gateway, and the security team allows no public subnet.
BAn egress-only internet gateway, with both private subnets' route tables sending outbound traffic to it
Incorrect
An egress-only internet gateway carries IPv6 traffic only. It cannot give instances outbound access over IPv4.
CA route from both private subnets to the internet gateway, with security groups that allow no inbound traffic
Incorrect
A route to an internet gateway turns the subnets into public subnets, and the servers would need public IP addresses to use it. The design breaks the no-public-subnet rule and leaves the servers addressable from the internet, guarded only by security groups.
DA regional NAT gateway for the VPC, with both private subnets' route tables sending 0.0.0.0/0 to it
Correct
A regional NAT gateway needs no public subnet, has its own route table with a route to the internet gateway, and expands across the Availability Zones where the workloads run, which gives high availability by default. Both subnets can route to its single ID.
Outbound-only IPv4 access calls for a NAT gateway. Zonal NAT gateways operate in one Availability Zone and sit in public subnets, so the resilient zonal design needs a public subnet per zone. A regional NAT gateway spans the zones of the workload and needs no public subnet, which meets every requirement here.
AWS documentation