Q: 6
A CloudOps engineer has created a VPC that contains a public subnet and a private subnet. Amazon
EC2 instances that were launched in the private subnet cannot access the internet. The default
network ACL is active on all subnets in the VPC, and all security groups allow outbound traffic.
Which solution will provide the EC2 instances in the private subnet with access to the internet?
Options
Discussion
Option A. I've seen similar questions on practice exams and the official guide covers this setup.
B
Don’t think it’s B. For private subnet EC2s to get internet, you need a NAT gateway in the public subnet, then update the private subnet's route table. Option B is a common trap because it has the route in the wrong place: traffic should go from the private subnet to NAT, not public. I’m pretty sure A lines up with AWS networking best practices. If anyone disagrees, would love to hear why!
Be respectful. No spam.