Q: 6
A CloudOps engineer has created a VPC that contains a public subnet and a private subnet. Amazon
EC2 instances that were launched in the private subnet cannot access the internet. The default
network ACL is active on all subnets in the VPC, and all security groups allow outbound traffic.
Which solution will provide the EC2 instances in the private subnet with access to the internet?
Options
Discussion
Option A. I've seen similar questions on practice exams and the official guide covers this setup.
Option D
Seen similar on practice exams-official study guide covers this. A
A, not B. Public subnet routing in B is a trap. Saw this pattern on a similar exam question.
A/B? Only A actually routes the private subnet outbound, B misses that detail. Pretty sure it's A but AWS wording sometimes flips stuff.
B
D imo, since the question trips up on where the NAT should go.
A for sure. NAT gateway goes in the public subnet, then route private subnet’s outbound traffic through it so those EC2s can hit the internet. Pretty basic VPC setup. Correct me if I’m missing something!
A saw a similar question on an exam report recently.
A tbh
Be respectful. No spam.