ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 684 - SAA-C03 discussion

Report
Export

A company wants to use NAT gateways in its AWS environment. The company's Amazon EC2 instances in private subnets must be able to connect to the public internet through the NAT gateways.

Which solution will meet these requirements'?

A.
Create public NAT gateways in the same private subnets as the EC2 instances
Answers
A.
Create public NAT gateways in the same private subnets as the EC2 instances
B.
Create private NAT gateways in the same private subnets as the EC2 instances
Answers
B.
Create private NAT gateways in the same private subnets as the EC2 instances
C.
Create public NAT gateways in public subnets in the same VPCs as the EC2 instances
Answers
C.
Create public NAT gateways in public subnets in the same VPCs as the EC2 instances
D.
Create private NAT gateways in public subnets in the same VPCs as the EC2 instances
Answers
D.
Create private NAT gateways in public subnets in the same VPCs as the EC2 instances
Suggested answer: C

Explanation:

A public NAT gateway enables instances in a private subnet to send outbound traffic to the internet, while preventing the internet from initiating connections with the instances. A public NAT gateway requires an elastic IP address and a route to the internet gateway for the VPC. A private NAT gateway enables instances in a private subnet to connect to other VPCs or on-premises networks through a transit gateway or a virtual private gateway. A private NAT gateway does not require an elastic IP address or an internet gateway. Both private and public NAT gateways map the source private IPv4 address of the instances to the private IPv4 address of the NAT gateway, but in the case of a public NAT gateway, the internet gateway then maps the private IPv4 address of the public NAT gateway to the elastic IP address associated with the NAT gateway. When sending response traffic to the instances, whether it's a public or private NAT gateway, the NAT gateway translates the address back to the original source IP address.

Creating public NAT gateways in the same private subnets as the EC2 instances (option A) is not a valid solution, as the NAT gateways would not have a route to the internet gateway. Creating private NAT gateways in the same private subnets as the EC2 instances (option B) is also not a valid solution, as the instances would not be able to access the internet through the private NAT gateways. Creating private NAT gateways in public subnets in the same VPCs as the EC2 instances (option D) is not a valid solution either, as the internet gateway would drop the traffic from the private NAT gateways.

Therefore, the only valid solution is to create public NAT gateways in public subnets in the same VPCs as the EC2 instances (option C), as this would allow the instances to access the internet through the public NAT gateways and the internet gateway.Reference:

NAT gateways - Amazon Virtual Private Cloud

NAT gateway use cases - Amazon Virtual Private Cloud

Amazon Web Services -- Introduction to NAT Gateways

What is AWS NAT Gateway? - KnowledgeHut

asked 16/09/2024
mohamed elfateh
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first