Application servers sit in private subnets in a VPC. They must be able to download operating system patches from vendor repositories on the internet, but nothing on the internet may be able to open a connection to them. Which design does this?
AWS Certified Cloud Practitioner (CLF-C02), objective 3. Cloud technology and services medium
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
The options
Correct A NAT gateway in a public subnet, with the private subnets' route table sending 0.0.0.0/0 to it
Correct. A NAT gateway translates outbound connections started by the private instances and returns the replies, and it offers nothing an outside party can connect to. Outbound yes, inbound no, which is the requirement stated.
Not correct Assign each application server a public IP address and route the subnet to the internet gateway
Wrong. That makes every server directly addressable from the internet; only the security group would then stand between the world and the instance, which is precisely the exposure the requirement forbids.
Not correct Attach an internet gateway and add a route to it from the private subnets
Wrong, and it is a contradiction in terms: a subnet with a route to an internet gateway is what 'public subnet' means. The instances would also still need public addresses to use it.
Not correct Create a VPC endpoint for the vendor's patch repository
Wrong. VPC endpoints provide private connectivity to AWS services and to services others publish through PrivateLink. An arbitrary vendor mirror on the public internet is not reachable that way.
Why
The whole public-versus-private distinction in a VPC comes down to one line in a route table: a subnet is public if it routes 0.0.0.0/0 to an internet gateway, and private if it does not. A NAT gateway is the managed way to let private instances start outbound connections; it lives in a public subnet, is scoped to one Availability Zone (so a resilient design has one per zone) and is billed per hour plus per gigabyte processed — which is why moving AWS-bound traffic onto VPC endpoints often shows up on the bill.
Where this comes from
- Cited
- AWS exam guide task statement 3.5
Practise this
Reading one question is not practice. The trainer will draw a set from objective 3 and space the ones you get wrong.
Practise AWS Certified Cloud Practitioner (CLF-C02)
More questions on this objective
- A team builds the same stack — a load balancer, three EC2 instances and a database — by clicking through the console once for dev, once for test and once for production. The three environments have quietly drifted apart and a bug that only appears in production took a week to trace to a missing setting. They want the stack described once, reviewed in a pull request, and applied identically to each environment. Which service does that? machine-checked
- A Python reporting job runs unattended every night. Inside its own logic it needs to list objects in an S3 bucket, read a few of them, and write a summary object back, handling failures with the program's existing retry and logging code. What is the appropriate way for that program to call AWS? machine-checked
- A small team has a Java web application and no operations staff. They want to hand AWS the application package and have it provision the instances, the load balancer and the scaling policy, while keeping the ability to inspect and adjust those resources later if they need to. Which service fits? machine-checked
- A manufacturer keeps its plant-floor control application on servers inside the factory, because production must continue when the internet link drops. Its reporting and analytics run in AWS and read the same production data. Which TWO statements about this arrangement are accurate? machine-checked
- An internal application runs on a single EC2 instance in one Availability Zone. During a power event in that Availability Zone the application was unreachable for four hours. The team wants the cheapest change that keeps it serving through the same kind of event, without moving to another Region. What should they do? machine-checked
- A German insurer is told by its regulator that customer records must remain within the European Union. Four candidate Regions can all run every service the workload needs, and one of them is noticeably cheaper per instance-hour. Which consideration settles the choice of Region first? machine-checked