Application servers sit in private subnets in a VPC. They must be able to download operating system patches from vendor repositories on the internet, but nothing on the internet may be able to open a connection to them. Which design does this?

AWS Certified Cloud Practitioner (CLF-C02), objective 3. Cloud technology and services medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

The options

Correct A NAT gateway in a public subnet, with the private subnets' route table sending 0.0.0.0/0 to it

Correct. A NAT gateway translates outbound connections started by the private instances and returns the replies, and it offers nothing an outside party can connect to. Outbound yes, inbound no, which is the requirement stated.

Not correct Assign each application server a public IP address and route the subnet to the internet gateway

Wrong. That makes every server directly addressable from the internet; only the security group would then stand between the world and the instance, which is precisely the exposure the requirement forbids.

Not correct Attach an internet gateway and add a route to it from the private subnets

Wrong, and it is a contradiction in terms: a subnet with a route to an internet gateway is what 'public subnet' means. The instances would also still need public addresses to use it.

Not correct Create a VPC endpoint for the vendor's patch repository

Wrong. VPC endpoints provide private connectivity to AWS services and to services others publish through PrivateLink. An arbitrary vendor mirror on the public internet is not reachable that way.

Why

The whole public-versus-private distinction in a VPC comes down to one line in a route table: a subnet is public if it routes 0.0.0.0/0 to an internet gateway, and private if it does not. A NAT gateway is the managed way to let private instances start outbound connections; it lives in a public subnet, is scoped to one Availability Zone (so a resilient design has one per zone) and is billed per hour plus per gigabyte processed — which is why moving AWS-bound traffic onto VPC endpoints often shows up on the bill.

Where this comes from

Cited
AWS exam guide task statement 3.5

Practise this

Reading one question is not practice. The trainer will draw a set from objective 3 and space the ones you get wrong.

Practise AWS Certified Cloud Practitioner (CLF-C02)

More questions on this objective

All questions on Cloud technology and services