A fleet of EC2 instances uploads build artifacts to a vendor that now enforces an allow list and requires all uploads to originate from a single public IP. What modification should the SysOps administrator make to ensure all uploads come from one IP address?
Choose an answer
Tap an option to check your answer.
Correct answer: Route all EC2 instances through a NAT gateway and provide the NAT gateway's public IP to the vendor..
Why this is the answer
Routing EC2 instances through a NAT gateway ensures all outbound traffic to the internet originates from the NAT gateway's single, static public IP address. This satisfies the vendor's requirement for an allow list based on a single IP. Internet gateways are used for public internet access but do not provide a single, static outbound IP for instances in private subnets; each instance would still have its own public IP or use an Elastic IP. Moving instances to one Availability Zone or a peered VPC does not inherently consolidate outbound public IP addresses.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed