After replacing NAT instance appliances with NAT gateways, EC2 instances in a private subnet cannot reach the internet. Which of the following could be reasons for this failure? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: The application uses a network protocol that the NAT gateway does not support., The NAT gateway is not showing an Available state..
Why this is the answer
The application using an unsupported network protocol is a valid reason because NAT gateways support TCP, UDP, and ICMP. If the application attempts to use a different protocol, traffic will fail. A NAT gateway not showing an "Available" state indicates it's not operational, preventing any traffic from flowing through it. Incorrect options: NAT gateways do not have security groups associated with them; security groups are applied to the EC2 instances. NAT gateways must be created in a specific Availability Zone, and they are designed to be highly available within that AZ. Creating it in an unsupported AZ is not a typical failure mode. Port forwarding rules are not relevant here, as NAT gateways primarily handle outbound internet access for instances in private subnets, not inbound access to internal services.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed