Security, Identity, and Compliance
CoreNAT gateways
Explicit VPC egress and troubleshooting/cost boundary.
Key points
- NAT gateways provide private IPv4 egress and create a distinct routing, availability, troubleshooting, and cost boundary.
Best-known use cases
- D4.1, D4.2, and D5.1: restore or optimize the named private IPv4 outbound path through NAT.
What candidates often confuse it with
- NAT supplies private IPv4 egress; egress-only internet gateways serve IPv6 and VPC endpoints reach supported services privately.
Key takeaway
Trace the subnet route, NAT placement, public path, return filters, and actual byte path before changing NAT capacity or topology.
Related services
- AWS Certificate Manager (ACM)
- Amazon EC2 security groups
- Egress-only internet gateways
Relevant exam tasks
- D4.1 — Task 4.1: Implement and manage security and compliance tools and policies.
- 4.1.1 — Implement IAM features (for example, password policies, multi-factor authentication [MFA], roles, federated identity, resource policies, policy conditions).
- D4.2 — Task 4.2: Implement strategies to protect data and infrastructure.
- 4.2.1 — Implement and enforce a data classification scheme.
- D5.1 — Task 5.1: Implement and optimize networking features and connectivity.
- 5.1.1 — Configure a VPC (for example, subnets, route tables, network ACLs, security groups, NAT gateways, internet gateway, egress-only internet gateway).