A NAT Gateway lets instances in a private subnet reach the internet for outbound traffic — updates, API calls — while keeping them unreachable from the internet.

NAT Gateway vs NAT Instance

Both do NAT, but NAT Gateway is the managed, highly-available, auto-scaling option AWS recommends — no server to maintain. A NAT Instance is a self-managed EC2 doing the same job, cheaper at tiny scale but your responsibility to patch and scale. On the exam, prefer NAT Gateway unless the scenario stresses cost at low scale.

Test yourself

Practice question

Instances in a private subnet need reliable, managed outbound internet access with high availability and no servers to maintain. What do you deploy?

  1. A NAT Instance
  2. A NAT Gateway
  3. An Internet Gateway in the private subnet
  4. A VPC endpoint
👉 Click to reveal the answer & explanation

Correct answer: B. A NAT Gateway is managed, highly available, and auto-scaling for outbound-only internet access. A NAT Instance (A) is self-managed; an Internet Gateway (C) would make the subnet public; a VPC endpoint (D) reaches AWS services privately, not the general internet.

Related topics

Amazon VPC · VPC endpoints · Security groups vs NACLs

CloudExamPro Premium

Ready to pass the AWS Solutions Architect Associate (SAA-C03)?

Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.

  • ✓  6 full-length practice exams
  • ✓  A detailed explanation for every single question
  • ✓  Realistic, scenario-based questions — not memory dumps
  • ✓  Lifetime access, kept current for 2026

Get the SAA-C03 Practice Exams →or try 25 free questions first

Limited-time offer · ends in --Days:--Hrs:--Min:--Sec
Get Instant Access