Question: 1/50
You are designing a VCN with public and private subnets. Instances in a private subnet must download OS updates from the internet, but must not accept any inbound internet-initiated connections. Which design best meets this requirement?
Use an Internet Gateway for the private subnet and allow inbound traffic using a security list
Use a NAT Gateway for egress and keep the private subnet without a route to an Internet Gateway
Use a Service Gateway to reach public internet update repositories
Use a Dynamic Routing Gateway (DRG) to provide internet access for the private subnet