Full AWS Practitioner Certification Question

An EC2 instance has been provisioned inside a private subnet of a newly created VPC. The subnet currently lacks any form of outbound internet access. However, the EC2 instance must be able to retrieve monthly security patches from an external vendor's internet-facing service. What is the appropriate solution to allow the EC2 instance to securely download these updates without exposing it directly to the internet?