Courseiva

SAA-C03 · topic practice

VPC practice questions

Practise AWS Certified Solutions Architect - Associate VPC practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member

What the exam tests

What to know about VPC

VPC questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common VPC exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Practice set

VPC questions

20 questions · select your answer, then reveal the explanation

Question 1easymultiple choice
Read the full VPC explanation →

A company wants to ensure that its internal applications can access Amazon S3 without the traffic ever leaving the AWS network or passing through the public internet. What should they implement to achieve this securely?

Question 2mediummultiple choice
Review the full subnetting walkthrough →

A developer needs to access an Amazon RDS database from an EC2 instance within a private subnet. The database must only accept traffic from the instance. Which security configuration is most appropriate?

Question 3mediummultiple choice
Review the full subnetting walkthrough →

A company is hosting a multi-tier web application on AWS using Amazon EC2 instances in a private subnet behind an Application Load Balancer (ALB). The security team requires that all incoming web traffic is encrypted in transit from the client to the ALB and from the ALB to the backend EC2 instances. Which combination of configurations meets these requirements?

Question 4easymultiple choice
Read the full VPC explanation →

A company has several VPCs in the same region that need to access an Amazon S3 bucket for data logging. Currently, data is transferred over the public internet, incurring data transfer charges. What is the most cost-effective way to allow the VPCs to access S3?

Question 5easymultiple choice
Review the full subnetting walkthrough →

A security engineer needs to block a specific range of malicious IP addresses from accessing an entire subnet within a VPC. The solution must ensure that the traffic is rejected before it reaches any EC2 instances. Which AWS feature should be used to implement this restriction?

Question 6hardmulti select
Read the full VPC explanation →

A large corporation uses AWS Organizations to manage hundreds of accounts. The security team wants to ensure that no account can provision resources in unauthorized regions and that only approved AWS services can be used. Which TWO features should be used to enforce these constraints across the entire organization? (Select TWO.)

Question 7mediummulti select
Review the full subnetting walkthrough →

A web application is deployed on Amazon EC2 instances within a private subnet. The application must receive traffic from an Application Load Balancer (ALB) in a public subnet and connect to an Amazon RDS MySQL database in a different private subnet. Which TWO steps are required to secure this architecture using security groups?

Question 8hardmultiple choice
Read the full VPC explanation →

Refer to the exhibit. A company is using this S3 bucket policy to secure high-performance data accessed by an analytics fleet on EC2. Users report that despite having the correct IAM permissions, they are receiving 403 Forbidden errors when trying to download data. What is the most likely cause of this performance and access issue?

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Deny",
      "Principal": "*",
      "Action": "s3:*",
      "Resource": "arn:aws:s3:::my-high-perf-data/*",
      "Condition": {
        "StringNotEquals": {
          "aws:sourceVpce": "vpce-1a2b3c4d"
        }
      }
    }
  ]
}
Question 9mediummulti select
Read the full VPC explanation →

An architect is designing a secure VPC architecture. Which TWO actions should be taken to ensure the infrastructure is compliant with security best practices regarding network isolation?

Question 10mediummultiple choice
Read the full VPC explanation →

A developer is using an EC2 instance to process images. The images are stored in an S3 bucket. The developer notices that the network transfer between S3 and the EC2 instance is the bottleneck. How can the developer resolve this?

Question 11hardmultiple choice
Read the full VPC explanation →

Refer to the exhibit. A solutions architect reviewed an AWS CloudFormation template used to deploy an Auto Scaling group for a production web application. During an AWS Availability Zone outage in us-east-1, users experienced partial application downtime even though the Auto Scaling group reported instances running. Why is this architecture failing resiliency best practices?

Exhibit

{
  "AWSTemplateFormatVersion": "2010-09-09",
  "Resources": {
    "WebserverGroup": {
      "Type": "AWS::AutoScaling::AutoScalingGroup",
      "Properties": {
        "AvailabilityZones": ["us-east-1a", "us-east-1b"],
        "LaunchTemplate": {
          "LaunchTemplateId": {
            "Ref": "WebLaunchTemplate"
          },
          "Version": "1"
        },
        "MinSize": "2",
        "MaxSize": "10",
        "DesiredCapacity": "2"
      }
    }
  }
}
Question 12hardmultiple choice
Read the full VPC explanation →

Refer to the exhibit. A company wants to optimize the performance and security of data transfers between their EC2 instances and an S3 bucket named 'my-app-data'. Which architectural benefit is primarily achieved by implementing the policy shown in the exhibit?

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": "*",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::my-app-data/*",
      "Condition": {
        "StringEquals": {
          "aws:SourceVpce": "vpce-1a2b3c4d"
        }
      }
    }
  ]
}
Question 13hardmulti select
Read the full VPC explanation →

A company is building a zero-trust architecture for its internal microservices running on Amazon EKS. Which THREE steps should the solutions architect take to ensure secure, least-privilege communication between services? (Select THREE)

Question 14mediummultiple choice
Read the full VPC explanation →

An application consists of a web tier and an application tier. The web tier must be accessible from the internet, but the application tier must remain private. How should the architect configure the network for maximum resilience?

Question 15mediummulti select
Review the full subnetting walkthrough →

A security architect is designing a multi-tier application in a VPC. The requirement is to block all traffic from a specific range of malicious IP addresses (CIDR 192.0.2.0/24) while allowing standard web traffic (HTTPS) from all other sources to the web tier. Which TWO actions should the architect take to implement this? (Select TWO.)

Question 16mediummultiple choice
Read the full DNS explanation →

A company is concerned about unauthorized access and potential data exfiltration within their AWS environment. They need a service that can continuously monitor VPC Flow Logs, AWS CloudTrail management events, and DNS logs to identify suspicious activities using machine learning. Which solution should the architect recommend for centralized threat detection?

Question 17mediummultiple choice
Read the full NAT/PAT explanation →

A company has several VPCs in a single region that need to access an S3 bucket for data processing. Currently, traffic goes through a NAT Gateway in each VPC. What is the most cost-effective way to provide access to S3?

Question 18mediummultiple choice
Review the full subnetting walkthrough →

A company is experiencing unauthorized network traffic in their VPC. They need to inspect traffic patterns between subnets to identify the source of the traffic. Which tool should they use?

Question 19hardmulti select
Read the full NAT/PAT explanation →

A solutions architect is reviewing the architecture of a large VPC. Currently, thousands of EC2 instances in private subnets transfer several terabytes of data daily to Amazon S3 through a NAT Gateway. The NAT Gateway costs have become prohibitively high. Which TWO changes will reduce these costs?

Question 20hardmultiple choice
Read the full VPC explanation →

Refer to the exhibit. An application running on an EC2 instance requires access to S3 objects but is encountering slow performance when fetching large files. An architect observes high network latency between the instance and S3. Which strategy will improve retrieval performance?

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": ["s3:GetObject"],
      "Resource": ["arn:aws:s3:::my-bucket/*"]
    }
  ]
}

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused VPC sessions

Start a VPC only practice session

Every question in these sessions is drawn from the VPC domain — nothing else.

Related practice questions

Related SAA-C03 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SAA-C03 exam test about VPC?
VPC questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just VPC questions in a focused session?
Yes — the session launcher on this page draws every question from the VPC domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SAA-C03 topics?
Use the topic links above to move to related areas, or go back to the SAA-C03 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SAA-C03 exam covers. They are not copied from any real exam or dump site.