SAA-C03 Design Cost-Optimized Architectures Practice Question
A batch analytics job currently uses two NAT gateways in each of three Availability Zones, but only one private subnet per AZ needs outbound internet access. What should the architect review first?
⚠ Common exam trap
Test-takers frequently assume more NAT gateways always improve reliability, but the question emphasizes cost optimization, so the first review should be whether the existing number of gateways is necessary rather than immediately adding or removing resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Whether one NAT gateway per AZ is sufficient for the required private subnets
The question asks what the architect should review first. Using two NAT gateways per Availability Zone (AZ) when only one private subnet per AZ needs outbound internet access is likely over-provisioned and costly. The architect should first verify if a single NAT gateway per AZ can handle the traffic load, as NAT gateways are highly available within an AZ and can support up to 45 Gbps of bandwidth. This review directly addresses cost optimization without sacrificing functionality.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Replacing every NAT gateway with an internet gateway attached to private subnets
Why it's wrong here
An internet gateway (IGW) is a VPC-level resource, not a per-subnet device, and it cannot be 'attached' to private subnets. When a private subnet routes 0.0.0.0/0 to an IGW, instances would need public IP addresses to actually reach the internet; without them the route is ineffective, and with them the subnet is effectively public. An IGW permits bidirectional traffic, so inbound connections from the internet can reach those resources, completely undermining the isolation that private subnets and NAT gateways are designed to provide. Replacing NAT gateways with IGWs does not preserve outbound-only access and is not a valid cost optimization.
- ✓
Whether one NAT gateway per AZ is sufficient for the required private subnets
Why this is correct
The right cost-optimization review here is to ask whether the batch analytics job truly needs a NAT gateway in every Availability Zone or whether one per AZ is sufficient. A NAT gateway is a zonal resource, and the standard high-availability pattern is to deploy one per AZ and route each AZ's private subnets to its local gateway; having two NAT gateways in the same AZ adds no resiliency because an AZ failure affects both, and the second gateway only doubles the hourly and per-GB costs. If the batch job is not required to be highly available or can tolerate an AZ outage, a single NAT gateway per AZ (or even one total) could be enough, which is exactly what should be evaluated before paying for four gateways.
- ✗
Disabling route tables
Why it's wrong here
Disabling route tables is not a valid operation in AWS, and more importantly, route tables are the essential mechanism that tells each subnet where to send traffic. Every private subnet that uses a NAT gateway must have a route table with a 0.0.0.0/0 entry pointing to that gateway; without that route, the batch job's outbound internet traffic would have no path and would be dropped, breaking the analytics pipeline. Disabling or deleting route tables would also disrupt internal VPC routing, not just internet access, so it would cause a full network outage rather than any cost savings. The correct optimization is to simplify or consolidate routing, not to remove the routing layer itself.
- ✗
Moving all workloads to public subnets
Why it's wrong here
Moving all workloads to public subnets would require assigning public IP addresses and routing traffic directly through an internet gateway, which exposes the batch analytics instances to unsolicited inbound internet traffic. This fundamentally violates defense-in-depth principles because private subnets exist to keep sensitive data and processing logic inaccessible from the public internet, and many compliance frameworks mandate that data-processing workloads remain private. While this change could eliminate NAT gateway costs, it is not a cost-first best practice because the security risk and potential compliance breach far outweigh the savings; a better cost play is to right-size the NAT gateway count, not expose the workload.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.