Courseiva

SAA-C03 Design Cost-Optimized Architectures Practice Question

A dev sandbox currently uses two NAT gateways in each of three Availability Zones, but only one private subnet per AZ needs outbound internet access. What should the architect review first?

⚠ Common exam trap

Watch out — candidates often assume more NAT gateways always improve availability or performance, but the question tests cost optimization by recognizing that one per AZ is often enough for low-traffic private subnets, and the first step is to verify sufficiency before making changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Whether one NAT gateway per AZ is sufficient for the required private subnets

The question states that only one private subnet per AZ needs outbound internet access, so using two NAT gateways per AZ is likely over-provisioned and costly. The architect should first review whether one NAT gateway per AZ is sufficient, as NAT gateways are billed per hour and per gigabyte of data processed, and reducing from two to one per AZ can cut costs without sacrificing availability. This aligns with the cost-optimized design principle of right-sizing resources to actual demand.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disabling route tables

    Why it's wrong here

    Disabling route tables would not reduce cost and would actually break all network traffic in the sandbox. Route tables are mandatory for any subnet to function; they determine how traffic is directed, including the default route to the NAT gateway. Removing or disabling them would make private subnets unable to route any packets, not even to the VPC's local network, thus undermining the entire environment. Cost optimization must not sacrifice fundamental routing, and this option is neither practical nor targeted at the NAT gateway expense.

  • ✗

    Replacing every NAT gateway with an internet gateway attached to private subnets

    Why it's wrong here

    An internet gateway (IGW) does not perform NAT for private instances; it only enables communication for resources with public IP addresses. If you attach an IGW to a private subnet, instances still lack public IPs and a route to the IGW, so outbound internet traffic will simply fail. To make it work, you would have to assign public IPs and convert your private subnets into public ones, which defeats the purpose of having a private subnet and exposes instances directly to the internet. Thus, this is not a like-for-like replacement and does not address the NAT gateway cost while maintaining the same architecture.

  • ✗

    Moving all workloads to public subnets

    Why it's wrong here

    Migrating all workloads to public subnets would eliminate the need for NAT gateways, but at the cost of removing the security boundary provided by private subnets. Public instances are directly reachable from the internet, requiring tight security group rules and exposing the attack surface; this is a security regression, not a cost-first best practice. Even if you maintain security groups, anything accidentally misconfigured could lead to data exposure. The question is focused on cost reduction without compromising the sandbox's architectural integrity, so this option is wrong because it trades security for cost rather than optimizing within the existing design.

  • ✓

    Whether one NAT gateway per AZ is sufficient for the required private subnets

    Why this is correct

    The correct cost-first question is whether one NAT gateway per AZ is sufficient for the required private subnets. Each NAT gateway incurs an hourly charge, so having two NAT gateways in the same AZ is redundant because they provide no additional resilience—AWS already makes a single NAT gateway highly available within its AZ. For a dev sandbox that may only use a single AZ or does not demand multi-AZ high availability, one NAT gateway is enough to serve all private subnets in that AZ. This optimization directly reduces the number of NAT gateways billed, while still meeting the actual connectivity and resilience needs if positioned correctly per AZ.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.