SAA-C03 Design Secure Architectures Practice Question
A logistics company runs workloads in a VPC with private subnets that have no internet gateway route. Instances in these subnets must retrieve secrets from AWS Secrets Manager and download patches from an Amazon S3 bucket owned by the company. The security team requires that this traffic never traverse the public internet. (Choose two.)
⚠ Common exam trap
The trap here is assuming that a NAT gateway keeps traffic private because it hides instance IPs, when in fact NAT gateway traffic still egresses to the public internet.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a gateway VPC endpoint for Amazon S3 and associate it with the private subnets' route tables.
Private connectivity to AWS services uses VPC endpoints. Secrets Manager requires an interface endpoint because it is accessed over its API through PrivateLink, while S3 supports a gateway endpoint that adds a route to the subnet route tables. Together these endpoints keep both secret retrieval and patch downloads inside the AWS network without an internet gateway or NAT gateway.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a VPC peering connection between the private subnets' VPC and the S3 service VPC in the same region.
Why it's wrong here
S3 is not a VPC that can be peered with; peering connects two customer VPCs, not an AWS service endpoint. Private access to S3 is provided by a gateway endpoint or an interface endpoint, not by peering. Attempting to peer with the S3 service network is not a supported configuration and would not establish connectivity for the patch downloads.
- ✓
Create a gateway VPC endpoint for Amazon S3 and associate it with the private subnets' route tables.
Why this is correct
A gateway endpoint for S3 adds a prefix list route to the subnet route tables that directs S3-bound traffic to the endpoint instead of an internet gateway or NAT device. Because the private subnets have no internet route, the gateway endpoint is what allows patch downloads from the company's bucket to succeed while keeping the traffic on the AWS network.
- ✗
Deploy a NAT gateway in a public subnet and route the private subnets' traffic to it.
Why it's wrong here
A NAT gateway provides outbound internet access, which means Secrets Manager and S3 requests would leave the VPC and travel over the public internet. Although it would allow the calls to succeed, it fails the explicit requirement that traffic never traverse the public internet. NAT gateways are the wrong tool when private connectivity to AWS services is mandated.
- ✗
Attach an internet gateway to the VPC and add a route for 0.0.0.0/0 to the private subnets' route tables.
Why it's wrong here
Adding an internet gateway route to the private subnets turns them into public subnets and sends traffic over the public internet, directly violating the requirement. It also exposes the instances to inbound reachability if they receive public addresses. This approach defeats the purpose of using private endpoints and is not needed for either Secrets Manager or S3 access.
- ✓
Create an interface VPC endpoint for Secrets Manager in the VPC and associate it with the private subnets.
Why this is correct
Secrets Manager is accessed through an interface endpoint powered by AWS PrivateLink, which places an elastic network interface in the selected subnets and resolves the service's DNS name to private IP addresses. This keeps API calls to Secrets Manager entirely within the AWS network, satisfying the requirement that secret retrieval traffic never traverse the public internet.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.