SAA-C03 Design Secure Architectures Practice Question
A private application in two private subnets must download objects from S3 and read parameters from Systems Manager Parameter Store without routing traffic through the public internet. Which two components should the architect use?
⚠ Common exam trap
It's easy for candidates to confuse gateway endpoints (used for S3 and DynamoDB) with interface endpoints (used for most other AWS services), and may incorrectly assume a NAT gateway or internet gateway is needed for private subnet outbound traffic, ignoring that gateway endpoints work via route tables without public IPs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Interface VPC endpoint for Systems Manager
Interface VPC endpoints (AWS PrivateLink) enable private connectivity to Systems Manager Parameter Store by creating an elastic network interface in the subnet with a private IP, allowing the application to read parameters without traversing the internet. Gateway VPC endpoints for S3 provide private access to S3 objects via route table entries, using the S3 public IP space but staying within the AWS network, avoiding the need for an internet gateway or NAT gateway.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Interface VPC endpoint for Systems Manager
Why this is correct
The interface VPC endpoint for Systems Manager is correct because SSM is a services that requires an interface endpoint powered by AWS PrivateLink. This creates elastic network interfaces (ENIs) with private IPs from the subnet that allow the private application to reach SSM without traversing the public internet, a NAT gateway, or an internet gateway. Traffic stays entirely within the AWS network, satisfying the private-only requirement.
- ✗
Internet gateway attached to the VPC
Why it's wrong here
An internet gateway attached to the VPC is not used by private subnets because the route table for a private subnet does not have a route to the internet gateway, and a subnet must be public with a 0.0.0.0/0 route pointing to an internet gateway to access it. Even if it were utilized, traffic would leave the AWS private network and traverse the public internet, which would not keep the communication private. Since the application is in private subnets, an internet gateway does not provide the required private connectivity.
- ✗
NAT gateway in each Availability Zone
Why it's wrong here
A NAT gateway in each Availability Zone provides outbound internet access, but it still routes traffic through the public side of the VPC via an internet gateway, so traffic to AWS services like Systems Manager would leave the AWS private backbone and travel over the public internet. This does not keep traffic fully private, and a NAT gateway is not a substitute for VPC endpoints. Additionally, a NAT gateway still requires an internet gateway to function, which reintroduces the public internet dependency and fails the private-only requirement.
- ✓
Gateway VPC endpoint for Amazon S3
Why this is correct
A gateway VPC endpoint for Amazon S3 is a correct private connectivity option because it allows instances in private subnets to reach S3 using prefix lists in the route table, without needing an internet gateway, NAT gateway, or interface endpoint. Traffic to S3 over a gateway endpoint stays entirely within the AWS network and is also free of charge. This makes it an ideal method for downloading objects directly from S3 while preserving privacy and minimizing cost.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.