Courseiva

SAA-C03 Interface VPC endpoints use AWS PrivateLink. Practice Question

A private application in two private subnets must download objects from S3 and read parameters from Systems Manager Parameter Store without routing traffic through the public internet. Which two components should the architect use? The design must avoid adding custom operational scripts.

⚠ Common exam trap

Candidates often confuse Gateway VPC endpoints (used for S3 and DynamoDB) with Interface VPC endpoints (used for most other AWS services like Systems Manager), and may incorrectly assume a NAT gateway or internet gateway is needed for private subnet access to AWS services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Interface VPC endpoint for Systems Manager

Option A is correct because an Interface VPC endpoint (powered by AWS PrivateLink) for Systems Manager creates elastic network interfaces in the private subnets with private IP addresses, allowing the instances to call the ssmmessages, ec2messages, and ssm endpoints privately without traversing the public internet. Option D is correct because a Gateway VPC endpoint for Amazon S3 adds a route-table target that lets traffic to S3 stay on the AWS private network, so the private application can download objects without an internet or NAT path. Together these two endpoints satisfy the requirement to reach both S3 and Parameter Store privately and require no custom operational scripts. Option B is not appropriate because an Internet gateway provides public internet connectivity and would expose or require public routing, which the scenario explicitly forbids. Option C is not appropriate because a NAT gateway enables outbound internet access (and incurs cost per AZ) rather than keeping traffic private, so it does not meet the no-public-internet requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Interface VPC endpoint for Systems Manager

    Why this is correct

    An interface VPC endpoint provisions an elastic network interface with a private IP in each subnet, carrying AWS PrivateLink traffic to Systems Manager Parameter Store. This satisfies the stem's requirement to read parameters without public internet routing and without custom operational scripts.

  • ✗

    Internet gateway attached to the VPC

    Why it's wrong here

    An internet gateway only enables public IPv4 connectivity for resources with public addresses; private subnets have no route to it, so S3 and Parameter Store traffic cannot traverse it. It is tempting because it is the standard egress path for public subnets, and would be correct if the instances held Elastic IPs and the requirement permitted internet routing.

  • ✗

    NAT gateway in each Availability Zone

    Why it's wrong here

    A NAT gateway routes traffic to the public internet via an internet gateway, which the stem explicitly forbids; it also cannot reach S3 or Parameter Store without public endpoints. It is tempting because NAT gateways are the usual answer for private-subnet egress, and would be correct if outbound internet access were permitted.

  • ✓

    Gateway VPC endpoint for Amazon S3

    Why this is correct

    A gateway VPC endpoint adds a route-table target for S3 prefix lists, so private-subnet traffic to S3 stays on the AWS network. This satisfies the stem's requirement to download objects without public internet routing and without custom operational scripts.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.