Courseiva

SAA-C03 Interface VPC endpoints use AWS PrivateLink. Practice Question

A private application in two private subnets must download objects from S3 and read parameters from Systems Manager Parameter Store without routing traffic through the public internet. Which two components should the architect use? The implementation must work across routine deployments without manual intervention.

⚠ Common exam trap

Watch out — candidates often confuse gateway VPC endpoints (used for S3 and DynamoDB) with interface VPC endpoints (used for most other AWS services), leading them to incorrectly select NAT gateways or internet gateways for private subnet access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Interface VPC endpoint for Systems Manager

Interface VPC endpoints (AWS PrivateLink) for Systems Manager allow private subnets to access Systems Manager Parameter Store without traversing the internet, using private IP addresses within the VPC. Gateway VPC endpoints for S3 provide a highly available, redundant path to S3 via route table entries, ensuring traffic stays within the AWS network. Together, they eliminate the need for internet gateways or NAT gateways, meeting the requirement for no public internet routing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Interface VPC endpoint for Systems Manager

    Why this is correct

    An interface VPC endpoint, powered by AWS PrivateLink, creates an elastic network interface with a private IP address directly in the subnets of your VPC. This allows instances in the private subnets to reach Systems Manager and Parameter Store using private DNS, with no internet gateway, NAT gateway, or public IP required. The traffic stays entirely within the AWS network, satisfying the requirement for fully private connectivity. This endpoint also supports security group attachment for granular traffic control.

  • ✗

    Internet gateway attached to the VPC

    Why it's wrong here

    An internet gateway is a horizontally scaled, redundant component that enables communication between a VPC and the public internet. It is associated with public subnets via a route table entry for 0.0.0.0/0, but private subnets deliberately have no such route; attaching an IGW alone does not grant private instances any connectivity. Even if you added a route, traffic to AWS services would traverse the public internet, violating the private nature of the workload. Therefore, an IGW cannot provide private, in-VPC access to Systems Manager or S3.

  • ✗

    NAT gateway in each Availability Zone

    Why it's wrong here

    A NAT gateway enables instances in private subnets to initiate outbound connections to the internet by translating their source IP to the NAT gateway's elastic IP. While it can reach AWS public endpoints, the traffic is not fully private—it leaves the VPC and travels over the public network before hitting the AWS service. Additionally, NAT gateways incur hourly and data-processing charges and are not a supported mechanism for accessing Systems Manager's private APIs. Using NAT would also require each AZ to have its own gateway and associated route table updates, still not meeting the strict privacy requirement.

  • ✓

    Gateway VPC endpoint for Amazon S3

    Why this is correct

    A gateway VPC endpoint for S3 is a route-table-based endpoint that adds an entry to the subnet's route table targeting the S3 prefix list, so traffic destined for S3 is routed through AWS's private backbone without needing NAT or an internet gateway. It is highly available across all Availability Zones by default and incurs no hourly cost. However, this type of endpoint is only supported for S3 and DynamoDB, so it cannot serve the Systems Manager access part of the requirement; it must be paired with an interface endpoint for SSM. In this scenario, it is correct for downloading 6 (likely 6 GB) from S3 privately.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.