Courseiva

SAA-C03 Design Cost-Optimized Architectures Practice Question

A service runs in private subnets. It must call AWS APIs (for example, S3 and Secrets Manager). The team currently sends all outbound traffic through a NAT Gateway, and NAT charges have become a major cost driver. The workload must not traverse the public internet. What change most directly reduces NAT Gateway cost while maintaining private connectivity to those AWS services?

⚠ Common exam trap

Test-takers frequently think NAT Gateway is the only way to provide outbound connectivity, overlooking that VPC endpoints can provide private, cost-effective access to AWS services without internet routing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Replace the NAT Gateway route with VPC endpoints: use a Gateway VPC endpoint for S3 and an Interface VPC endpoint for Secrets Manager.

VPC endpoints allow private connectivity to AWS services without traversing the internet or a NAT Gateway. A Gateway VPC endpoint for S3 uses route table entries to reach S3 privately, and an Interface VPC endpoint for Secrets Manager uses an elastic network interface with a private IP. This eliminates NAT Gateway data processing charges entirely while keeping traffic within the AWS network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Continue using the NAT Gateway but reduce CloudWatch log retention to 1 day.

    Why it's wrong here

    Reducing CloudWatch log retention affects only the storage costs for logs, not the NAT Gateway's hourly usage or data processing fees. NAT Gateway charges are based on the amount of data it forwards per GB and the amount of time the gateway is provisioned, regardless of how many logs are kept. Since the workload's outbound API calls still traverse the NAT to the public internet, the processing costs remain unchanged, so this does not address the underlying cost or security concern.

  • ✓

    Replace the NAT Gateway route with VPC endpoints: use a Gateway VPC endpoint for S3 and an Interface VPC endpoint for Secrets Manager.

    Why this is correct

    VPC endpoints provide private connectivity to AWS services without sending traffic through the internet or through NAT. A Gateway endpoint is used for S3, and an Interface endpoint is used for services like Secrets Manager. Traffic to those services stays within the AWS network, reducing or eliminating NAT charges for those API calls.

  • ✗

    Launch a bastion host in a public subnet and force private instances to use SSH tunneling for API calls.

    Why it's wrong here

    Using a bastion host for SSH tunneling would require each private instance to maintain an encrypted tunnel to the bastion, and then the bastion would still need to route API traffic outbound — typically through a NAT gateway or internet gateway to reach the public AWS endpoints. This adds complexity, creates a single point of failure, and does not reduce NAT data processing charges because the traffic still leaves the VPC and traverses the internet. Moreover, the SSH tunnels themselves become a management burden and do not keep traffic securely within the AWS network.

  • ✗

    Switch to public subnets and attach security groups with the same rules to limit inbound access.

    Why it's wrong here

    Moving instances to public subnets and relying on security groups does not eliminate the need to reach AWS APIs via the public internet; traffic still goes through the internet gateway and across the public network. Security groups only filter inbound and outbound traffic, but they do not provide private connectivity to AWS services, nor do they reduce the cost or latency of API calls. This approach also increases the attack surface by exposing instances to the internet, and it does not satisfy the requirement to keep traffic within the AWS private backbone.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.