Courseiva

SAA-C03 Design Secure Architectures Practice Question

A startup runs a two-tier web application on Amazon EC2 instances behind an Application Load Balancer. The instances are in private subnets and must reach the internet only to download operating system patches. Security policy forbids any inbound internet traffic to the instances. Which configuration meets these requirements with the least operational overhead?

⚠ Common exam trap

The trap here is equating outbound internet access with public subnets, when a NAT gateway gives private instances outbound-only connectivity without inbound exposure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy a NAT gateway in a public subnet and route the private subnets' outbound traffic through it.

Instances in private subnets need outbound internet access for patching but must not accept inbound connections. A NAT gateway placed in a public subnet provides that one-way connectivity and is a fully managed, highly available service, minimizing operational effort. Alternatives either expose the instances publicly or require extra cross-VPC routing, both of which conflict with the policy or the simplicity requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Assign each EC2 instance an Elastic IP address and open the security group to inbound HTTPS.

    Why it's wrong here

    Elastic IP addresses make instances directly reachable from the internet, which violates the prohibition on inbound internet traffic. Opening inbound HTTPS also expands the attack surface unnecessarily. This design conflicts with the stated security policy and adds public exposure that the scenario explicitly forbids, so it is not appropriate.

  • ✗

    Create a VPC peering connection to a shared services VPC that has an internet gateway.

    Why it's wrong here

    VPC peering alone does not provide internet access unless the peered VPC routes and NATs the traffic, which adds complexity and cross-VPC dependencies. It also requires careful route table and security group configuration in both VPCs. This introduces more operational overhead than a simple NAT gateway and is not the least-effort solution for outbound patching.

  • ✓

    Deploy a NAT gateway in a public subnet and route the private subnets' outbound traffic through it.

    Why this is correct

    A NAT gateway in a public subnet allows instances in private subnets to initiate outbound connections for patching while remaining unreachable from the internet. It is a managed, highly available service, so operational overhead is minimal. This satisfies the outbound-only requirement without exposing the instances, matching the security policy and simplicity goal.

  • ✗

    Place the instances in public subnets and attach a security group that allows only outbound traffic.

    Why it's wrong here

    Public subnets give instances a route to an internet gateway, and unless a public IP is assigned they still cannot reach the internet. Assigning one would make them publicly addressable, contradicting the policy. The requirement is outbound-only internet access from private subnets, which this design does not reliably provide without exposing the instances.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.