SAA-C03 Design Secure Architectures Practice Question
A startup runs a two-tier web application on Amazon EC2 instances behind an Application Load Balancer. The instances are in private subnets and must reach the internet only to download operating system patches. Security policy forbids any inbound internet traffic to the instances. Which configuration meets these requirements with the least operational overhead?
⚠ Common exam trap
The trap here is equating outbound internet access with public subnets, when a NAT gateway gives private instances outbound-only connectivity without inbound exposure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a NAT gateway in a public subnet and route the private subnets' outbound traffic through it.
Instances in private subnets need outbound internet access for patching but must not accept inbound connections. A NAT gateway placed in a public subnet provides that one-way connectivity and is a fully managed, highly available service, minimizing operational effort. Alternatives either expose the instances publicly or require extra cross-VPC routing, both of which conflict with the policy or the simplicity requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assign each EC2 instance an Elastic IP address and open the security group to inbound HTTPS.
Why it's wrong here
Elastic IP addresses make instances directly reachable from the internet, which violates the prohibition on inbound internet traffic. Opening inbound HTTPS also expands the attack surface unnecessarily. This design conflicts with the stated security policy and adds public exposure that the scenario explicitly forbids, so it is not appropriate.
- ✗
Create a VPC peering connection to a shared services VPC that has an internet gateway.
Why it's wrong here
VPC peering alone does not provide internet access unless the peered VPC routes and NATs the traffic, which adds complexity and cross-VPC dependencies. It also requires careful route table and security group configuration in both VPCs. This introduces more operational overhead than a simple NAT gateway and is not the least-effort solution for outbound patching.
- ✓
Deploy a NAT gateway in a public subnet and route the private subnets' outbound traffic through it.
Why this is correct
A NAT gateway in a public subnet allows instances in private subnets to initiate outbound connections for patching while remaining unreachable from the internet. It is a managed, highly available service, so operational overhead is minimal. This satisfies the outbound-only requirement without exposing the instances, matching the security policy and simplicity goal.
- ✗
Place the instances in public subnets and attach a security group that allows only outbound traffic.
Why it's wrong here
Public subnets give instances a route to an internet gateway, and unless a public IP is assigned they still cannot reach the internet. Assigning one would make them publicly addressable, contradicting the policy. The requirement is outbound-only internet access from private subnets, which this design does not reliably provide without exposing the instances.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.