SAA-C03 Design Secure Architectures Practice Question
A workload runs in private subnets and must reach Amazon S3 and AWS Secrets Manager without using the internet or a NAT gateway. The team wants to keep the traffic on AWS private networking and avoid public IPs. Which two changes should the architect make? Select two.
⚠ Common exam trap
Many exam-takers confuse gateway endpoints (for S3 and DynamoDB) with interface endpoints (for most other services) and may incorrectly assume a NAT gateway is needed for all AWS service access, ignoring that gateway endpoints provide a free, internet-free alternative for S3.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an S3 gateway VPC endpoint and update the route tables for the private subnets.
Option A is correct because an S3 gateway VPC endpoint provides private access to Amazon S3 by adding a prefix-list route to the private subnet route tables, so traffic to S3 stays on the AWS network without internet or NAT. Option C is correct because AWS Secrets Manager is accessed through an interface VPC endpoint (AWS PrivateLink), which creates an elastic network interface in the subnet and requires the workload's security group to allow outbound/inbound access to that endpoint on port 443. Option B is wrong because a NAT gateway still routes traffic through the internet and requires a public subnet, which the scenario explicitly excludes. Option D is wrong because assigning public IPv4 addresses exposes the instances to the internet and does not provide private AWS service access. Option E is wrong because VPC peering connects VPCs, not AWS service endpoints, and cannot be used to reach S3 or Secrets Manager privately.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an S3 gateway VPC endpoint and update the route tables for the private subnets.
Why this is correct
An S3 gateway endpoint attaches to the private subnet route tables, directing S3 traffic through AWS's private network instead of the internet or NAT gateway. This satisfies the constraint of reaching S3 without public IPs, and gateway endpoints cost nothing per hour.
- ✗
Place a NAT gateway in the public subnet so the private instances can reach AWS services.
Why it's wrong here
A NAT gateway routes traffic through the public subnet and the internet, giving instances public-facing egress and contradicting the requirement to avoid both. It is tempting because NAT gateways commonly grant private-subnet access to AWS services, and would be correct if internet egress were permitted.
- ✓
Create an interface VPC endpoint for AWS Secrets Manager and allow the workload security group to reach it.
Why this is correct
Secrets Manager is not supported by gateway endpoints, so an interface endpoint (powered by AWS PrivateLink) is required. Adding it to the workload's security group allows the private subnets to reach Secrets Manager entirely over private networking, avoiding NAT and public IPs.
- ✗
Assign public IPv4 addresses to the instances and restrict them with security groups.
Why it's wrong here
Public IPv4 addresses expose the instances to the internet and route S3 and Secrets Manager traffic over public endpoints, breaching the no-public-IP requirement. It is tempting because security groups can restrict inbound access, and would be correct if internet-based access with tight filtering were acceptable.
- ✗
Use VPC peering to the AWS service endpoints instead of VPC endpoints.
Why it's wrong here
VPC peering connects VPCs to each other, not to AWS service endpoints, and S3 and Secrets Manager are not reachable through a peering connection. It is tempting because peering keeps traffic on the AWS backbone, and would be correct for private connectivity between two customer VPCs.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.