Courseiva

SAA-C03 Design Cost-Optimized Architectures Practice Question

A workload runs in private subnets. It must access AWS services such as Amazon S3, but the company wants to avoid using a NAT Gateway to reduce outbound networking costs. What is the best solution?

⚠ Common exam trap

Candidates often assume private subnets must use a NAT Gateway or internet gateway for any AWS service access, overlooking that VPC endpoints provide direct, cost-free connectivity to supported services within the AWS network.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create VPC endpoints for the required AWS services and route traffic to them

VPC endpoints (Gateway Endpoints for S3 and DynamoDB, or Interface Endpoints for other services) allow instances in private subnets to access AWS services privately without traversing the internet or a NAT Gateway. This eliminates NAT Gateway data processing and hourly charges, directly reducing outbound networking costs while keeping traffic within the AWS network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create VPC endpoints for the required AWS services and route traffic to them

    Why this is correct

    VPC endpoints provide private connectivity from your VPC to supported AWS services without traversing the public internet or a NAT Gateway. For example, you can use a gateway endpoint for S3 (and interface endpoints for other services where supported), which avoids NAT Gateway hourly and data-processing charges.

  • ✗

    Attach Elastic IP addresses to instances in private subnets

    Why it's wrong here

    Elastic IP addresses are static public IPv4 addresses that require an instance to reside in a public subnet with a route to an Internet Gateway to be useful for egress; they do not create any private path from a private subnet to AWS service APIs. Even if you attach an EIP to an instance in a private subnet, outbound traffic would still need a NAT Gateway or similar egress device, so it cannot satisfy the cost-avoidance goal. EIPs also incur additional charges for idle addresses and fail to provide the PrivateLink-like connectivity that VPC endpoints offer.

    When this WOULD be correct

    If the question required instances in a public subnet to have static public IP addresses for outbound internet access, attaching Elastic IPs would be correct, assuming an internet gateway is configured.

  • ✗

    Install a NAT Gateway in every subnet to minimize routing hops

    Why it's wrong here

    Installing a NAT Gateway in every subnet does not remove the need for an Internet Gateway (IGW) nor does it bypass pay-per-hour and per-GB data processing charges; in fact, it compounds those costs across multiple gateways. NAT routing still forces traffic through the public border (IGW) before reaching AWS services, adding latency and complexity, which is the opposite of the low-hop private path provided by a VPC endpoint. The premise of 'minimizing routing hops' is also incorrect: a gateway endpoint for S3 or an interface endpoint for other services routes directly from your VPC to the service, without any NAT device.

    When this WOULD be correct

    A question where the requirement is to provide outbound internet access to instances in private subnets for general internet access (not just AWS services), and cost is not a primary concern. For example: 'A workload in private subnets needs to download patches from the internet. What is the most reliable solution?'

  • ✗

    Open outbound internet access with a security group rule to reach service endpoints directly

    Why it's wrong here

    Reaching AWS service endpoints via the internet typically reintroduces outbound connectivity (and associated data-transfer costs and security considerations). It also does not provide the NAT-avoidance behavior of VPC endpoints for private access to AWS services.

    When this WOULD be correct

    If the question asked about allowing outbound internet access from instances in a public subnet to a specific IP range, and the goal was to restrict traffic at the instance level, then a security group rule would be appropriate. For example: 'A web server in a public subnet needs to access an external API; which security group configuration allows this?'

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.

✓Create VPC endpoints for the required AWS services and route traffic to themCorrect answer▾

Why this is correct

VPC endpoints provide private connectivity from your VPC to supported AWS services without traversing the public internet or a NAT Gateway. For example, you can use a gateway endpoint for S3 (and interface endpoints for other services where supported), which avoids NAT Gateway hourly and data-processing charges.

✗Attach Elastic IP addresses to instances in private subnetsWrong answer — click to see why▾

Why this is wrong here

Attaching Elastic IP addresses to instances in private subnets does not provide internet access because private subnets lack a route to an internet gateway; Elastic IPs require an internet gateway to be reachable.

★ When this WOULD be the correct answer

If the question required instances in a public subnet to have static public IP addresses for outbound internet access, attaching Elastic IPs would be correct, assuming an internet gateway is configured.

Why candidates choose this

Candidates may mistakenly think Elastic IPs directly enable internet access, overlooking that private subnets cannot route to the internet without a NAT gateway or internet gateway.

✗Install a NAT Gateway in every subnet to minimize routing hopsWrong answer — click to see why▾

Why this is wrong here

Installing a NAT Gateway in every subnet increases costs (each NAT Gateway incurs hourly and data processing charges) and does not reduce outbound networking costs as required by the question.

★ When this WOULD be the correct answer

A question where the requirement is to provide outbound internet access to instances in private subnets for general internet access (not just AWS services), and cost is not a primary concern. For example: 'A workload in private subnets needs to download patches from the internet. What is the most reliable solution?'

Why candidates choose this

Candidates may think that placing a NAT Gateway in each subnet reduces latency or routing hops, and they might overlook the cost implications, especially if they are focused on network performance rather than cost optimization.

✗Open outbound internet access with a security group rule to reach service endpoints directlyWrong answer — click to see why▾

Why this is wrong here

Security group rules control inbound and outbound traffic at the instance level, but they cannot provide direct private connectivity to AWS services like S3. Instances in private subnets without a NAT Gateway or VPC Endpoint cannot reach public service endpoints over the internet.

★ When this WOULD be the correct answer

If the question asked about allowing outbound internet access from instances in a public subnet to a specific IP range, and the goal was to restrict traffic at the instance level, then a security group rule would be appropriate. For example: 'A web server in a public subnet needs to access an external API; which security group configuration allows this?'

Why candidates choose this

Candidates may think that security groups can replace network infrastructure components like NAT Gateways or VPC Endpoints, misunderstanding that security groups only filter traffic but do not provide routing or private connectivity.

Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.