SAA-C03 Design Cost-Optimized Architectures Practice Question
A workload runs in private subnets. It must access AWS services such as Amazon S3, but the company wants to avoid using a NAT Gateway to reduce outbound networking costs. What is the best solution?
⚠ Common exam trap
Candidates often assume private subnets must use a NAT Gateway or internet gateway for any AWS service access, overlooking that VPC endpoints provide direct, cost-free connectivity to supported services within the AWS network.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create VPC endpoints for the required AWS services and route traffic to them
VPC endpoints (Gateway Endpoints for S3 and DynamoDB, or Interface Endpoints for other services) allow instances in private subnets to access AWS services privately without traversing the internet or a NAT Gateway. This eliminates NAT Gateway data processing and hourly charges, directly reducing outbound networking costs while keeping traffic within the AWS network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create VPC endpoints for the required AWS services and route traffic to them
Why this is correct
VPC endpoints provide private connectivity from your VPC to supported AWS services without traversing the public internet or a NAT Gateway. For example, you can use a gateway endpoint for S3 (and interface endpoints for other services where supported), which avoids NAT Gateway hourly and data-processing charges.
- ✗
Attach Elastic IP addresses to instances in private subnets
Why it's wrong here
Elastic IP addresses are static public IPv4 addresses that require an instance to reside in a public subnet with a route to an Internet Gateway to be useful for egress; they do not create any private path from a private subnet to AWS service APIs. Even if you attach an EIP to an instance in a private subnet, outbound traffic would still need a NAT Gateway or similar egress device, so it cannot satisfy the cost-avoidance goal. EIPs also incur additional charges for idle addresses and fail to provide the PrivateLink-like connectivity that VPC endpoints offer.
When this WOULD be correct
If the question required instances in a public subnet to have static public IP addresses for outbound internet access, attaching Elastic IPs would be correct, assuming an internet gateway is configured.
- ✗
Install a NAT Gateway in every subnet to minimize routing hops
Why it's wrong here
Installing a NAT Gateway in every subnet does not remove the need for an Internet Gateway (IGW) nor does it bypass pay-per-hour and per-GB data processing charges; in fact, it compounds those costs across multiple gateways. NAT routing still forces traffic through the public border (IGW) before reaching AWS services, adding latency and complexity, which is the opposite of the low-hop private path provided by a VPC endpoint. The premise of 'minimizing routing hops' is also incorrect: a gateway endpoint for S3 or an interface endpoint for other services routes directly from your VPC to the service, without any NAT device.
When this WOULD be correct
A question where the requirement is to provide outbound internet access to instances in private subnets for general internet access (not just AWS services), and cost is not a primary concern. For example: 'A workload in private subnets needs to download patches from the internet. What is the most reliable solution?'
- ✗
Open outbound internet access with a security group rule to reach service endpoints directly
Why it's wrong here
Reaching AWS service endpoints via the internet typically reintroduces outbound connectivity (and associated data-transfer costs and security considerations). It also does not provide the NAT-avoidance behavior of VPC endpoints for private access to AWS services.
When this WOULD be correct
If the question asked about allowing outbound internet access from instances in a public subnet to a specific IP range, and the goal was to restrict traffic at the instance level, then a security group rule would be appropriate. For example: 'A web server in a public subnet needs to access an external API; which security group configuration allows this?'
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.
✓Create VPC endpoints for the required AWS services and route traffic to themCorrect answer▾
Why this is correct
VPC endpoints provide private connectivity from your VPC to supported AWS services without traversing the public internet or a NAT Gateway. For example, you can use a gateway endpoint for S3 (and interface endpoints for other services where supported), which avoids NAT Gateway hourly and data-processing charges.
✗Attach Elastic IP addresses to instances in private subnetsWrong answer — click to see why▾
Why this is wrong here
Attaching Elastic IP addresses to instances in private subnets does not provide internet access because private subnets lack a route to an internet gateway; Elastic IPs require an internet gateway to be reachable.
★ When this WOULD be the correct answer
If the question required instances in a public subnet to have static public IP addresses for outbound internet access, attaching Elastic IPs would be correct, assuming an internet gateway is configured.
Why candidates choose this
Candidates may mistakenly think Elastic IPs directly enable internet access, overlooking that private subnets cannot route to the internet without a NAT gateway or internet gateway.
✗Install a NAT Gateway in every subnet to minimize routing hopsWrong answer — click to see why▾
Why this is wrong here
Installing a NAT Gateway in every subnet increases costs (each NAT Gateway incurs hourly and data processing charges) and does not reduce outbound networking costs as required by the question.
★ When this WOULD be the correct answer
A question where the requirement is to provide outbound internet access to instances in private subnets for general internet access (not just AWS services), and cost is not a primary concern. For example: 'A workload in private subnets needs to download patches from the internet. What is the most reliable solution?'
Why candidates choose this
Candidates may think that placing a NAT Gateway in each subnet reduces latency or routing hops, and they might overlook the cost implications, especially if they are focused on network performance rather than cost optimization.
✗Open outbound internet access with a security group rule to reach service endpoints directlyWrong answer — click to see why▾
Why this is wrong here
Security group rules control inbound and outbound traffic at the instance level, but they cannot provide direct private connectivity to AWS services like S3. Instances in private subnets without a NAT Gateway or VPC Endpoint cannot reach public service endpoints over the internet.
★ When this WOULD be the correct answer
If the question asked about allowing outbound internet access from instances in a public subnet to a specific IP range, and the goal was to restrict traffic at the instance level, then a security group rule would be appropriate. For example: 'A web server in a public subnet needs to access an external API; which security group configuration allows this?'
Why candidates choose this
Candidates may think that security groups can replace network infrastructure components like NAT Gateways or VPC Endpoints, misunderstanding that security groups only filter traffic but do not provide routing or private connectivity.
Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.