mediummulti selectObjective-mapped

An application runs in private subnets and must access Amazon S3, Amazon DynamoDB, and AWS Secrets Manager. The security team wants the traffic to stay on the AWS network and the finance team wants to eliminate NAT Gateway charges. Which three changes should they make? Select three.

Question 1mediummulti select
Full question →

An application runs in private subnets and must access Amazon S3, Amazon DynamoDB, and AWS Secrets Manager. The security team wants the traffic to stay on the AWS network and the finance team wants to eliminate NAT Gateway charges. Which three changes should they make? Select three.

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Best answer

Create gateway VPC endpoints for S3.

A gateway endpoint for S3 allows private access without sending traffic through a NAT Gateway. It keeps S3 traffic on the AWS network and reduces NAT processing charges.

B

Best answer

Create gateway VPC endpoints for DynamoDB.

DynamoDB also supports gateway endpoints, which remove the need for NAT when private subnets access the service. This directly lowers cost and keeps traffic private.

C

Best answer

Create an interface VPC endpoint for Secrets Manager.

Secrets Manager uses an interface endpoint for private connectivity from a VPC. This avoids internet egress and lets the workload reach the service without a NAT Gateway.

D

Distractor review

Place the instances in public subnets with an internet gateway.

Public subnets increase exposure and do not solve the cost goal in a better way. They also violate the requirement to keep traffic private where possible.

E

Distractor review

Keep the NAT Gateway and add a proxy instance for service access.

A proxy instance adds more management work and does not remove the NAT Gateway cost. It is a poor fit when AWS-native VPC endpoints can satisfy the requirement directly.

Common exam trap

Common exam trap: usable hosts are not the same as total addresses

Subnetting questions often tempt you into counting all addresses. In normal IPv4 subnets, the network and broadcast addresses are not usable host addresses.

Technical deep dive

How to think about this question

Subnetting questions test whether you can identify the network, broadcast address, usable range, mask and correct subnet. Slow down enough to calculate the block size correctly.

KKey Concepts to Remember

  • CIDR notation defines the prefix length.
  • Block size helps identify subnet boundaries.
  • Network and broadcast addresses are not usable hosts in normal IPv4 subnets.
  • The required host count determines the smallest suitable subnet.

TExam Day Tips

  • Write the block size before choosing the subnet.
  • Check whether the question asks for hosts, subnets or a specific address range.
  • Do not confuse /24, /25, /26 and /27 host counts.

Related practice questions

Related SAA-C03 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this SAA-C03 question test?

CIDR notation defines the prefix length.

What is the correct answer to this question?

The correct answer is: Create gateway VPC endpoints for S3. — The most cost-effective way to keep this private is to replace NAT-based access with VPC endpoints. S3 and DynamoDB use gateway endpoints, which are low-cost and route traffic privately. Secrets Manager requires an interface endpoint, which also keeps traffic within AWS networking. Together, these endpoints eliminate unnecessary NAT charges while preserving private connectivity for the application. Putting instances in public subnets increases exposure and is not needed. Keeping the NAT Gateway and adding a proxy still leaves the NAT cost in place and adds operational overhead. AWS-native endpoints are the cleaner and cheaper solution for the services in the scenario.

What should I do if I get this SAA-C03 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.