SAA-C03 Design Cost-Optimized Architectures Practice Question
An application runs on EC2 in us-east-1 and frequently reads objects from an S3 bucket that is physically located in us-west-2. The finance team reports unexpectedly high inter-Region data transfer charges because the application retrieves objects for many user requests. A constraint: the bucket in us-west-2 must remain the system of record for compliance, but the application can read from a replica in us-east-1.
What should the solutions architect do to minimize network spend while meeting the compliance constraint?
⚠ Common exam trap
Many exam-takers assume VPC endpoints or peering can eliminate inter-region costs, but S3 data transfer charges are based on the bucket's physical region, not the network path, so only replicating the data locally avoids the charges.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable S3 Cross-Region Replication from the us-west-2 source bucket to a destination bucket in us-east-1, and update the app to read from the us-east-1 bucket.
S3 Cross-Region Replication (CRR) automatically replicates objects from the source bucket in us-west-2 to a destination bucket in us-east-1, satisfying the compliance requirement that the us-west-2 bucket remains the system of record. By updating the application to read from the us-east-1 bucket, all read traffic stays within the same region, eliminating inter-region data transfer charges for object retrievals. This approach directly addresses the cost issue while preserving the original bucket as the authoritative source.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable S3 Cross-Region Replication from the us-west-2 source bucket to a destination bucket in us-east-1, and update the app to read from the us-east-1 bucket.
Why this is correct
S3 Cross-Region Replication (CRR) creates an asynchronous, automatic copy of every object in the us-west-2 source bucket to a destination bucket in us-east-1. By updating the application to read from the us-east-1 bucket, all GET requests stay within the same Region, eliminating inter-Region data transfer charges that currently accrue for each cross-Region read. Since CRR transfers each object once during replication (rather than on every read), this pattern becomes cost-effective when the application frequently reads the same large objects. You must still account for a short replication lag, so the app should tolerate eventual consistency for newly written objects.
- ✗
Create an interface VPC endpoint for S3 in us-east-1 and keep all object reads pointing to the us-west-2 bucket.
Why it's wrong here
An interface VPC endpoint for S3 in us-east-1 provides private connectivity to S3 via AWS PrivateLink, but it only works for S3 buckets in the same Region as the endpoint. If the bucket remains in us-west-2, requests from the us-east-1 EC2 instance must still cross the U.S. inter-Region network, incurring standard inter-Region data transfer fees. The endpoint removes the need for a NAT gateway or internet path, but it does not change the physical location of the data or the cost of moving bytes between Regions.
When this WOULD be correct
If the S3 bucket were in the same region as the VPC endpoint (e.g., both in us-east-1) and the goal were to avoid public internet exposure or reduce data transfer costs within a region, an interface VPC endpoint would be correct.
- ✗
Use VPC peering between two regions and route all requests to the us-west-2 bucket over the peering link.
Why it's wrong here
VPC peering connects two VPCs over the AWS global network, but it provides connectivity at the VPC/instance level, not for S3 endpoints. S3 is a regional managed service, and you cannot route its traffic through a VPC peering connection—S3 requests must still use either a public endpoint, a gateway endpoint, or an interface endpoint local to the Region. Even if you placed a VPC endpoint in the us-west-2 VPC and peered it, the inter-Region traffic between us-east-1 and us-west-2 would still be measured and billed by AWS as inter-Region data transfer, so peering adds complexity without addressing the cost driver.
When this WOULD be correct
If the application needs to access an S3 bucket in another region with lower latency and the data transfer costs are not a concern, or if the bucket is in the same region as the VPC (e.g., both in us-east-1), VPC peering could provide private connectivity without traversing the public internet.
- ✗
Use Route 53 latency-based routing to send users to a us-west-2 web endpoint and keep the S3 bucket unchanged.
Why it's wrong here
Route 53 latency-based routing controls how end users are directed to HTTP endpoints, so moving or adding a web endpoint in us-west-2 would affect only the client-facing tier. It does nothing to change the data path between the EC2 application in us-east-1 and the S3 bucket in us-west-2; the app's reads still traverse the inter-Region network and incur the same per-GB data transfer charges. If the goal is to reduce S3 read costs, you need to either move the application to the same Region as the bucket or copy the data to the application's Region—not redirect users.
When this WOULD be correct
This option would be correct if the application needed to minimize latency for global users accessing a web application hosted in multiple regions, and the S3 bucket was in the same region as the web endpoint, with no requirement to replicate data or reduce inter-Region transfer costs.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.
✓Enable S3 Cross-Region Replication from the us-west-2 source bucket to a destination bucket in us-east-1, and update the app to read from the us-east-1 bucket.Correct answer▾
Why this is correct
S3 Cross-Region Replication (CRR) creates an asynchronous, automatic copy of every object in the us-west-2 source bucket to a destination bucket in us-east-1. By updating the application to read from the us-east-1 bucket, all GET requests stay within the same Region, eliminating inter-Region data transfer charges that currently accrue for each cross-Region read. Since CRR transfers each object once during replication (rather than on every read), this pattern becomes cost-effective when the application frequently reads the same large objects. You must still account for a short replication lag, so the app should tolerate eventual consistency for newly written objects.
✗Create an interface VPC endpoint for S3 in us-east-1 and keep all object reads pointing to the us-west-2 bucket.Wrong answer — click to see why▾
Why this is wrong here
An interface VPC endpoint does not eliminate inter-region data transfer charges; traffic from the endpoint in us-east-1 to the bucket in us-west-2 still traverses the public internet or AWS backbone across regions, incurring costs.
★ When this WOULD be the correct answer
If the S3 bucket were in the same region as the VPC endpoint (e.g., both in us-east-1) and the goal were to avoid public internet exposure or reduce data transfer costs within a region, an interface VPC endpoint would be correct.
Why candidates choose this
Candidates may think that using a VPC endpoint privatizes all traffic and eliminates all data transfer costs, not realizing that inter-region traffic still incurs charges regardless of endpoint type.
✗Use VPC peering between two regions and route all requests to the us-west-2 bucket over the peering link.Wrong answer — click to see why▾
Why this is wrong here
VPC peering does not reduce inter-region data transfer charges because traffic between peered VPCs in different regions still incurs standard inter-region data transfer costs. Additionally, the application would still read from the us-west-2 bucket, not reducing costs.
★ When this WOULD be the correct answer
If the application needs to access an S3 bucket in another region with lower latency and the data transfer costs are not a concern, or if the bucket is in the same region as the VPC (e.g., both in us-east-1), VPC peering could provide private connectivity without traversing the public internet.
Why candidates choose this
Candidates may think VPC peering provides free or cheaper inter-region data transfer, but AWS charges for inter-region traffic even over peering. They might also confuse VPC peering with other connectivity options like Direct Connect or VPN.
✗Use Route 53 latency-based routing to send users to a us-west-2 web endpoint and keep the S3 bucket unchanged.Wrong answer — click to see why▾
Why this is wrong here
Route 53 latency-based routing directs user traffic to a web endpoint in us-west-2, but the application still reads from the S3 bucket in us-west-2, incurring inter-Region data transfer charges. It does not create a replica in us-east-1, so the compliance constraint of reading from a replica is not met.
★ When this WOULD be the correct answer
This option would be correct if the application needed to minimize latency for global users accessing a web application hosted in multiple regions, and the S3 bucket was in the same region as the web endpoint, with no requirement to replicate data or reduce inter-Region transfer costs.
Why candidates choose this
Candidates may think latency-based routing optimizes performance and reduces costs by directing users to the nearest endpoint, but they overlook that the S3 bucket remains in us-west-2, causing inter-Region charges when the application reads from it.
Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.