SAA-C03 Design Secure Architectures Practice Question
An engineering team runs application servers in private subnets. The instances must download patches and software packages from Amazon S3, but the company does not want the traffic to traverse the internet or a NAT gateway. Which design should they use?
⚠ Common exam trap
Watch out — candidates often confuse Gateway VPC endpoints with Interface VPC endpoints, or mistakenly think that a security group rule alone can bypass the need for a routing path to the internet, when in fact routing decisions are made at the subnet route table level, not by security groups.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use an Amazon S3 gateway VPC endpoint in the route tables for the private subnets.
An S3 Gateway VPC endpoint allows instances in private subnets to access Amazon S3 without traversing the internet or a NAT gateway. The endpoint uses AWS’s internal network and is added to the route table of the private subnets, directing S3 traffic through the endpoint prefix list. This design meets the requirement of keeping traffic off the internet while providing secure, low-latency access to S3.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add an internet gateway to the VPC and route private subnet traffic through it.
Why it's wrong here
Adding an internet gateway (IGW) and routing private-subnet traffic through it would make the instances effectively public or at least give them direct internet egress, violating the requirement that they remain in private subnets. An IGW is used for bidirectional communication with the public internet, and it does not provide any private or encrypted path specifically to S3. While you could combine an IGW with a NAT device to allow outbound-only access, that adds cost and complexity and still sends traffic over the internet. The correct private-connectivity mechanism is a gateway VPC endpoint, which keeps S3 traffic within the AWS network without requiring an IGW or NAT.
When this WOULD be correct
If the requirement were to provide internet access to instances in private subnets (e.g., for general web downloads) and a NAT gateway was not allowed due to cost, but internet traffic was acceptable, then adding an internet gateway and routing private subnet traffic through it (with appropriate NAT) would be correct.
- ✓
Use an Amazon S3 gateway VPC endpoint in the route tables for the private subnets.
Why this is correct
A gateway VPC endpoint for S3 keeps traffic between the VPC and S3 on the AWS network without using the public internet or a NAT gateway. This is the standard private-connectivity pattern for S3 access from private subnets. It also simplifies the architecture and reduces NAT-related cost while preserving access to the bucket from workloads that must remain nonpublic.
- ✗
Use a security group rule that allows outbound traffic to the S3 public IP range.
Why it's wrong here
A security group rule permitting outbound traffic to the S3 public IP range only authorizes the traffic path; it does not establish a private, non-internet route. Security groups are stateful virtual firewalls that filter traffic at the instance level, but they have no effect on how packets are routed. Without a gateway VPC endpoint or NAT device, the instance's route table would still send S3-destined traffic to the internet gateway, defeating the private-subnet requirement. Moreover, S3 public IP ranges are shared and dynamic, making this approach both insecure and operationally brittle.
- ✗
Create a VPC peering connection to the S3 service VPC.
Why it's wrong here
VPC peering connects your VPC to another customer-controlled VPC over the AWS backbone; it cannot connect to a managed AWS service like S3 because S3 is not exposed as a peer VPC. Amazon S3 is a regional service with publicly routable endpoints, so there is no S3 service VPC available for peering. Peering also does not support transitive routing, and even if you attempted to reach S3 via a peered VPC, that VPC would still need an internet path or a gateway endpoint. This option is based on a fundamental misunderstanding of how AWS service connectivity works.
When this WOULD be correct
When connecting two separate VPCs (e.g., in different accounts or regions) to allow private IP communication between instances, such as for database replication or shared services, without using the internet or a VPN.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.
✓Use an Amazon S3 gateway VPC endpoint in the route tables for the private subnets.Correct answer▾
Why this is correct
A gateway VPC endpoint for S3 keeps traffic between the VPC and S3 on the AWS network without using the public internet or a NAT gateway. This is the standard private-connectivity pattern for S3 access from private subnets. It also simplifies the architecture and reduces NAT-related cost while preserving access to the bucket from workloads that must remain nonpublic.
✗Add an internet gateway to the VPC and route private subnet traffic through it.Wrong answer — click to see why▾
Why this is wrong here
An internet gateway allows traffic to the internet, but the company explicitly does not want traffic to traverse the internet or a NAT gateway. Using an internet gateway would route traffic over the internet, violating the requirement.
★ When this WOULD be the correct answer
If the requirement were to provide internet access to instances in private subnets (e.g., for general web downloads) and a NAT gateway was not allowed due to cost, but internet traffic was acceptable, then adding an internet gateway and routing private subnet traffic through it (with appropriate NAT) would be correct.
Why candidates choose this
Candidates may think an internet gateway is the standard way to provide outbound internet access, overlooking the specific constraint that traffic must not traverse the internet.
✗Create a VPC peering connection to the S3 service VPC.Wrong answer — click to see why▾
Why this is wrong here
VPC peering does not support transitive routing to AWS services like S3; S3 is not a VPC that can be peered with. Traffic would still need internet access or a gateway endpoint.
★ When this WOULD be the correct answer
When connecting two separate VPCs (e.g., in different accounts or regions) to allow private IP communication between instances, such as for database replication or shared services, without using the internet or a VPN.
Why candidates choose this
Candidates may think VPC peering provides direct private connectivity to any AWS service, misunderstanding that peering only connects VPCs, not service endpoints.
Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.