Courseiva

SAA-C03 Design Secure Architectures Practice Question

Exhibit

Private subnet route table rtb-priv:
- 10.0.0.0/16 local
- 0.0.0.0/0 -> nat-0a12bc34

Application logs:
2026-04-20T10:14:11Z ERROR could not reach https://secretsmanager.us-east-1.amazonaws.com:443
2026-04-20T10:14:11Z ERROR timeout after 30s while downloading s3://company-artifacts-builds

Finance note:
"NAT data processing charges increased 42% last month."

Based on the exhibit, a workload in private subnets must reach only Amazon S3 and AWS Secrets Manager. The team wants to eliminate internet exposure for those calls and reduce NAT gateway charges. What change should be made?

⚠ Common exam trap

Watch out — candidates often confuse Gateway Endpoints (for S3 and DynamoDB) with Interface Endpoints (for most other AWS services), and may incorrectly assume a single endpoint type works for all services, or that a NAT gateway is still required for private subnet traffic to AWS services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an S3 gateway endpoint and a Secrets Manager interface endpoint with private DNS, then remove NAT dependency for those service calls.

VPC Gateway Endpoints (for S3) and Interface Endpoints (for Secrets Manager) allow private subnet instances to access these services over the AWS network without traversing the internet or a NAT gateway. Enabling private DNS on the interface endpoint ensures that the default Secrets Manager DNS name resolves to the endpoint's private IP, eliminating the need for a NAT gateway for those calls and reducing costs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Move the instances into a public subnet and restrict inbound access with security groups.

    Why it's wrong here

    Moving the instances to public subnets directly contradicts the requirement that the workload remain in private subnets and would give them public IP addresses with an Internet Gateway route. Even if inbound security groups are locked down, outbound calls to AWS services would still egress through the public internet, and the instances would be exposed at the network layer to any allowed source. Security groups are stateful packet filters, not a substitute for a private network path; they cannot turn a public placement into a private one, and this change would fail compliance and security requirements.

    When this WOULD be correct

    This option would be correct if the requirement was to allow internet access for the workload while restricting inbound traffic, and the team was not concerned about eliminating internet exposure or NAT gateway charges.

  • ✗

    Add a NAT instance and disable the managed NAT gateway to lower cost.

    Why it's wrong here

    Swapping the managed NAT gateway for a NAT instance simply moves the same pattern to a self-managed EC2 instance. The NAT instance still relies on an Internet Gateway and an Elastic IP to perform source NAT, so outbound calls to S3 and Secrets Manager still traverse the public internet before reaching the service endpoints. Moreover, the NAT instance becomes a single point of failure and adds operational burden for patching and high availability, without addressing the core requirement of eliminating NAT dependency for AWS service API calls.

    When this WOULD be correct

    This option would be correct if the question asked to reduce NAT gateway costs while still allowing internet-bound traffic (not just AWS services) and the team is okay with managing a single EC2 instance for NAT. For example, a workload that needs to reach external APIs or databases on the internet.

  • ✓

    Create an S3 gateway endpoint and a Secrets Manager interface endpoint with private DNS, then remove NAT dependency for those service calls.

    Why this is correct

    S3 is best reached through a gateway VPC endpoint, while Secrets Manager requires an interface endpoint. With private DNS enabled, the application can resolve and reach those services without leaving AWS private networking. This removes the need for NAT traffic for those calls, cuts cost, and keeps service access off the public internet.

  • ✗

    Use VPC peering to a shared services VPC and route all AWS service traffic through that VPC.

    Why it's wrong here

    VPC peering only creates a layer-2/3 connection between two VPCs using the AWS network backbone; it does not magically attach private endpoints for AWS managed services. Any traffic in the shared services VPC that needs to hit S3 or Secrets Manager would still require a route through an Internet Gateway or NAT device, because peering does not alter the public nature of AWS service API endpoints. It also adds non-transitive routing complexity and does not provide the private connectivity or cost savings that VPC endpoints offer.

    When this WOULD be correct

    This option would be correct if the question required accessing services or resources hosted in a shared services VPC (e.g., a centralized proxy or inspection appliance) and the workload needed to route all traffic through that VPC for compliance or monitoring, while still using NAT or internet for AWS service calls.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.

✓Create an S3 gateway endpoint and a Secrets Manager interface endpoint with private DNS, then remove NAT dependency for those service calls.Correct answer▾

Why this is correct

S3 is best reached through a gateway VPC endpoint, while Secrets Manager requires an interface endpoint. With private DNS enabled, the application can resolve and reach those services without leaving AWS private networking. This removes the need for NAT traffic for those calls, cuts cost, and keeps service access off the public internet.

✗Move the instances into a public subnet and restrict inbound access with security groups.Wrong answer — click to see why▾

Why this is wrong here

Moving instances to a public subnet exposes them to the internet, violating the requirement to eliminate internet exposure for S3 and Secrets Manager calls. The goal is to use private connectivity, not public subnets.

★ When this WOULD be the correct answer

This option would be correct if the requirement was to allow internet access for the workload while restricting inbound traffic, and the team was not concerned about eliminating internet exposure or NAT gateway charges.

Why candidates choose this

Candidates may think that placing instances in a public subnet with restrictive security groups is a simple way to provide outbound internet access without a NAT gateway, overlooking the requirement to avoid internet exposure entirely.

✗Add a NAT instance and disable the managed NAT gateway to lower cost.Wrong answer — click to see why▾

Why this is wrong here

A NAT instance still requires an internet gateway for outbound traffic to AWS services, which does not eliminate internet exposure. The goal is to remove internet dependency entirely, which is achieved by using VPC endpoints instead.

★ When this WOULD be the correct answer

This option would be correct if the question asked to reduce NAT gateway costs while still allowing internet-bound traffic (not just AWS services) and the team is okay with managing a single EC2 instance for NAT. For example, a workload that needs to reach external APIs or databases on the internet.

Why candidates choose this

Candidates may think a NAT instance is a cheaper alternative to a managed NAT gateway, but they overlook that it still requires an internet gateway and does not address the requirement to eliminate internet exposure for AWS service calls.

✗Use VPC peering to a shared services VPC and route all AWS service traffic through that VPC.Wrong answer — click to see why▾

Why this is wrong here

VPC peering does not provide private connectivity to AWS services like S3 and Secrets Manager; it only connects VPCs. The workload would still need internet or VPC endpoints to reach those services, and routing through another VPC adds complexity without eliminating internet exposure or NAT costs.

★ When this WOULD be the correct answer

This option would be correct if the question required accessing services or resources hosted in a shared services VPC (e.g., a centralized proxy or inspection appliance) and the workload needed to route all traffic through that VPC for compliance or monitoring, while still using NAT or internet for AWS service calls.

Why candidates choose this

Candidates may think VPC peering can route traffic to AWS services via another VPC that has internet access, misunderstanding that VPC peering does not support transitive routing to AWS public endpoints.

Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.