SAA-C03 Design Secure Architectures Practice Question
Exhibit
{
"subnet_route_table": [
{"destination": "10.0.0.0/16", "target": "local"},
{"destination": "0.0.0.0/0", "target": "-"}
],
"dns_test": {
"command": "nslookup secretsmanager.us-east-1.amazonaws.com",
"result": "Name: secretsmanager.us-east-1.amazonaws.com\nAddress: 54.239.28.82"
},
"application_log": [
"2026-04-18T12:10:04Z ERROR GetSecretValue timed out after 3000 ms",
"2026-04-18T12:10:04Z INFO calling https://secretsmanager.us-east-1.amazonaws.com"
]
}Based on the exhibit, an application runs in private subnets without a NAT gateway and must retrieve a secret from AWS Secrets Manager. Security requires the traffic to stay on the AWS network and not traverse the public internet. What is the best solution?
⚠ Common exam trap
Watch out — candidates often confuse gateway VPC endpoints (which work only for S3 and DynamoDB) with interface VPC endpoints (which are used for most other AWS services including Secrets Manager), leading them to incorrectly select option C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an interface VPC endpoint for Secrets Manager and enable private DNS for the endpoint.
An interface VPC endpoint for Secrets Manager allows the application in the private subnet to securely access Secrets Manager over the AWS network using private IP addresses, without needing a NAT gateway or internet gateway. Enabling private DNS ensures that the default Secrets Manager DNS name resolves to the endpoint's private IP addresses, keeping all traffic within the AWS backbone and satisfying the security requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add a NAT gateway to the private subnet route table and keep using the public Secrets Manager endpoint.
Why it's wrong here
A NAT gateway gives your private subnet outbound internet connectivity, so the application could reach the public Secrets Manager endpoint, but that path travels through the internet gateway and leaves the AWS private network. This exposes sensitive API traffic to the public path, incurs NAT gateway hourly and data-processing charges, and adds a single point of failure. It also requires a public IP for the NAT gateway and an internet gateway, which is less secure and more expensive than using a VPC endpoint.
- ✓
Create an interface VPC endpoint for Secrets Manager and enable private DNS for the endpoint.
Why this is correct
An interface VPC endpoint for Secrets Manager uses AWS PrivateLink to place an elastic network interface with a private IP directly into your subnet, making the service reachable without internet access. Enabling private DNS for the endpoint ensures the default Secrets Manager DNS name resolves to that private interface instead of the public endpoint, so your application code works unchanged. This keeps traffic entirely within the AWS network, avoids internet transit, and requires no NAT or internet gateway.
- ✗
Create a gateway VPC endpoint for Secrets Manager and point the route table to it.
Why it's wrong here
Gateway VPC endpoints are route-table-based and are only supported for Amazon S3 and DynamoDB; AWS Secrets Manager is not eligible. A gateway endpoint works by adding a prefix list to a route table, which does not apply to Secrets Manager because it is a Regional service exposed through an API. Pointing the route table to such an endpoint would not create any path to the Secrets Manager API, leaving the application without connectivity to retrieve secrets.
- ✗
Use VPC peering to connect the application subnet to another VPC that already has internet access.
Why it's wrong here
VPC peering connects two VPCs privately, but it does not let you use the peered VPC's internet gateway for egress because peering does not support transitive or shared internet access. Even if the peered VPC has full internet connectivity, your application subnet would still need its own NAT gateway or internet gateway to reach the public Secrets Manager endpoint. If the peered VPC instead contained an interface endpoint, you would need custom routing and additional components like a Network Load Balancer to make it usable, so this option is not a direct or simple solution.
Visual reference
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.