Courseiva

SAA-C03 Design Secure Architectures Practice Question

Exhibit

VPC configuration:
- Subnet-Private-A route table: local 10.0.0.0/16 only
- Subnet-Private-B route table: local 10.0.0.0/16 only
- No 0.0.0.0/0 route to an Internet Gateway or NAT Gateway

Existing endpoints:
- com.amazonaws.us-east-1.s3 (Gateway endpoint)

Application log:
ERROR: Unable to retrieve secret arn:aws:secretsmanager:us-east-1:111122223333:secret:prod/api/db
ERROR: connect timeout to secretsmanager.us-east-1.amazonaws.com
ERROR: KMS Decrypt access not completed

Based on the exhibit, an EC2 application runs in private subnets with no NAT gateway and must retrieve a secret from AWS Secrets Manager. The secret uses a customer managed KMS key. Which change will allow the application to reach the service while keeping traffic off the internet?

⚠ Common exam trap

A common mix-up: candidates assume a single endpoint type (like a gateway endpoint) can serve all AWS services, but Secrets Manager and KMS specifically require interface endpoints, and forgetting the KMS endpoint is a common oversight.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an interface VPC endpoint for Secrets Manager and another interface VPC endpoint for KMS, and enable private DNS for both.

It creates interface VPC endpoints for both Secrets Manager and KMS, which allows the EC2 instance in the private subnet to securely access these services over the AWS network without traversing the internet. Enabling private DNS ensures that the standard service endpoints resolve to the private IP addresses of the VPC endpoints, eliminating the need for a NAT gateway or internet gateway.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an interface VPC endpoint for Secrets Manager and another interface VPC endpoint for KMS, and enable private DNS for both.

    Why this is correct

    Secrets Manager is an interface endpoint service, and the customer managed KMS key means the application also needs private access to KMS for decrypt operations. Private DNS lets the SDK resolve standard service names to the VPC endpoints, keeping all traffic inside AWS private networking.

  • ✗

    Create an S3 gateway endpoint for Secrets Manager and use the existing S3 gateway endpoint for both secret retrieval and KMS decryption.

    Why it's wrong here

    Gateway endpoints are not used for Secrets Manager or KMS. They are specifically for supported services such as S3 and DynamoDB. The existing S3 endpoint does not provide network path or name resolution for the secret or decrypt operations.

  • ✗

    Add a NAT gateway in a public subnet and route 0.0.0.0/0 from the private subnets to the NAT gateway.

    Why it's wrong here

    A NAT gateway would allow outbound internet access, but the requirement says to keep traffic off the internet. It would also introduce additional cost and does not meet the private connectivity constraint. AWS PrivateLink endpoints are the correct design.

  • ✗

    Move the application into a public subnet so it can call the public Secrets Manager endpoint directly.

    Why it's wrong here

    Moving the application into a public subnet still uses the public Secrets Manager endpoint, which requires an internet path and exposes the workload to a broader network attack surface. This directly contradicts the stated requirement to keep all traffic within AWS private networking and avoid internet egress. It also does nothing to address the need for private access to the customer-managed KMS key for decryption, so the application would still need a way to reach KMS securely. Proper architecture uses interface VPC endpoints with private DNS to keep both Secrets Manager and KMS traffic fully inside the AWS backbone.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.