SAA-C03 Design Cost-Optimized Architectures Practice Question
Exhibit
VPC: vpc-0a1b2c3d Private subnets: 10.0.10.0/24, 10.0.11.0/24 Route tables: 10.0.10.0/24 -> 0.0.0.0/0 -> nat-07fabc123 10.0.11.0/24 -> 0.0.0.0/0 -> nat-07fabc123 VPC Flow Logs (sample): 10.0.10.45 -> 52.216.23.11 ACCEPT 10.0.10.45 -> 54.239.28.85 ACCEPT 10.0.11.18 -> 52.94.76.21 ACCEPT Cost Explorer last 30 days: NATGateway-Hours: $31.20 NATGateway-Bytes: $614.80 App requirement: no internet access is needed; only AWS service access is required.
Based on the exhibit, your application runs entirely in private subnets and only needs to reach Amazon S3, Amazon DynamoDB, AWS Secrets Manager, and CloudWatch Logs. The monthly bill is dominated by NAT Gateway charges. Which change most directly reduces cost while preserving private connectivity to these AWS services?
⚠ Common exam trap
It's easy for candidates to assume all AWS services require the same type of VPC endpoint, leading them to either use only interface endpoints (costly) or keep the NAT Gateway as a safety net, missing the opportunity to use free gateway endpoints for S3 and DynamoDB.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create S3 and DynamoDB gateway endpoints, create interface endpoints for Secrets Manager and CloudWatch Logs, update route tables, and remove the NAT Gateway.
It replaces the costly NAT Gateway with free VPC Gateway Endpoints for S3 and DynamoDB, and uses AWS PrivateLink interface endpoints for Secrets Manager and CloudWatch Logs. This eliminates all internet-bound data transfer costs while keeping traffic entirely within the AWS network, directly addressing the cost concern without sacrificing private connectivity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Replace the NAT Gateway with an Internet Gateway and keep the current private subnet routes unchanged.
Why it's wrong here
An Internet Gateway (IGW) only works for instances with public IPv4 addresses; private instances have no public IP, so routing them to an IGW won't provide any outbound connectivity without also redesigning the subnet architecture and adding public IPs. That change would expose the private workload to the internet and does not reduce NAT costs; it also leaves the original problem of paying for internet-only egress to AWS services unsolved.
- ✗
Add a second NAT Gateway in another Availability Zone to reduce cross-AZ data transfer charges.
Why it's wrong here
A second NAT Gateway adds a second hourly charge and per-GB processing fee; it does not reduce cross-AZ data transfer because NAT Gateway is always deployed in a specific AZ and you must route to the gateway in that AZ. In fact, if you place the second NAT Gateway in a different AZ from your instances and send traffic across AZs to use it, you'll incur additional per-GB cross-AZ charges. This only improves availability, not cost, and it still doesn't remove the NAT charges for traffic to AWS services.
- ✗
Create only interface endpoints for all four services and keep the NAT Gateway for fallback.
Why it's wrong here
Creating interface endpoints for S3 and DynamoDB as well as Secrets Manager and CloudWatch Logs would work, but interface endpoints for S3/DynamoDB incur hourly and per-GB charges, whereas gateway endpoints for those two services are free and use prefix lists. Keeping the NAT Gateway as a fallback preserves the hourly NAT charge and the per-GB data processing fee even when no fallback traffic is flowing, so this hybrid design is more expensive than necessary. The correct pattern is gateway endpoints for S3/DynamoDB, interface endpoints for Secrets Manager/CloudWatch Logs, and deleting the NAT Gateway.
- ✓
Create S3 and DynamoDB gateway endpoints, create interface endpoints for Secrets Manager and CloudWatch Logs, update route tables, and remove the NAT Gateway.
Why this is correct
S3 and DynamoDB use gateway endpoints, which are the cost-effective private path for those services. Secrets Manager and CloudWatch Logs require interface endpoints for private access. Once these are in place, the NAT Gateway is no longer needed for this workload, eliminating the hourly and per-GB NAT charges while keeping traffic on the AWS network.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.