Courseiva

SAA-C03 Design Cost-Optimized Architectures Practice Question

Exhibit

VPC: vpc-0a1b2c3d
Private subnets: 10.0.10.0/24, 10.0.11.0/24
Route tables:
  10.0.10.0/24 -> 0.0.0.0/0 -> nat-07fabc123
  10.0.11.0/24 -> 0.0.0.0/0 -> nat-07fabc123
VPC Flow Logs (sample):
  10.0.10.45 -> 52.216.23.11 ACCEPT
  10.0.10.45 -> 54.239.28.85 ACCEPT
  10.0.11.18 -> 52.94.76.21 ACCEPT
Cost Explorer last 30 days:
  NATGateway-Hours: $31.20
  NATGateway-Bytes: $614.80
App requirement: no internet access is needed; only AWS service access is required.

Based on the exhibit, your application runs entirely in private subnets and only needs to reach Amazon S3, Amazon DynamoDB, AWS Secrets Manager, and CloudWatch Logs. The monthly bill is dominated by NAT Gateway charges. Which change most directly reduces cost while preserving private connectivity to these AWS services?

⚠ Common exam trap

It's easy for candidates to assume all AWS services require the same type of VPC endpoint, leading them to either use only interface endpoints (costly) or keep the NAT Gateway as a safety net, missing the opportunity to use free gateway endpoints for S3 and DynamoDB.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create S3 and DynamoDB gateway endpoints, create interface endpoints for Secrets Manager and CloudWatch Logs, update route tables, and remove the NAT Gateway.

It replaces the costly NAT Gateway with free VPC Gateway Endpoints for S3 and DynamoDB, and uses AWS PrivateLink interface endpoints for Secrets Manager and CloudWatch Logs. This eliminates all internet-bound data transfer costs while keeping traffic entirely within the AWS network, directly addressing the cost concern without sacrificing private connectivity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Replace the NAT Gateway with an Internet Gateway and keep the current private subnet routes unchanged.

    Why it's wrong here

    An Internet Gateway (IGW) only works for instances with public IPv4 addresses; private instances have no public IP, so routing them to an IGW won't provide any outbound connectivity without also redesigning the subnet architecture and adding public IPs. That change would expose the private workload to the internet and does not reduce NAT costs; it also leaves the original problem of paying for internet-only egress to AWS services unsolved.

  • ✗

    Add a second NAT Gateway in another Availability Zone to reduce cross-AZ data transfer charges.

    Why it's wrong here

    A second NAT Gateway adds a second hourly charge and per-GB processing fee; it does not reduce cross-AZ data transfer because NAT Gateway is always deployed in a specific AZ and you must route to the gateway in that AZ. In fact, if you place the second NAT Gateway in a different AZ from your instances and send traffic across AZs to use it, you'll incur additional per-GB cross-AZ charges. This only improves availability, not cost, and it still doesn't remove the NAT charges for traffic to AWS services.

  • ✗

    Create only interface endpoints for all four services and keep the NAT Gateway for fallback.

    Why it's wrong here

    Creating interface endpoints for S3 and DynamoDB as well as Secrets Manager and CloudWatch Logs would work, but interface endpoints for S3/DynamoDB incur hourly and per-GB charges, whereas gateway endpoints for those two services are free and use prefix lists. Keeping the NAT Gateway as a fallback preserves the hourly NAT charge and the per-GB data processing fee even when no fallback traffic is flowing, so this hybrid design is more expensive than necessary. The correct pattern is gateway endpoints for S3/DynamoDB, interface endpoints for Secrets Manager/CloudWatch Logs, and deleting the NAT Gateway.

  • ✓

    Create S3 and DynamoDB gateway endpoints, create interface endpoints for Secrets Manager and CloudWatch Logs, update route tables, and remove the NAT Gateway.

    Why this is correct

    S3 and DynamoDB use gateway endpoints, which are the cost-effective private path for those services. Secrets Manager and CloudWatch Logs require interface endpoints for private access. Once these are in place, the NAT Gateway is no longer needed for this workload, eliminating the hourly and per-GB NAT charges while keeping traffic on the AWS network.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.