Courseiva
Design Secure ArchitecturesmediumMultiple ChoiceObjective-mapped

Resolve STS Connectivity from Private EC2: Create Interface VPC Endpoint

Your EC2 instances run in private subnets with no NAT gateway. The instances use the AWS SDK to call STS AssumeRole to obtain temporary credentials for other services. Application logs show errors like: "EndpointConnectionError: Could not connect to https://sts.<region>.amazonaws.com".

Which change most directly resolves this while keeping instances private?

Quick Answer

The correct fix is an interface VPC endpoint for STS because the failure is a pure connectivity problem: EC2 instances in private subnets with no NAT gateway have no path to the public internet, and STS is reached over a public endpoint by default. An interface endpoint uses AWS PrivateLink to place an elastic network interface for the service directly inside the VPC, so the SDK's call to the STS endpoint resolves to a private IP inside the subnet instead of a public one, and the security group on that interface just needs to allow HTTPS from the instances. This is different from how S3 or DynamoDB are typically reached, since those two services use gateway endpoints that work through route tables rather than an ENI-based interface, but for STS, and most other regional AWS APIs, the interface endpoint pattern is what applies. Adding a NAT gateway would also solve connectivity, but it routes traffic out to the internet and adds cost, and the question specifically asks for a solution that keeps the instances private without that path. Any time you see a private subnet with no NAT gateway failing to reach an AWS service endpoint by name, think interface VPC endpoint first, and remember that S3 and DynamoDB are the notable exceptions that use gateway endpoints instead.

⚠ Common exam trap

Watch out — candidates often confuse gateway endpoints (for S3/DynamoDB) with interface endpoints (for most other AWS services like STS), or they mistakenly think security group rules alone can enable internet access without a proper routing path.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create an interface VPC endpoint for STS (com.amazonaws.<region>.sts) and associate it with the instance subnets and a security group that allows HTTPS.

The error indicates that the EC2 instances in private subnets cannot reach the STS public endpoint over the internet because there is no NAT gateway or internet gateway attached to the private subnets. Creating an interface VPC endpoint for STS (com.amazonaws.<region>.sts) allows the instances to communicate with the STS API privately using AWS PrivateLink, without requiring internet access. Associating the endpoint with the instance subnets and a security group that allows HTTPS (port 443) ensures that traffic stays within the AWS network, resolving the connectivity error while keeping the instances private.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create an interface VPC endpoint for STS (com.amazonaws.<region>.sts) and associate it with the instance subnets and a security group that allows HTTPS.

    Why this is correct

    Interface endpoints provide private, in-VPC connectivity to AWS APIs like STS without requiring internet access or NAT.

  • Create a gateway VPC endpoint for S3 and route the STS traffic through the S3 endpoint gateway.

    Why it's wrong here

    Gateway endpoints are for specific services (like S3/DynamoDB) and cannot be used to route STS traffic to the correct API.

    When this WOULD be correct

    This option would be correct in a scenario where EC2 instances in a private subnet need to access S3 buckets without a NAT gateway or internet gateway, and the question asks for a solution to access S3 specifically.

  • Open an inbound rule in the instances’ security group to allow outbound HTTPS to the internet CIDR block directly.

    Why it's wrong here

    Security groups control allowed traffic, but the subnet route table still needs a path. Without NAT/endpoint routing, traffic cannot reach STS.

    When this WOULD be correct

    This would be correct if the instances were in a public subnet with an internet gateway, and the security group needed to allow outbound HTTPS traffic to the internet for STS calls.

  • Attach an Internet Gateway to the private subnet route table so the STS API can be reached over public internet.

    Why it's wrong here

    Adding an Internet Gateway to private subnets contradicts the requirement to keep instances private and increases exposure.

    When this WOULD be correct

    This option would be correct if the question required instances in a private subnet to access the internet (e.g., for software updates) and explicitly allowed making the subnet public, or if the subnet was already public and needed internet access for STS.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.

Create an interface VPC endpoint for STS (com.amazonaws.<region>.sts) and associate it with the instance subnets and a security group that allows HTTPS.Correct answer

Why this is correct

Interface endpoints provide private, in-VPC connectivity to AWS APIs like STS without requiring internet access or NAT.

Create a gateway VPC endpoint for S3 and route the STS traffic through the S3 endpoint gateway.Wrong answer — click to see why

Why this is wrong here

A gateway VPC endpoint only supports S3 and DynamoDB; it cannot route STS traffic, which requires an interface endpoint. STS uses HTTPS traffic that must be directed through an interface endpoint, not a gateway endpoint.

★ When this WOULD be the correct answer

This option would be correct in a scenario where EC2 instances in a private subnet need to access S3 buckets without a NAT gateway or internet gateway, and the question asks for a solution to access S3 specifically.

Why candidates choose this

Candidates may confuse gateway endpoints with interface endpoints, assuming all AWS services can be accessed via a gateway endpoint, or they may think routing STS traffic through an S3 endpoint is possible due to similar naming.

Open an inbound rule in the instances’ security group to allow outbound HTTPS to the internet CIDR block directly.Wrong answer — click to see why

Why this is wrong here

Opening an inbound rule for outbound HTTPS to the internet CIDR does not provide a route to the internet; the instances are in a private subnet with no NAT gateway, so outbound traffic cannot reach the internet.

★ When this WOULD be the correct answer

This would be correct if the instances were in a public subnet with an internet gateway, and the security group needed to allow outbound HTTPS traffic to the internet for STS calls.

Why candidates choose this

Candidates may think that allowing outbound HTTPS in the security group is sufficient to reach the STS endpoint, overlooking the missing route to the internet from a private subnet.

Attach an Internet Gateway to the private subnet route table so the STS API can be reached over public internet.Wrong answer — click to see why

Why this is wrong here

Attaching an Internet Gateway to the private subnet route table would make the subnet public, violating the requirement to keep instances private. The instances would have direct internet access, which is not allowed.

★ When this WOULD be the correct answer

This option would be correct if the question required instances in a private subnet to access the internet (e.g., for software updates) and explicitly allowed making the subnet public, or if the subnet was already public and needed internet access for STS.

Why candidates choose this

Candidates may think that an Internet Gateway is necessary for any outbound internet access, not realizing that private subnets should not have direct internet routes, and that VPC endpoints can provide private connectivity.

Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 302 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SAA-C03

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your EC2 instances run in private subnets with no NAT gateway. The instances use the AWS SDK to call STS AssumeRole to obtain temporary credentials for other services. Application logs show errors like: "EndpointConnectionError: Could not connect to https://sts.<region>.amazonaws.com". Which change most directly resolves this while keeping instances private?

medium
  • A.Create an interface VPC endpoint for STS (com.amazonaws.<region>.sts) and associate it with the instance subnets and a security group that allows HTTPS.
  • B.Create a gateway VPC endpoint for S3 and route the STS traffic through the S3 endpoint gateway.
  • C.Open an inbound rule in the instances’ security group to allow outbound HTTPS to the internet CIDR block directly.
  • D.Attach an Internet Gateway to the private subnet route table so the STS API can be reached over public internet.

Why A: The error indicates the EC2 instances cannot reach the STS public endpoint over the internet because they are in private subnets without a NAT gateway. An interface VPC endpoint for STS (com.amazonaws.<region>.sts) allows private, direct connectivity to the STS API using AWS PrivateLink, without requiring internet access. Associating the endpoint with the instance subnets and a security group that allows HTTPS (port 443) resolves the connectivity issue while keeping the instances private.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.