Question 435 of 1,040
Design Secure ArchitectureshardMultiple SelectObjective-mapped

Quick Answer

The correct answer is a Gateway VPC endpoint for Amazon S3 and an Interface VPC endpoint (AWS PrivateLink) for Systems Manager. This combination works because a Gateway endpoint provides a highly available, cost-free route to S3 via the VPC route table, while the Interface endpoint for Systems Manager uses an elastic network interface with a private IP to reach the Parameter Store—both keeping all traffic entirely within the AWS network and never crossing the public internet. On the SAA-C03 exam, this scenario tests your ability to distinguish between Gateway and Interface endpoints: Gateway endpoints are only for S3 and DynamoDB, whereas Interface endpoints (PrivateLink) are used for most other AWS services, including Systems Manager. A common trap is assuming both services need the same endpoint type; remember that S3 is the only major service that uses a Gateway endpoint. Memory tip: "S3 goes through the Gate, everything else through the Interface."

SAA-C03 Interface VPC endpoints use AWS PrivateLink. Practice Question

This SAA-C03 practice question tests your understanding of design secure architectures. Match the stated requirement to the specific cloud service, access model, or configuration option — many options are valid in isolation but not for this scenario. A key principle to apply: interface VPC endpoints use AWS PrivateLink.. Once you have made your selection, read the full explanation to reinforce the concept and understand why each distractor is designed to mislead on exam day.

A private application in two private subnets must download objects from S3 and read parameters from Systems Manager Parameter Store without routing traffic through the public internet. Which two components should the architect use? The team wants the control to be enforceable during normal operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Interface VPC endpoint for Systems Manager

An Interface VPC endpoint (AWS PrivateLink) for Systems Manager allows the private subnets to securely access Systems Manager Parameter Store without traversing the internet, using private IP addresses within the VPC. This ensures traffic stays within the AWS network and is enforceable via VPC endpoint policies and security groups.

Key principle: Interface VPC endpoints use AWS PrivateLink.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Interface VPC endpoint for Systems Manager

    Why this is correct

    Systems Manager/Parameter Store access uses interface endpoints powered by AWS PrivateLink.

    Related concept

    Interface VPC endpoints use AWS PrivateLink.

  • Internet gateway attached to the VPC

    Why it's wrong here

    An internet gateway is not used by private subnets for private AWS service access.

  • NAT gateway in each Availability Zone

    Why it's wrong here

    A NAT gateway allows outbound internet access but does not keep traffic fully private.

  • Gateway VPC endpoint for Amazon S3

    Why this is correct

    A gateway endpoint provides private connectivity from a VPC to S3 without NAT or internet gateways.

    Related concept

    Interface VPC endpoints use AWS PrivateLink.

Common exam traps

Common exam trap: answer the scenario, not the keyword

AWS often tests the distinction between Interface VPC endpoints (for services like Systems Manager, API Gateway, and Kinesis) and Gateway VPC endpoints (for S3 and DynamoDB), and candidates mistakenly assume a NAT gateway or internet gateway is required for private subnets to access these services.

Detailed technical explanation

How to think about this question

Interface VPC endpoints use AWS PrivateLink to create an elastic network interface (ENI) in the subnet with a private IP, allowing traffic to AWS services via the AWS backbone. Gateway VPC endpoints for S3 use route table entries to direct S3 traffic through the AWS network without leaving the VPC, and they support endpoint policies for fine-grained access control. Both endpoint types are highly available within an Availability Zone and can be used together to meet the requirement without internet gateways or NAT gateways.

KKey Concepts to Remember

  • Interface VPC endpoints use AWS PrivateLink.
  • They provide private connectivity to many AWS services.
  • Traffic remains within the AWS network, not the public internet.
  • Interface endpoints appear as ENIs with private IPs in your subnets.

TExam Day Tips

  • Watch for words such as best, first, most likely and least administrative effort.
  • Review why wrong options are wrong, not only why the correct option is correct.

Key takeaway

Interface VPC endpoints use AWS PrivateLink.

Real-world example

How this comes up in practice

A media company stores terabytes of video archives that are accessed once a year for audit purposes. Moving these objects to a cold storage tier (Azure Archive, S3 Glacier, or Google Nearline) costs a fraction of hot storage. Questions like this test whether you understand storage tiers, access frequency tradeoffs, and retrieval latency requirements.

What to study next

Got this wrong? Here's your next step.

Review interface VPC endpoints use AWS PrivateLink., then practise related SAA-C03 questions on the same topic to reinforce the concept.

Related practice questions

Related SAA-C03 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

Practice this exam

Start a free SAA-C03 practice session

Short sessions build daily habit. Longer sessions build exam-day stamina. Try a timed session to simulate real conditions.

FAQ

Questions learners often ask

What does this SAA-C03 question test?

Design Secure Architectures — This question tests Design Secure Architectures — Interface VPC endpoints use AWS PrivateLink..

What is the correct answer to this question?

The correct answer is: Interface VPC endpoint for Systems Manager — An Interface VPC endpoint (AWS PrivateLink) for Systems Manager allows the private subnets to securely access Systems Manager Parameter Store without traversing the internet, using private IP addresses within the VPC. This ensures traffic stays within the AWS network and is enforceable via VPC endpoint policies and security groups.

What should I do if I get this SAA-C03 question wrong?

Review interface VPC endpoints use AWS PrivateLink., then practise related SAA-C03 questions on the same topic to reinforce the concept.

What is the key concept behind this question?

Interface VPC endpoints use AWS PrivateLink.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on SAA-C03

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A private application in two private subnets must download objects from S3 and read parameters from Systems Manager Parameter Store without routing traffic through the public internet. Which two components should the architect use? The design must avoid adding custom operational scripts.

hard
  • A.Interface VPC endpoint for Systems Manager
  • B.Internet gateway attached to the VPC
  • C.NAT gateway in each Availability Zone
  • D.Gateway VPC endpoint for Amazon S3

Why A: An Interface VPC endpoint for Systems Manager (SSM) allows private subnets to communicate with AWS Systems Manager Parameter Store over the AWS network using private IP addresses, without traversing the internet. This endpoint uses AWS PrivateLink, enabling secure and private access to SSM APIs, which is required for reading parameters from Parameter Store.

Variation 2. A private application in two private subnets must download objects from S3 and read parameters from Systems Manager Parameter Store without routing traffic through the public internet. Which two components should the architect use? The security team requires the decision to be auditable.

hard
  • A.Interface VPC endpoint for Systems Manager
  • B.Internet gateway attached to the VPC
  • C.NAT gateway in each Availability Zone
  • D.Gateway VPC endpoint for Amazon S3

Why A: Interface VPC endpoints (AWS PrivateLink) allow private subnets to access Systems Manager Parameter Store without traversing the internet, using private IP addresses within the VPC. This meets the requirement for private, auditable access because all traffic stays within the AWS network and can be logged via VPC Flow Logs.

Variation 3. A private application in two private subnets must download objects from S3 and read parameters from Systems Manager Parameter Store without routing traffic through the public internet. Which two components should the architect use? The business wants to avoid a reactive-only remediation approach.

hard
  • A.Interface VPC endpoint for Systems Manager
  • B.Internet gateway attached to the VPC
  • C.NAT gateway in each Availability Zone
  • D.Gateway VPC endpoint for Amazon S3

Why A: An Interface VPC endpoint for Systems Manager (using AWS PrivateLink) allows the private application to securely read parameters from Parameter Store without traversing the internet. A Gateway VPC endpoint for S3 provides a private, highly available route to download objects from S3 using the S3 service's prefix list and route table entries, avoiding NAT or internet gateways. Together, these endpoints ensure all traffic stays within the AWS network, meeting the requirement to avoid public internet routing.

Keep practising

More SAA-C03 practice questions

Last reviewed: Jun 30, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.