Question 435 of 1,040
Design Secure ArchitectureshardMultiple SelectObjective-mapped

SAA-C03 Interface VPC endpoints use AWS PrivateLink. Practice Question

This SAA-C03 practice question tests your understanding of design secure architectures. Match the stated requirement to the specific cloud service, access model, or configuration option — many options are valid in isolation but not for this scenario. A key principle to apply: interface VPC endpoints use AWS PrivateLink.. Once you have made your selection, read the full explanation to reinforce the concept and understand why each distractor is designed to mislead on exam day.

A private application in two private subnets must download objects from S3 and read parameters from Systems Manager Parameter Store without routing traffic through the public internet. Which two components should the architect use? The team wants the control to be enforceable during normal operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Interface VPC endpoint for Systems Manager

An Interface VPC endpoint (AWS PrivateLink) for Systems Manager allows the private subnets to securely access Systems Manager Parameter Store without traversing the internet, using private IP addresses within the VPC. This ensures traffic stays within the AWS network and is enforceable via VPC endpoint policies and security groups.

Key principle: Interface VPC endpoints use AWS PrivateLink.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Interface VPC endpoint for Systems Manager

    Why this is correct

    Systems Manager/Parameter Store access uses interface endpoints powered by AWS PrivateLink.

    Related concept

    Interface VPC endpoints use AWS PrivateLink.

  • Internet gateway attached to the VPC

    Why it's wrong here

    An internet gateway is not used by private subnets for private AWS service access.

  • NAT gateway in each Availability Zone

    Why it's wrong here

    A NAT gateway allows outbound internet access but does not keep traffic fully private.

  • Gateway VPC endpoint for Amazon S3

    Why this is correct

    A gateway endpoint provides private connectivity from a VPC to S3 without NAT or internet gateways.

    Related concept

    Interface VPC endpoints use AWS PrivateLink.

Common exam traps

Common exam trap: answer the scenario, not the keyword

AWS often tests the distinction between Interface VPC endpoints (for services like Systems Manager, API Gateway, and Kinesis) and Gateway VPC endpoints (for S3 and DynamoDB), and candidates mistakenly assume a NAT gateway or internet gateway is required for private subnets to access these services.

Detailed technical explanation

How to think about this question

Interface VPC endpoints use AWS PrivateLink to create an elastic network interface (ENI) in the subnet with a private IP, allowing traffic to AWS services via the AWS backbone. Gateway VPC endpoints for S3 use route table entries to direct S3 traffic through the AWS network without leaving the VPC, and they support endpoint policies for fine-grained access control. Both endpoint types are highly available within an Availability Zone and can be used together to meet the requirement without internet gateways or NAT gateways.

KKey Concepts to Remember

  • Interface VPC endpoints use AWS PrivateLink.
  • They provide private connectivity to many AWS services.
  • Traffic remains within the AWS network, not the public internet.
  • Interface endpoints appear as ENIs with private IPs in your subnets.

TExam Day Tips

  • Watch for words such as best, first, most likely and least administrative effort.
  • Review why wrong options are wrong, not only why the correct option is correct.

Key takeaway

Interface VPC endpoints use AWS PrivateLink.

Real-world example

How this comes up in practice

A media company stores terabytes of video archives that are accessed once a year for audit purposes. Moving these objects to a cold storage tier (Azure Archive, S3 Glacier, or Google Nearline) costs a fraction of hot storage. Questions like this test whether you understand storage tiers, access frequency tradeoffs, and retrieval latency requirements.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

What to study next

Got this wrong? Here's your next step.

Review interface VPC endpoints use AWS PrivateLink., then practise related SAA-C03 questions on the same topic to reinforce the concept.

Related practice questions

Related SAA-C03 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

Practice this exam

Start a free SAA-C03 practice session

Short sessions build daily habit. Longer sessions build exam-day stamina. Try a timed session to simulate real conditions.

FAQ

Questions learners often ask

What does this SAA-C03 question test?

Design Secure Architectures — This question tests Design Secure Architectures — Interface VPC endpoints use AWS PrivateLink..

What is the correct answer to this question?

The correct answer is: Interface VPC endpoint for Systems Manager — An Interface VPC endpoint (AWS PrivateLink) for Systems Manager allows the private subnets to securely access Systems Manager Parameter Store without traversing the internet, using private IP addresses within the VPC. This ensures traffic stays within the AWS network and is enforceable via VPC endpoint policies and security groups.

What should I do if I get this SAA-C03 question wrong?

Review interface VPC endpoints use AWS PrivateLink., then practise related SAA-C03 questions on the same topic to reinforce the concept.

What is the key concept behind this question?

Interface VPC endpoints use AWS PrivateLink.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Keep practising

More SAA-C03 practice questions

Last reviewed: Jun 30, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.