SAA-C03 Design Secure Architectures Practice Question
You have EC2 instances in private subnets with no NAT gateway. They must retrieve secrets from AWS Secrets Manager without sending traffic to the public internet. Which VPC endpoint type is the correct choice for connecting to AWS Secrets Manager?
⚠ Common exam trap
Many exam-takers confuse Gateway endpoints (which are free and only for S3/DynamoDB) with Interface endpoints (which incur hourly charges but support many services like Secrets Manager, KMS, and CloudWatch).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an Interface VPC endpoint (AWS PrivateLink) for Secrets Manager and associate security groups for the endpoint.
AWS Secrets Manager is accessed via an API endpoint that uses HTTPS. Interface VPC endpoints (AWS PrivateLink) are the correct choice for connecting to services like Secrets Manager because they use elastic network interfaces (ENIs) with private IPs in your VPC, allowing traffic to stay within the AWS network. Gateway endpoints only support S3 and DynamoDB, not Secrets Manager.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a Gateway VPC endpoint for Secrets Manager.
Why it's wrong here
Gateway VPC endpoints operate by adding route table entries with prefix lists, and AWS only supports them for Amazon S3 and DynamoDB. Secrets Manager is not a service that offers a gateway endpoint; it uses an interface endpoint backed by AWS PrivateLink. Attempting to create a gateway endpoint for Secrets Manager is impossible, and it would not provide the private connectivity required to keep traffic off the public internet.
- ✓
Create an Interface VPC endpoint (AWS PrivateLink) for Secrets Manager and associate security groups for the endpoint.
Why this is correct
An interface VPC endpoint for Secrets Manager creates elastic network interfaces (ENIs) with private IPs inside your subnets, enabling direct, private access to the service over the AWS backbone. You can attach security groups to the endpoint to enforce inbound and outbound traffic controls, and endpoint policies further restrict which secrets or actions are allowed. This fully satisfies the requirement to avoid internet egress because no traffic leaves the AWS network.
- ✗
Use a Transit Gateway attachment to route traffic to the public internet for Secrets Manager.
Why it's wrong here
A Transit Gateway attachment is designed for interconnecting VPCs, VPN connections, and Direct Connect gateways; it does not, by itself, provide a path to Secrets Manager. To reach the public internet via Transit Gateway, you would still need an internet gateway, a NAT gateway, or a virtual appliance, which would force traffic through the public internet. That contradicts the requirement, and Transit Gateway offers no built-in private connectivity to Secrets Manager.
- ✗
Deploy a NAT gateway and allow outbound HTTPS traffic to Secrets Manager.
Why it's wrong here
Deploying a NAT gateway and allowing outbound HTTPS would route Secrets Manager traffic through the public internet, because a NAT gateway provides outbound-only internet access via the VPC's internet gateway. Although HTTPS encrypts the session, the traffic still traverses public infrastructure, violating the explicit need to avoid public internet egress. Moreover, a NAT gateway does not create a private connection to Secrets Manager; it only grants internet access, which is not the correct architectural solution.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.