SAA-C03 Design Secure Architectures Practice Question
Your company has an internal service hosted behind a Network Load Balancer (NLB) in VPC 10.0.0.0/16. A consumer team in a different VPC (10.1.0.0/16) must call the service without using the public internet. You want private connectivity using AWS PrivateLink. Which configuration best enables least-privilege access while keeping the traffic private?
⚠ Common exam trap
Test-takers frequently confuse Gateway Endpoints (which only work for S3 and DynamoDB) with Interface Endpoints (which support PrivateLink for services behind an NLB), leading them to pick Option C incorrectly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a VPC endpoint (interface endpoint) in the consumer VPC that points to the service name published by the provider account, and limit allowed clients using the endpoint’s security group rules.
AWS PrivateLink uses an interface VPC endpoint in the consumer VPC to connect privately to a Network Load Balancer (NLB) in the provider VPC, without traversing the public internet. The endpoint’s security group acts as a least-privilege firewall, allowing only specific clients (by source IP or security group) to access the service. This keeps traffic within the AWS network and avoids exposing the NLB to the internet.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Expose the NLB with an Internet Gateway route and restrict access using a security group attached to the NLB.
Why it's wrong here
Security groups cannot be attached directly to NLBs for this purpose in the way implied, and exposing the service via the public internet violates the private-only requirement. PrivateLink is designed for private connectivity without relying on public exposure.
When this WOULD be correct
If the question required public internet access to an Application Load Balancer (ALB) and asked for access restriction, an Internet Gateway with a security group attached to the ALB would be appropriate. For example: 'Allow external clients to access an ALB over the internet, but restrict access to a specific IP range.'
- ✓
Create a VPC endpoint (interface endpoint) in the consumer VPC that points to the service name published by the provider account, and limit allowed clients using the endpoint’s security group rules.
Why this is correct
PrivateLink uses an interface VPC endpoint in the consumer VPC (using the provider’s published service name). Traffic stays on the AWS network, not the public internet. Security groups on the interface endpoint provide least-privilege control over which client resources can reach the endpoint, and the provider side can also restrict who can connect.
- ✗
Create an S3 Gateway endpoint in the consumer VPC and store the service hostname in SSM Parameter Store so clients can resolve privately.
Why it's wrong here
An S3 Gateway endpoint is a route-based mechanism that grants private connectivity only to S3 and DynamoDB; it cannot reach an arbitrary internal service hosted behind a Network Load Balancer. Storing the service hostname in SSM Parameter Store merely lets clients look up a DNS name—it does not create any private network path, and the clients would still try to traverse the public internet or existing routes. PrivateLink requires an interface VPC endpoint, which is an elastic network interface with a private IP in the consumer VPC, not a gateway device. This option conflates centralised configuration with connectivity and selects the wrong endpoint type for the required AWS PrivateLink architecture.
When this WOULD be correct
This option would be correct if the question asked for private access to an S3 bucket from a consumer VPC, and the service hostname was stored in SSM Parameter Store for client configuration. For example: 'Your company needs to allow a consumer VPC to access an S3 bucket privately without using the internet.'
- ✗
Use a bastion host in the provider VPC and allow the consumer VPC to SSH to it; from there, the consumer makes HTTP calls to the NLB.
Why it's wrong here
A bastion host provides interactive SSH access for administrative tasks, not a scalable, least-privilege service endpoint; the consumer team would need to manage SSH keys and sessions, and the NLB’s traffic remains unexposed to PrivateLink’s VPC endpoint security groups. This option is tempting because bastion hosts are a common pattern for secure remote administration of private resources, and they would be correct if the consumer needed occasional SSH-based management of the provider’s instances rather than automated HTTP calls from another VPC.
When this WOULD be correct
A scenario where a consumer needs occasional, interactive access to a provider's internal resources (e.g., database administration) and the provider cannot expose a service via PrivateLink; a bastion host with strict security group rules and SSH key management would be appropriate.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.
✓Create a VPC endpoint (interface endpoint) in the consumer VPC that points to the service name published by the provider account, and limit allowed clients using the endpoint’s security group rules.Correct answer▾
Why this is correct
PrivateLink uses an interface VPC endpoint in the consumer VPC (using the provider’s published service name). Traffic stays on the AWS network, not the public internet. Security groups on the interface endpoint provide least-privilege control over which client resources can reach the endpoint, and the provider side can also restrict who can connect.
✗Expose the NLB with an Internet Gateway route and restrict access using a security group attached to the NLB.Wrong answer — click to see why▾
Why this is wrong here
NLBs do not support security groups; they rely on target group health checks and network ACLs. Additionally, routing through an Internet Gateway would expose the NLB to the public internet, violating the requirement for private connectivity.
★ When this WOULD be the correct answer
If the question required public internet access to an Application Load Balancer (ALB) and asked for access restriction, an Internet Gateway with a security group attached to the ALB would be appropriate. For example: 'Allow external clients to access an ALB over the internet, but restrict access to a specific IP range.'
Why candidates choose this
Candidates may mistakenly think security groups can be attached to any load balancer, and that an Internet Gateway is necessary for any cross-VPC communication, overlooking AWS PrivateLink as a private solution.
✗Create an S3 Gateway endpoint in the consumer VPC and store the service hostname in SSM Parameter Store so clients can resolve privately.Wrong answer — click to see why▾
Why this is wrong here
S3 Gateway endpoints only provide private access to S3 services, not to NLB-hosted services. They cannot route traffic to a Network Load Balancer or any non-S3 endpoint.
★ When this WOULD be the correct answer
This option would be correct if the question asked for private access to an S3 bucket from a consumer VPC, and the service hostname was stored in SSM Parameter Store for client configuration. For example: 'Your company needs to allow a consumer VPC to access an S3 bucket privately without using the internet.'
Why candidates choose this
Candidates may confuse 'Gateway Endpoint' with 'Interface Endpoint' or think that any VPC endpoint can provide private connectivity to any service, not realizing S3 Gateway endpoints are service-specific.
✗Use a bastion host in the provider VPC and allow the consumer VPC to SSH to it; from there, the consumer makes HTTP calls to the NLB.Wrong answer — click to see why▾
Why this is wrong here
Using a bastion host requires SSH access and does not provide private connectivity via AWS PrivateLink; it introduces a single point of failure, management overhead, and violates the least-privilege principle by granting broad network access.
★ When this WOULD be the correct answer
A scenario where a consumer needs occasional, interactive access to a provider's internal resources (e.g., database administration) and the provider cannot expose a service via PrivateLink; a bastion host with strict security group rules and SSH key management would be appropriate.
Why candidates choose this
Candidates may think a bastion host is a standard pattern for cross-VPC access and overlook that PrivateLink offers a more secure, managed, and scalable solution without requiring SSH or a jump box.
Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.