Courseiva

SAA-C03 Design Cost-Optimized Architectures Practice Question

Your global users access static images stored in S3. Origin bandwidth costs are higher than expected because CloudFront is not caching effectively. What change most directly reduces origin fetches (and typically lowers data transfer costs) without changing application logic?

⚠ Common exam trap

Many candidates think disabling caching or bypassing CloudFront entirely will reduce costs, when in fact the opposite is true—effective caching is the key to reducing origin fetches and lowering data transfer costs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure CloudFront caching by setting appropriate cache-control headers and/or CloudFront cache policy/TTL values for the static objects

The high origin bandwidth costs are caused by CloudFront not caching effectively, meaning too many requests reach the S3 origin. By configuring appropriate Cache-Control headers or a CloudFront cache policy with optimal TTL values, you ensure that CloudFront caches the static images at edge locations for longer periods. This directly reduces the number of origin fetches, lowering data transfer costs without any changes to the application logic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure CloudFront caching by setting appropriate cache-control headers and/or CloudFront cache policy/TTL values for the static objects

    Why this is correct

    CloudFront reduces origin fetches when responses are cacheable and allowed to remain in the edge cache for a meaningful duration. Ensuring the objects include correct cache-control headers (or configuring CloudFront cache policy TTLs) increases cache hit rate, so fewer requests require fetching from S3 origin. This directly reduces origin bandwidth and related data transfer costs.

  • ✗

    Disable CloudFront caching so every request goes back to S3 for the latest image

    Why it's wrong here

    Setting TTLs to zero or otherwise disabling CloudFront caching forces every request to be treated as a cache miss and triggers a fetch to the S3 origin that hosts the static images. This re-introduces full origin load, multiplies S3 GET request costs, and removes the edge-side response that CloudFront could have reused, which also increases user-perceived latency especially for remote clients. It directly contradicts the goal of using a CDN, because the image objects are immutable static files that should be cached for high hit ratios.

    When this WOULD be correct

    A question asks for the most direct way to ensure users always see the latest version of an object without any delay, and cost is not a concern. Disabling caching would guarantee fresh content from S3 on every request.

  • ✗

    Route users directly to the S3 website endpoint to bypass CloudFront

    Why it's wrong here

    Bypassing CloudFront by sending users directly to the S3 website endpoint eliminates edge caching. All image requests then traverse to the bucket's origin region, causing higher latency for global users, and S3's standard request/transfer pricing applies for every object served. Unlike CloudFront, the S3 website endpoint is typically HTTP-only (unless you use the REST endpoint with custom SSL), and it lacks the ability to enforce cache-control headers at the CDN level, so it would not reduce the volume of data pulled from the origin.

  • ✗

    Turn on a NAT Gateway for the CloudFront origin to reduce bandwidth charges

    Why it's wrong here

    A NAT Gateway is unrelated to CloudFront or S3 origin access; it provides outbound internet connectivity for resources in private subnets of a VPC. CloudFront reaches S3 through AWS's internal network, and NAT Gateway does not sit in that data path, so it cannot influence cache hit ratio or origin fetch frequency. Moreover, NAT Gateway charges an hourly fee plus per-GB processing cost, so adding one would simply increase the bill without any benefit to image delivery.

    When this WOULD be correct

    In a scenario where an application in a private subnet needs to access an S3 bucket (or other internet resource) and you want to avoid using a public IP or an internet gateway, a NAT Gateway would be the correct solution to provide outbound internet access.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SAA-C03 exam frequently reuses these exact scenarios with slightly different constraints.

✓Configure CloudFront caching by setting appropriate cache-control headers and/or CloudFront cache policy/TTL values for the static objectsCorrect answer▾

Why this is correct

CloudFront reduces origin fetches when responses are cacheable and allowed to remain in the edge cache for a meaningful duration. Ensuring the objects include correct cache-control headers (or configuring CloudFront cache policy TTLs) increases cache hit rate, so fewer requests require fetching from S3 origin. This directly reduces origin bandwidth and related data transfer costs.

✗Disable CloudFront caching so every request goes back to S3 for the latest imageWrong answer — click to see why▾

Why this is wrong here

Disabling CloudFront caching forces every request to the S3 origin, increasing origin fetches and data transfer costs, which is the opposite of the goal to reduce them.

★ When this WOULD be the correct answer

A question asks for the most direct way to ensure users always see the latest version of an object without any delay, and cost is not a concern. Disabling caching would guarantee fresh content from S3 on every request.

Why candidates choose this

Candidates may think that disabling caching simplifies configuration or avoids stale content, but they overlook that caching is the primary mechanism to reduce origin load and costs.

✗Turn on a NAT Gateway for the CloudFront origin to reduce bandwidth chargesWrong answer — click to see why▾

Why this is wrong here

A NAT Gateway is used to enable private subnets to access the internet or other AWS services, not to reduce bandwidth charges for CloudFront origins. It does not affect CloudFront caching or origin fetch behavior.

★ When this WOULD be the correct answer

In a scenario where an application in a private subnet needs to access an S3 bucket (or other internet resource) and you want to avoid using a public IP or an internet gateway, a NAT Gateway would be the correct solution to provide outbound internet access.

Why candidates choose this

Candidates may mistakenly think that a NAT Gateway can reduce data transfer costs because it is associated with network address translation and cost management, but it does not apply to CloudFront-to-S3 data transfer.

Analysis generated from the official SAA-C03blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.