Skip to content
BytePatterns

SAA-C03 · Domain 4: Design Cost-Optimized Architectures · 20% of the exam

Task 4.4: Design cost-optimized network architectures.

Where network money goes: NAT gateways, data transfer between zones and Regions, VPC endpoints, edge caching, and Direct Connect versus VPN for hybrid links.

Study it

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 2

EC2 instances in private subnets send about 80 TB per month to Amazon S3 and 20 TB per month to Amazon DynamoDB in the same Region, all through a NAT gateway. The NAT gateway's data processing charges are the largest item on the network bill. Which changes reduce these costs the most? (Choose TWO.)

  1. AAdd a gateway VPC endpoint for Amazon S3 to the private route tables
  2. BCreate an interface VPC endpoint for Amazon S3 in each Availability Zone
  3. CMove the NAT gateway to a public subnet in another Availability Zone
  4. DAdd a gateway VPC endpoint for DynamoDB to the private route tables
  5. ETurn on S3 Transfer Acceleration for the buckets the instances use
Show the answer and why
  • AAdd a gateway VPC endpoint for Amazon S3 to the private route tables

    Correct

    Gateway endpoints reach S3 without a NAT device and carry no additional charge, so the S3 traffic leaves the NAT gateway's bill.

  • BCreate an interface VPC endpoint for Amazon S3 in each Availability Zone

    Incorrect

    It also bypasses the NAT gateway, but interface endpoints are charged per hour in each zone and per GB processed, unlike gateway endpoints.

  • CMove the NAT gateway to a public subnet in another Availability Zone

    Incorrect

    Sending traffic to a NAT gateway in another zone adds cross-zone data transfer charges on top of the processing charges.

  • DAdd a gateway VPC endpoint for DynamoDB to the private route tables

    Correct

    DynamoDB also supports gateway endpoints at no additional charge, so its traffic stops passing through the NAT gateway.

  • ETurn on S3 Transfer Acceleration for the buckets the instances use

    Incorrect

    Transfer Acceleration can add charges and the traffic would still go through the NAT gateway.

Traffic to S3 and DynamoDB does not need a NAT gateway at all. Gateway endpoints remove it from the NAT path at no extra charge.

Question 2 · choose 1

A development VPC has private subnets in two Availability Zones and light outbound internet traffic over IPv4. Each zone has its own NAT gateway today. The instances must stay unreachable from the internet, but losing outbound access during a zone outage is acceptable for this environment. Which change reduces cost?

  1. AReplace both NAT gateways with one egress-only internet gateway
  2. BRemove the NAT gateways and give each instance a public IPv4 address
  3. CReplace the NAT gateways with an interface VPC endpoint in each zone
  4. DKeep a single NAT gateway and route both private subnets through it
Show the answer and why
  • AReplace both NAT gateways with one egress-only internet gateway

    Incorrect

    An egress-only internet gateway carries IPv6 traffic only; outbound IPv4 traffic still needs a NAT gateway.

  • BRemove the NAT gateways and give each instance a public IPv4 address

    Incorrect

    Public IPv4 addresses make the instances directly reachable from the internet, which the requirement forbids, and each address is charged.

  • CReplace the NAT gateways with an interface VPC endpoint in each zone

    Incorrect

    Interface endpoints reach AWS services and endpoint services privately; they do not provide general internet access.

  • DKeep a single NAT gateway and route both private subnets through it

    Correct

    One shared NAT gateway halves the hourly charges. If its zone fails, the other zone loses internet access, which this environment accepts.

A NAT gateway per zone buys resilience. Where an outage is acceptable, a single shared NAT gateway costs less; light cross-zone traffic adds only a small charge.

Question 3 · choose 1

A company sends about 200 TB per month from AWS to its data center over a Site-to-Site VPN on the internet. Throughput varies with internet conditions, and data transfer out has become a large part of the bill. The company needs more consistent network performance and lower transfer costs. What should a solutions architect recommend?

  1. AAdd VPN connections on a transit gateway and spread traffic across them
  2. BSet up an AWS Direct Connect connection and move the traffic onto it
  3. CTurn on S3 Transfer Acceleration for the data the data center downloads
  4. DMove the VPN to a second internet provider with a faster connection
Show the answer and why
  • AAdd VPN connections on a transit gateway and spread traffic across them

    Incorrect

    More tunnels can add bandwidth, but traffic still crosses the internet, and VPN traffic incurs standard data transfer out charges.

  • BSet up an AWS Direct Connect connection and move the traffic onto it

    Correct

    Direct Connect gives a more consistent network experience than internet-based VPNs and reduces network costs, with its own data transfer out rates.

  • CTurn on S3 Transfer Acceleration for the data the data center downloads

    Incorrect

    Transfer Acceleration can add data transfer charges, and it applies only to S3 transfers over the internet.

  • DMove the VPN to a second internet provider with a faster connection

    Incorrect

    The traffic still crosses the public internet at standard data transfer out rates, so neither problem is solved.

Steady, high-volume hybrid traffic is the case for a dedicated Direct Connect link: steadier performance and lower transfer cost than the internet.

Question 4 · choose 1

A company serves software downloads of about 500 TB per month directly from an S3 bucket to anonymous users worldwide. Data transfer out from S3 to the internet is the largest item on its bill. Which change reduces this cost the MOST while keeping downloads fast?

  1. ATurn on S3 Transfer Acceleration for the bucket
  2. BServe the downloads through an Amazon CloudFront distribution with the bucket as its origin
  3. CTurn on Requester Pays for the bucket so that each user pays for their downloads
  4. DMove the objects to the S3 Standard-IA storage class
Show the answer and why
  • ATurn on S3 Transfer Acceleration for the bucket

    Incorrect

    Transfer Acceleration adds a per-GB fee on top of data transfer, so it raises the cost.

  • BServe the downloads through an Amazon CloudFront distribution with the bucket as its origin

    Correct

    Transfer from S3 to CloudFront is free, CloudFront's rates for delivery to the internet fall with volume, and caching at edge locations keeps downloads fast.

  • CTurn on Requester Pays for the bucket so that each user pays for their downloads

    Incorrect

    Requester Pays rejects anonymous requests, so the public downloads would stop working.

  • DMove the objects to the S3 Standard-IA storage class

    Incorrect

    The class lowers storage cost and adds retrieval fees. Data transfer out is charged the same.

Heavy public delivery from S3 belongs behind a CDN: origin fetches from S3 cost nothing and edge delivery is priced for volume.

Question 5 · choose 1

Two VPCs in the same Region exchange about 400 TB of data per month through a transit gateway. They have no other network connections, and the transit gateway's data processing charges have become significant. Which change reduces cost while keeping the traffic private?

  1. AReplace the transit gateway with a VPC peering connection between the two VPCs
  2. BSend the traffic through NAT gateways and public endpoints in each VPC instead
  3. CAdd a second transit gateway and split the traffic between the two
  4. DConnect the VPCs with Site-to-Site VPN connections over the internet
Show the answer and why
  • AReplace the transit gateway with a VPC peering connection between the two VPCs

    Correct

    There is no charge to create a peering connection and no data processing fee. Data that stays within an Availability Zone is free, and data that crosses zones pays only the data transfer rate.

  • BSend the traffic through NAT gateways and public endpoints in each VPC instead

    Incorrect

    NAT gateways add their own data processing charges, and the traffic would no longer stay private.

  • CAdd a second transit gateway and split the traffic between the two

    Incorrect

    Data processing is charged per GB on each transit gateway, so splitting the traffic does not lower the total.

  • DConnect the VPCs with Site-to-Site VPN connections over the internet

    Incorrect

    VPN connections add hourly and data transfer charges and send the traffic over the internet.

A transit gateway is worth its processing fee when it connects many networks. For two VPCs, peering is the cheaper private link.

Question 6 · choose 1

A company's NAT gateway data processing charges tripled last month. The network team must find which EC2 instances send the most traffic through the NAT gateway and to which destinations. Which solution should a solutions architect use?

  1. AAWS CloudTrail management events recorded for the VPC
  2. BAWS Cost Explorer, with the NAT gateway costs grouped by usage type
  3. CVPC Flow Logs for the NAT gateway's network interface, queried with CloudWatch Logs Insights
  4. DAWS Config rules that evaluate the NAT gateway's configuration
Show the answer and why
  • AAWS CloudTrail management events recorded for the VPC

    Incorrect

    CloudTrail records API calls such as creating a route. It records no network traffic.

  • BAWS Cost Explorer, with the NAT gateway costs grouped by usage type

    Incorrect

    Cost Explorer shows how much the NAT gateway cost and for which usage type, but not which instances or destinations caused it.

  • CVPC Flow Logs for the NAT gateway's network interface, queried with CloudWatch Logs Insights

    Correct

    Flow logs record the source, destination and bytes of each flow through the interface, and Logs Insights can sum the bytes by source and destination.

  • DAWS Config rules that evaluate the NAT gateway's configuration

    Incorrect

    Config records and evaluates resource configurations. It knows nothing about who sends traffic.

Finding top talkers is a traffic question, answered by flow logs, not by billing, API or configuration records.

Question 7 · choose 1

A company's apex domain and its www subdomain both point to an Application Load Balancer. The records are hosted in Amazon Route 53 and receive hundreds of millions of DNS queries per month. The company wants to keep Route 53 query charges as low as possible. Which record configuration should it use?

  1. ACNAME records for both names that point to the load balancer's DNS name
  2. BA records that list the load balancer's current IP addresses
  3. CWeighted CNAME records for both names, with a health check on each record
  4. DAlias records for both names that point to the load balancer
Show the answer and why
  • ACNAME records for both names that point to the load balancer's DNS name

    Incorrect

    Route 53 charges for CNAME queries, and a CNAME record cannot be created at the zone apex at all.

  • BA records that list the load balancer's current IP addresses

    Incorrect

    The load balancer's IP addresses change, so the records would break, and these queries are charged.

  • CWeighted CNAME records for both names, with a health check on each record

    Incorrect

    CNAME queries are charged, health checks add their own monthly fee, and a CNAME is still not allowed at the apex.

  • DAlias records for both names that point to the load balancer

    Correct

    Route 53 does not charge for alias queries to AWS resources such as a load balancer, and alias records work at the zone apex.

Alias records are the Route 53 way to point names at AWS resources: they work at the apex and their queries are free.

Question 8 · choose 2

A company needs a private connection from its data center to AWS for about 300 Mbps of steady traffic. It also needs a backup path, which may run over the internet with lower performance. The company wants the lowest cost that meets these needs. Which combination should a solutions architect recommend? (Choose TWO.)

  1. ATwo AWS Direct Connect dedicated connections of 10 Gbps each, at different locations
  2. BA single AWS Direct Connect dedicated connection of 100 Gbps
  3. CAWS Global Accelerator in front of the VPC as the backup path
  4. DAn AWS Direct Connect hosted connection of 500 Mbps from a Direct Connect Partner
  5. EAn AWS Site-to-Site VPN connection as the backup path
Show the answer and why
  • ATwo AWS Direct Connect dedicated connections of 10 Gbps each, at different locations

    Incorrect

    Two dedicated 10 Gbps ports give far more capacity and resilience than 300 Mbps with an internet backup needs, at a much higher price.

  • BA single AWS Direct Connect dedicated connection of 100 Gbps

    Incorrect

    A 100 Gbps port is hundreds of times the capacity needed, and it gives no backup path.

  • CAWS Global Accelerator in front of the VPC as the backup path

    Incorrect

    Global Accelerator routes internet users to AWS endpoints. It is not a connection between a data center network and a VPC.

  • DAn AWS Direct Connect hosted connection of 500 Mbps from a Direct Connect Partner

    Correct

    Hosted connections come in sizes from 50 Mbps upward, so a 500 Mbps connection covers the steady 300 Mbps without paying for a full dedicated port.

  • EAn AWS Site-to-Site VPN connection as the backup path

    Correct

    A VPN over the internet is a low-cost backup for Direct Connect when lower performance during a failure is acceptable.

Size the primary link to the traffic and match the backup to its requirements: a right-sized hosted connection plus a VPN backup.

Practise domain 4 →Practise all domains →