SAA-C03
Amazon VPC for the AWS Exams: Networking Without the Headache (2026)
Sep 25, 2026
A VPC is your own private slice of the AWS network. You draw the boundaries (the IP range), carve it into subnets, decide what’s allowed in and out, and connect the pieces to the internet — or deliberately don’t. On the architect exam, VPC is a whole section and where a lot of people lose points.
Get these four straight
An Internet Gateway is the door to the public internet, both ways. A NAT Gateway is a one-way door: private servers reach out but nobody reaches in. A security group is a stateful firewall around an instance. A network ACL is a stateless firewall around a subnet.
Test yourself
Instances in a private subnet must download OS patches from the internet but must NOT be reachable from the internet. What should you deploy?
- An Internet Gateway in the private subnet
- A NAT Gateway in a public subnet, with a route from the private subnet
- A public IP on each instance
- VPC peering
👉 Click to reveal the answer & explanation
Correct answer: B. A NAT Gateway gives private instances outbound-only internet access. An Internet Gateway (A) or public IPs (C) would make them reachable from the internet — exactly what’s forbidden. Peering (D) connects VPCs, not the internet.
Related topics
Security groups vs NACLs · Amazon Route 53 · Elastic Load Balancing
Ready to pass the AWS Solutions Architect Associate (SAA-C03)?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026
Get the SAA-C03 Practice Exams →or try 25 free questions first
