VPC endpoints let resources in your VPC reach AWS services privately, without traffic ever crossing the public internet. The exam likes them for security-focused scenarios.
Gateway vs interface endpoints
Gateway endpoints are for S3 and DynamoDB — free, added as a route table entry. Interface endpoints (powered by PrivateLink) put an ENI in your subnet for most other services. Either way, traffic to the AWS service stays on the AWS network, not the internet — the answer whenever a question wants “private access to S3 without a NAT/internet gateway.”
Test yourself
Instances in a private subnet must access S3 without any traffic leaving the AWS network or using a NAT gateway. What do you use?
- An Internet Gateway
- A Gateway VPC endpoint for S3
- A public subnet
- A second NAT gateway
👉 Click to reveal the answer & explanation
Correct answer: B. A Gateway VPC endpoint for S3 routes traffic privately over the AWS network with no internet exposure and no NAT cost. An Internet Gateway (A) or public subnet (C) exposes traffic; another NAT (D) still routes over the internet and adds cost.
Related topics
Amazon VPC · Security groups vs NACLs · Amazon S3
Ready to pass the AWS Solutions Architect Associate (SAA-C03)?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026
Get the SAA-C03 Practice Exams →or try 25 free questions first