AWSSAA-C03VPCNetworkingSolutions Architect

AWS VPC & Networking Guide for SAA-C03 (2026)

Preporato TeamSeptember 4, 202614 min readSAA-C03
AWS VPC & Networking Guide for SAA-C03 (2026)

Networking is where SAA-C03 candidates most often lose points they thought were safe, because VPC questions are precise: a security group and a NACL sound interchangeable until a question hinges on one being stateful and the other not. Networking runs through the Security domain (30%) and the Resilience and Performance domains too, so getting the VPC model solid pays across the whole exam.

This guide covers the VPC building blocks and the connectivity decisions AWS tests. For the wider service map, see the domains breakdown; to study it in weight order, the 8-week plan puts networking in week 2.

Find out where you stand first

Take the free SAA-C03 sample questions cold (no signup, real exam style), then read on with your gaps in mind. When you are ready for full rehearsal, Preporato's SAA-C03 practice tests include 6 full-length exams (401 questions in total, domain-proportional, every answer explained) for a one-time $19.99 with lifetime access.

The VPC Building Blocks

A VPC is your private, isolated network in a Region, defined by a CIDR block (e.g. 10.0.0.0/16). Inside it:

  • Subnets carve the CIDR into ranges, each pinned to one Availability Zone. A subnet is public if its route table sends 0.0.0.0/0 to an internet gateway, private if it does not.
  • Route tables decide where traffic goes. The distinction between public and private is entirely about routing, not a checkbox.
  • Internet gateway (IGW) gives a VPC two-way internet access; attach one per VPC, route to it from public subnets.
  • NAT gateway lets instances in private subnets reach the internet outbound (updates, API calls) without being reachable inbound. It lives in a public subnet. For high availability, deploy one NAT gateway per AZ, because a NAT gateway is AZ-scoped and an AZ failure takes it down.

The canonical exam architecture: public subnets hold load balancers and NAT gateways; private subnets hold application servers and databases; the app reaches out through NAT, and users reach in through the load balancer.

Preparing for SAA-C03? Practice with 390+ exam questions

Security Groups vs NACLs: The Most-Tested Pair

This comparison appears on nearly every SAA-C03 exam. Memorize it cold:

Security Group vs Network ACL

PropertySecurity GroupNetwork ACL
Operates atInstance (ENI) levelSubnet level
StateStateful: return traffic auto-allowedStateless: return traffic needs its own rule
RulesAllow onlyAllow and Deny
EvaluationAll rules evaluatedRules processed in number order, first match wins
DefaultDeny all inbound, allow all outboundDefault NACL allows all; custom NACL denies all

The stateful/stateless distinction is where questions bite. A security group that allows inbound port 443 automatically allows the response out. A NACL does not: if you allow inbound 443, you must also allow outbound on the ephemeral port range (1024-65535) or the response is dropped. A scenario describing "connections succeed outbound but responses are blocked" is usually a NACL missing its ephemeral-range rule.

Use security groups as your primary control (simpler, stateful) and NACLs as a coarse subnet-level backstop, especially the ability to deny a specific IP, which security groups cannot do.

VPC Endpoints: Keeping Traffic Private

By default, an instance in a private subnet reaching S3 or DynamoDB routes through the NAT gateway and over the public AWS network. VPC endpoints keep that traffic inside AWS:

  • Gateway endpoints (S3 and DynamoDB only) add a route-table entry; free, and the frequent "reduce NAT cost / keep S3 traffic private" answer.
  • Interface endpoints (PrivateLink) put an ENI in your subnet for most other services; hourly and per-GB cost, but works for the long tail of services and for private connectivity to third-party SaaS.

A question about accessing S3 from a private subnet "without traversing the internet" and "at minimal cost" wants a Gateway endpoint.

Master These Concepts with Practice

Our SAA-C03 practice bundle includes:

  • 6 full practice exams (390+ questions)
  • Detailed explanations for every answer
  • Domain-by-domain performance tracking

30-day money-back guarantee

Connecting VPCs and On-Premises

Connectivity options

NeedOptionKey rule
Connect two VPCsVPC PeeringOne-to-one, non-transitive: A-B and B-C does not give A-C
Connect many VPCs at scaleTransit GatewayHub-and-spoke, transitive; the answer once peering becomes a mesh
On-prem over the internet, encryptedSite-to-Site VPNQuick, cheaper, but rides the public internet
On-prem, private and consistentDirect ConnectDedicated line: predictable latency, higher bandwidth, no internet
On-prem private + VPN failoverDirect Connect + VPN backupDX for primary, VPN as resilient fallback

Two exam favorites: peering is non-transitive (a mesh of many VPCs is the signal to switch to Transit Gateway), and Direct Connect is the answer when the stem stresses "consistent latency," "private," or "not over the internet," while VPN is the answer when it stresses "quick to set up" or "cost."

See it as a map

Networking clicks when it is spatial. Our SAA-C03 world map lays the VPC components out as connected territory, which many learners find easier to hold than a list.

Route 53 and Traffic Management

DNS is networking too, and Route 53 routing policies are tested directly:

  • Simple: one record, no logic.
  • Weighted: split traffic by percentage (A/B testing, gradual rollout).
  • Latency: send users to the lowest-latency Region.
  • Failover: primary with a health-checked secondary for HA.
  • Geolocation / geoproximity: route by user location or bias traffic toward a Region.

Pair "route users to the nearest Region for performance" with latency-based, and "automatically send traffic to a backup site if the primary fails" with failover plus health checks.

How This Shows Up on the Exam

  • Instances in a private subnet need OS updates but must not be internet-reachable. What provides outbound access? (NAT gateway in a public subnet; one per AZ for HA.)
  • Outbound connections work but responses are dropped at the subnet boundary. Likely cause? (A NACL missing the ephemeral-port outbound rule; NACLs are stateless.)
  • Access S3 from private subnets without the public internet, at lowest cost. (Gateway VPC endpoint.)
  • Three VPCs are peered A-B and B-C; A cannot reach C. Why, and what fixes it at scale? (Peering is non-transitive; use Transit Gateway.)

Key Takeaways

  • Public vs private subnet is purely a routing decision (does it route to an IGW)
  • NAT gateway = outbound-only for private subnets, AZ-scoped, one per AZ for HA
  • Security groups are stateful/allow-only/instance-level; NACLs are stateless/allow-deny/subnet-level
  • Gateway endpoints (S3, DynamoDB, free) keep traffic private and cut NAT cost
  • Peering is non-transitive; Transit Gateway is the many-VPC answer; Direct Connect for private, consistent on-prem links

Continue with the IAM and security guide for the rest of the 30% Security domain, and test yourself against the full domain in Preporato's SAA-C03 practice exams.


Sources:

Last updated: July 10, 2026

Ready to Pass the SAA-C03 Exam?

Join thousands who passed with Preporato practice tests

Instant access30-day guaranteeUpdated monthly
SAA-C03
6 Practice Exams
Detailed Explanations
Performance Analytics
Get Full Access - $19.99See what's included →

SAA-C03 · 6 practice exams

$19.99one-time

Get full access