VPC as your network trust boundary
A Virtual Private Cloud (VPC) is a logically isolated network in a Region. SAA scenarios expect you to place workloads in private subnets, control north-south and east-west traffic, and reach AWS services without exposing data to the public internet.
Subnets and routing
- Public subnet — route table has
0.0.0.0/0→ Internet Gateway (IGW). - Private subnet — no direct IGW route; outbound via NAT Gateway (per-AZ HA) or NAT instance (legacy).
- Isolated subnet — no internet route at all (databases, internal services).
Place NAT gateways in public subnets; one per AZ for resilience.
Security groups vs NACLs
| Security group | Network ACL | |
|---|---|---|
| Level | ENI / instance | Subnet |
| State | Stateful — return traffic auto-allowed | Stateless — need explicit inbound & outbound rules |
| Default | Deny inbound, allow outbound | Allow all |
| Rules | Allow only | Allow + deny |
Exam tip: SGs are your primary micro-segmentation tool. NACLs are coarse subnet belt-and-suspenders (e.g. block IP ranges).
Private access to AWS APIs
- Gateway endpoints — S3 and DynamoDB; route table entry, no charge, stays on AWS network.
- Interface endpoints (PrivateLink) — ENI in subnet for most other services (EC2 API, SNS, etc.). Use private DNS so apps keep standard endpoints.
- Gateway Load Balancer — insert third-party appliances (IDS/IPS) in traffic path.
Prefer endpoints over NAT for S3/Dynamo to reduce cost and data exfiltration risk.
Hybrid connectivity
- Site-to-Site VPN — quick encrypted tunnel over internet to on-premises.
- AWS Direct Connect — dedicated private link; lower latency, consistent throughput; often paired with VPN for backup.
- Transit Gateway — hub connecting VPCs and on-prem; scales better than full mesh peering.
VPC peering vs PrivateLink
- Peering — private IP connectivity between two VPCs; non-transitive, CIDR must not overlap.
- PrivateLink (endpoint services) — consumer connects to provider service without peering entire networks; good for ISV SaaS patterns.
AWS Network Firewall
Managed stateful inspection for VPCs — domain lists, intrusion prevention, centralized egress control. Use when compliance requires deep packet inspection beyond SGs/NACLs.
Design pattern: three-tier web app
- ALB in public subnets.
- App tier in private subnets (SG: only ALB → app port).
- Database in isolated subnets (SG: only app tier → DB port).
- S3 access via gateway endpoint; patching via NAT or Systems Manager Session Manager (no inbound SSH).
Exam traps
- NACL deny does not override SG allow for stateful flows the same way — understand evaluation order at subnet vs ENI.
- NAT Gateway is AZ-specific; design multi-AZ NAT for HA.
- Interface endpoint needs security group on the endpoint ENI.
Official reference
SAA-C03 exam guide — secure network architectures.