Uni Cert / SAA-C03 / VPC security groups, NACLs, and endpoints

VPC security groups, NACLs, and endpoints

Network isolation, PrivateLink, and secure connectivity choices.

Estimated reading: ~30 min

VPC as your network trust boundary

A Virtual Private Cloud (VPC) is a logically isolated network in a Region. SAA scenarios expect you to place workloads in private subnets, control north-south and east-west traffic, and reach AWS services without exposing data to the public internet.

Subnets and routing

  • Public subnet — route table has 0.0.0.0/0 → Internet Gateway (IGW).
  • Private subnet — no direct IGW route; outbound via NAT Gateway (per-AZ HA) or NAT instance (legacy).
  • Isolated subnet — no internet route at all (databases, internal services).

Place NAT gateways in public subnets; one per AZ for resilience.

Security groups vs NACLs

Security groupNetwork ACL
LevelENI / instanceSubnet
StateStateful — return traffic auto-allowedStateless — need explicit inbound & outbound rules
DefaultDeny inbound, allow outboundAllow all
RulesAllow onlyAllow + deny

Exam tip: SGs are your primary micro-segmentation tool. NACLs are coarse subnet belt-and-suspenders (e.g. block IP ranges).

Private access to AWS APIs

  • Gateway endpoints — S3 and DynamoDB; route table entry, no charge, stays on AWS network.
  • Interface endpoints (PrivateLink) — ENI in subnet for most other services (EC2 API, SNS, etc.). Use private DNS so apps keep standard endpoints.
  • Gateway Load Balancer — insert third-party appliances (IDS/IPS) in traffic path.

Prefer endpoints over NAT for S3/Dynamo to reduce cost and data exfiltration risk.

Hybrid connectivity

  • Site-to-Site VPN — quick encrypted tunnel over internet to on-premises.
  • AWS Direct Connect — dedicated private link; lower latency, consistent throughput; often paired with VPN for backup.
  • Transit Gateway — hub connecting VPCs and on-prem; scales better than full mesh peering.

VPC peering vs PrivateLink

  • Peering — private IP connectivity between two VPCs; non-transitive, CIDR must not overlap.
  • PrivateLink (endpoint services) — consumer connects to provider service without peering entire networks; good for ISV SaaS patterns.

AWS Network Firewall

Managed stateful inspection for VPCs — domain lists, intrusion prevention, centralized egress control. Use when compliance requires deep packet inspection beyond SGs/NACLs.

Design pattern: three-tier web app

  1. ALB in public subnets.
  2. App tier in private subnets (SG: only ALB → app port).
  3. Database in isolated subnets (SG: only app tier → DB port).
  4. S3 access via gateway endpoint; patching via NAT or Systems Manager Session Manager (no inbound SSH).

Exam traps

  • NACL deny does not override SG allow for stateful flows the same way — understand evaluation order at subnet vs ENI.
  • NAT Gateway is AZ-specific; design multi-AZ NAT for HA.
  • Interface endpoint needs security group on the endpoint ENI.

Official reference

SAA-C03 exam guide — secure network architectures.

Official reference: AWS documentation

Chat with G.U.S.

Share suggestions to improve the site or any complaints. We use your feedback to make unigrat.com better.

Hi, I am G.U.S. — Growth Upgrade Suggestions.

Share your suggestions or complaints below.