Silent budget killers
Domain 4 loves data transfer, wrong storage class, and over-provisioned IOPS. Security and resilience still matter — cheapest S3 One Zone-IA for sole backup copy is a bad trade even if cheap.
S3 cost optimization
Storage classes (cost vs access)
- Standard — frequent access.
- Intelligent-Tiering — auto moves tiers; small monitoring fee; great for unknown patterns.
- Standard-IA / One Zone-IA — infrequent; One Zone-IA cheaper, less resilient.
- Glacier Instant / Flexible / Deep Archive — archive; retrieval fees and time vary.
Lifecycle policies
- Transition to IA/Glacier after N days; expire old versions (versioned buckets accumulate cost).
- Abort incomplete multipart uploads after 7 days.
- S3 Lifecycle vs Intelligent-Tiering — lifecycle is rule-based schedule; IT is automatic access-based.
Request and transfer costs
- LIST and GET per-request charges matter at billions of small objects — use prefix design and S3 Inventory.
- Data transfer OUT to internet — charged; in to S3 free; same-Region to CloudFront origin optimized.
Exam: "Logs rarely accessed after 90 days" → lifecycle to Glacier or Intelligent-Tiering.
EBS cost tips
- Delete unattached volumes and old snapshots (Trusted Advisor flags these).
- gp3 often cheaper than gp2 at same performance — migrate.
- Don't over-provision io2 if gp3 IOPS sufficient.
- Snapshots incremental but full chain affects storage — lifecycle snapshots to archive tier (where supported).
RDS and Aurora cost
- Right-size instance — db.t3.micro dev vs db.r6g for prod.
- Reserved DB instances for steady production.
- Aurora Serverless v2 — pay for capacity used in variable workloads vs idle large instance.
- Stop dev RDS instances when not needed (limited stop duration for standard RDS).
- Storage autoscaling — convenience vs monitor growth.
Exam: variable dev DB → Aurora Serverless or stop/start schedule; not largest Multi-AZ prod instance.
Data transfer cheat sheet
| Path | Typical cost note |
|---|---|
| Internet → AWS | Usually free inbound |
| AWS → Internet | Charged (tiered by volume) |
| Cross-AZ same Region | Charged (~$0.01/GB each direction) |
| Cross-Region replication | Charged transfer + storage in dest |
| VPC endpoint to S3/DynamoDB | No NAT processing charge for that traffic |
| NAT Gateway | Hourly + per-GB processed — expensive at scale |
| CloudFront to users | CloudFront pricing; may reduce origin egress |
Exam patterns:
- "High NAT costs pulling from S3" → Gateway VPC endpoint for S3.
- "Replicate backups to another Region" → accept transfer cost for DR; use compression and lifecycle.
- "Users global, reduce egress" → CloudFront caches at edge.
Network design for cost
- Single NAT Gateway — cheap but AZ failure domain; NAT per AZ — HA but 2× hourly.
- VPC endpoints — reduce NAT GB processed for AWS service traffic.
- Direct Connect — not free but predictable; vs internet VPN for bulk hybrid transfer economics at scale.
DynamoDB cost
- On-demand vs provisioned — provisioned + auto scaling cheaper at predictable traffic.
- Standard-IA table class — cheaper storage, higher read cost for infrequent tables.
Balanced exam answer
When question says ** MOST cost-effective** with no HA caveat for dev:
- Spot, One Zone-IA, single NAT (dev), smaller Graviton instance.
When question says production or compliance:
- Don't sacrifice Multi-AZ, cross-Region backup, or encryption to save pennies.
Official reference
SAA-C03 exam guide — cost-optimized storage and database.