AWS Training
Modules Listen All tracks

← Design Cost-Optimized Architectures

Starts this lesson and continues through 3 more to the end of certification prep.

Network cost — which bytes you pay for, and the routes that avoid them

Why this lesson closes the module

Task statement 4.4 is "Design cost-optimized network architectures", and its skills are the most concrete in the domain. Verbatim:

The distinguishing question is: which direction is the byte going, and what does it pass through on the way? Every network cost answer is about removing a charged hop.

The data transfer rules

From the pages below, fetched 2026-09-25 and checked against the raw page text. The EC2 page's "Data Transfer within the same AWS Region" section is the most useful single source; its internet-egress rate table is filled in client-side and I don't quote it.

Direction Rule Source
Internet → AWS "There's no charge for data transfer from the internet to AWS." CUR data transfer guide
AWS → internet charged; "100 GB of free data transfer out to the internet free each month, aggregated across all AWS Services and Regions (except China and GovCloud)" EC2 pricing
Between AZs (same Region) "Data transferred "in" to and "out" from Amazon EC2, Amazon RDS, Amazon Redshift, Amazon DynamoDB Accelerator (DAX), Amazon ElastiCache instances, and Elastic Network Interfaces across Availability Zones in the same AWS Region is charged at $0.01/GB in each direction." EC2 pricing
Same AZ "Data transferred between Amazon EC2, Amazon RDS, Amazon Redshift, Amazon ElastiCache instances, and Elastic Network Interfaces in the same Availability Zone is free." EC2 pricing
EC2 ↔ S3, DynamoDB, SQS, SNS, Kinesis, ECR… same Region "Data transferred directly … between Amazon S3, … Amazon DynamoDB, Amazon SES, Amazon SQS, Amazon Kinesis, Amazon ECR, Amazon SNS or Amazon SimpleDB and Amazon EC2 instances in the same AWS Region is free." EC2 pricing
…but a service in the path "If other AWS services are in the path of your data transfer, you will be charged their associated data processing costs. These services include, but are not limited to, PrivateLink endpoints, NAT Gateway and Transit Gateway." EC2 pricing
Between Regions "There's no charge for the data transferred into the destination Region. The data transfer charge is determined by the data transferred out from the source Region." CUR data transfer guide
S3 → any AWS service, same Region no charge S3 pricing
S3 → CloudFront no charge S3 pricing
AWS origin → CloudFront "Data transfer between CloudFront and your AWS origins is automatically waived" CloudFront pricing
VPC peering, same AZ "All data transfer over a VPC peering connection that stays within an Availability Zone is free." multi-VPC whitepaper
VPC peering, cross-AZ "charged at the standard in-region data transfer rates"; the VPC pricing page: "charged at $0.01/GB in both "In" and "Out" direction" whitepaper; VPC pricing
Direct Connect in "data transferred into AWS over AWS Direct Connect is $0.00 per GB in all locations" Direct Connect pricing

That last row is the whole NAT-gateway story in one sentence: EC2 → S3 in the same Region is free, until a NAT gateway sits in the path and charges data processing on every byte.

The cost-shaped design rules that follow:

   bytes IN from the internet          free       → ingest is cheap
   bytes OUT to the internet           charged    → put CloudFront in front (origin fetch waived)
   bytes between AZs                   charged ×2 → keep chatty tiers in one AZ where resilience allows
   bytes between Regions               charged    → replicate only what you must
   S3 ↔ same-Region service            free       → but a NAT gateway in the path is not (below)

⚠️ Resilience costs transfer. Multi-AZ designs from SAA2 send traffic across AZs, and that traffic is charged. The exam's answer is almost never "collapse to one AZ to save money" for production — the skill is "Determining the required availability for different classes of workloads". Non-production, yes; production, no.

NAT gateway vs NAT instance

From Compare NAT gateways and NAT instances, fetched 2026-09-25 — the knowledge item is literally "NAT instance costs compared with NAT gateway costs":

NAT gateway NAT instance
Cost basis "the number of NAT gateways you use, duration of usage, and amount of data that you send through" "the number of NAT instances that you use, duration of usage, and instance type and size"
Availability "Highly available. NAT gateways in each Availability Zone are implemented with redundancy." "Use a script to manage failover between instances."
Bandwidth "Scale up to 100 Gbps." "Depends on the bandwidth of the instance type."
Maintenance "Managed by AWS." "Managed by you" — patching, updates
Security groups can't associate can associate
Port forwarding / bastion not supported supported

AWS's recommendation, verbatim: "We recommend that you use NAT gateways because they provide better availability and bandwidth and require less effort on your part to administer."

The cost trade in one line: a NAT gateway charges per GB processed on top of hourly; a NAT instance charges only for the instance, but you run it, patch it, and script its failover. At high volume the per-GB charge dominates; at tiny volume in a dev account, a small NAT instance can be cheaper. The exam's default answer for production is still the NAT gateway, on operational overhead.

Prices — from the US East (Ohio) worked example on Amazon VPC pricing, fetched 2026-09-25: "For this region, the rate is $0.045 per hour", and 1 GB through the gateway "will result in a charge of $0.045". "Data processing charges apply for each gigabyte processed through the NAT gateway regardless of the traffic's source or destination", and "You also incur standard AWS data transfer charges". The same example ends with the fix: "To avoid the NAT Gateway Data Processing charge in this example, you could set up a gateway Type VPC endpoint."

One NAT gateway, or one per AZ?

From Pricing for NAT gateways, fetched 2026-09-25:

"If your AWS resources send or receive a significant volume of traffic across Availability Zones, ensure that the resources are in the same Availability Zone as the NAT gateway. Alternatively, create a NAT gateway in each Availability Zone with resources."

And the comparison page: "Create a NAT gateway in each Availability Zone to ensure zone-independent architecture."

Single shared NAT gateway NAT gateway per AZ
Hourly charges one one per AZ
Cross-AZ transfer traffic from other AZs crosses AZs to reach it none — each AZ uses its own
AZ failure lose the NAT AZ → every private subnet loses outbound zone-independent
Fits dev/test, low traffic production, or high traffic

⚠️ The VPC pricing page also describes a Regional NAT Gateway: "you are charged for each hour that the NAT Gateway is configured in each availability zone" — its Ohio example bills three AZs as three NAT Gateway-hours. SAA2 flagged regional NAT gateways as unverified and I did not fetch the user-guide page for them, so this lesson doesn't teach their behaviour. Read docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html.

VPC endpoints — take S3 and DynamoDB traffic off the NAT

From Gateway endpoints, fetched 2026-09-25:

"Gateway VPC endpoints provide reliable connectivity to Amazon S3 and DynamoDB without requiring an internet gateway or a NAT device for your VPC."

"There is no additional charge for using gateway endpoints."

The VPC pricing page agrees: "There are no data processing or hourly charges for using Gateway Type VPC endpoints."

This is the highest-yield network cost fact on the exam. A private-subnet workload reading from S3 through a NAT gateway pays NAT per-GB processing on every byte. Add an S3 gateway endpoint and that traffic routes to the endpoint instead — free.

How it works: "Each subnet route table must have a route that sends traffic destined for the service to the gateway endpoint using the prefix list for the service." And by longest-prefix match, "the endpoint route takes precedence for traffic destined for the service … in the current Region."

⚠️ Limits that decide questions:

The NAT pricing page itself recommends the move: "If most traffic through your NAT gateway is to AWS services that support interface endpoints or gateway endpoints, consider creating an interface endpoint or gateway endpoint for these services."

⚠️ Interface endpoints are not free. The VPC pricing page lists them separately and I did not capture their rates. They can still be cheaper than NAT for heavy traffic to one service — check aws.amazon.com/privatelink/pricing/ before claiming it.

Connecting VPCs — peering vs Transit Gateway

From the multi-VPC whitepaper, VPC peering section, fetched 2026-09-25:

"VPC peering offers the lowest overall cost and highest aggregate performance when compared to other options for inter-VPC connectivity."

"VPC peering is best used when … the number of VPCs to be connected is less than 10."

But it doesn't scale: "if you have 100 VPCs and you want to setup a full mesh peering between them, it will take 4,950 peering connections [n(n-1)/2]", against "a maximum limit of 125 active peering connections per VPC". And it's not transitive — from the peering guide: "you can't route traffic from VPC B to VPC C through VPC A." Nor can a peered VPC borrow another's internet gateway, NAT, VPN, Direct Connect, or gateway endpoint.

Transit Gateway, from Transit Gateway pricing, fetched 2026-09-25 — figures from the page's US East (Ohio) worked example:

VPC peering Transit Gateway
Topology point-to-point, no transitive routing hub-and-spoke
Per-GB processing none — only data transfer (free same-AZ) $0.02/GB (Ohio) + transfer
Hourly none stated per attachment
Sweet spot < 10 VPCs, high volume between a few many VPCs, shared VPN/DX, central routing

Exam signal: "two VPCs, heavy traffic, lowest cost" → peering. "Forty VPCs across accounts, plus on-premises, simple routing" → Transit Gateway, accepting the per-GB charge for operational sanity. "Connect one VPN to many VPCs" — the VPN quotas page recommends it: "To connect the same Site-to-Site VPN connection to multiple VPCs, we recommend that you explore using a transit gateway."

On-premises connectivity — Direct Connect vs VPN vs internet

Site-to-Site VPN, from VPN pricing and VPN quotas, fetched 2026-09-25:

That last line is the answer to the skill "a single VPN compared with multiple VPNs": multiple VPN connections on a Transit Gateway, dynamic routing, ECMP. A virtual private gateway doesn't aggregate that way.

Direct Connect, from What is Direct Connect? and Direct Connect pricing, fetched 2026-09-25:

"Direct Connect links your internal network to a Direct Connect location over a standard Ethernet fiber-optic cable … bypassing internet service providers in your network path."

Bandwidth allocation — "Direct Connect speed": hosted connections give sub-1-Gbps steps; dedicated give 1 Gbps and up. Size to the sustained need, because port-hours bill whether you use them or not.

Internet Site-to-Site VPN Direct Connect
Setup none minutes physical circuit, partner or colocation
Recurring data transfer connection-hours + data transfer port-hours + data out
Egress rate internet rate internet rate Direct Connect rate (lower on the page)
Bandwidth variable 1.25 Gbps/tunnel (ECMP to add) 50 Mbps – 400 Gbps
Consistency variable variable ("internet weather") consistent, bypasses ISPs

⚠️ I did not fetch a page stating Direct Connect provisioning lead time or whether a Direct Connect link is encrypted. SAA1 lesson 3 flags the same encryption gap. Read docs.aws.amazon.com/directconnect/latest/UserGuide/ before answering either from memory.

Exam signal: "large, steady data egress from AWS to on-premises; reduce cost" → Direct Connect (lower per-GB out, and in is free). "Need connectivity this week, modest volume" → VPN. "Need more than 1.25 Gbps over VPN" → multiple VPNs on a Transit Gateway with ECMP.

CloudFront — cheaper and faster egress

The skill is "Determining strategic needs for content delivery networks (CDNs) and edge caching". From CloudFront pricing, fetched 2026-09-25:

The cost argument: every cache hit is a byte that doesn't leave your origin Region as internet egress, and the origin-to-CloudFront leg is waived. Caching mechanics (TTLs, origin failover) are in SAA2 lesson 6 and SAA3 lesson 4.

⚠️ I didn't retrieve CloudFront price classes — the page didn't mention them. Read the CloudFront developer guide before answering "restrict to cheaper edge locations".

⚠️ Global Accelerator appears in the routing skill. I did not fetch its pricing, so this module makes no cost claim about it; SAA3 lesson 4 covers what it does.

⚠️ DNS ("Network services with appropriate use cases (for example, DNS)"): I did not fetch Route 53 pricing. The cost-relevant design facts about alias records and health checks are in SAA2 lesson 5.

Throttling — protecting the bill as well as the backend

The skill "Selecting an appropriate throttling strategy". From Throttle requests to your REST APIs, fetched 2026-09-25:

"API Gateway throttles requests to your API using the token bucket algorithm, where a token counts for a request."

Four levels, applied in this order:

  1. Per-client or per-method limits in a usage plan (clients identified by API key)
  2. Per-method limits for a stage
  3. Account-level per Region
  4. AWS Regional throttling

When limits are exceeded, "Clients may receive 429 Too Many Requests error responses". And the honesty clause: "Both throttles and quotas are applied on a best-effort basis and should be thought of as targets rather than guaranteed request ceilings."

Exam signal: "limit each partner to 100 requests per second and 1 million a month" → usage plan + API keys. Throttling caps what a runaway client can make your Lambda and database spend.

Choosing, under exam conditions

The stem says Answer
"private instances read TBs from S3 via a NAT gateway; cut cost" S3 gateway endpoint — no additional charge
"same, but for DynamoDB" DynamoDB gateway endpoint
"same, for SQS / Secrets Manager" interface endpoint (charged; no gateway option)
"dev VPC, 3 AZs, minimise NAT cost" one shared NAT gateway
"production, must survive an AZ loss, heavy outbound" NAT gateway per AZ
"patchable, cheapest, very low traffic, ops overhead acceptable" NAT instance
"two VPCs, heavy traffic, lowest cost" VPC peering
"dozens of VPCs + on-premises, central routing" Transit Gateway
"static assets served globally; egress bill high" CloudFront (origin fetch waived)
"large steady egress to on-premises" Direct Connect
"need > 1.25 Gbps over VPN" multiple VPNs, Transit Gateway, ECMP, dynamic routing
"cap each API customer's request rate" API Gateway usage plan + API keys
"where is our data transfer cost coming from?" CUR usage types (lesson 1)

Check yourself

  1. What does an S3 gateway endpoint cost, and why does it cut the bill for private-subnet S3 access?
  2. One NAT gateway or one per AZ — give the cost argument for each.
  3. When is VPC peering the cheaper choice, and when does Transit Gateway win anyway?
  4. How do you get more than 1.25 Gbps over Site-to-Site VPN?
  5. Who pays for data transfer between Regions — the source or the destination?
Answers
  1. "There is no additional charge for using gateway endpoints." S3 traffic that used to pass through the NAT gateway — billed per GB processed — now routes to the free endpoint.
  2. One: fewer hourly charges, but traffic from other AZs crosses AZs and an AZ failure cuts every subnet's outbound — fine for dev. Per AZ: more hourly charges, but no cross-AZ transfer and "zone-independent architecture" — right for production or heavy traffic.
  3. Peering: "lowest overall cost", no per-GB processing, best under ~10 VPCs. Transit Gateway: hub-and- spoke when full-mesh peering becomes unmanageable (4,950 links for 100 VPCs) or you need shared on-premises connectivity — at $0.02/GB processed (Ohio).
  4. Multiple VPN connections on a Transit Gateway with ECMP, using dynamic routing.
  5. The source — "The data transfer charge is determined by the data transferred out from the source Region."

Teaching this section

← PreviousDatabase cost — engine, capacity mode, retention, and the cache in frontFinished →Cheat sheet, lab & quiz