Pair your devices with a code and playback position follows you: pause on this device, hit resume on the other. Position is saved to the site every minute and on pause.
Open this panel on your other device and enter the same code.
Starts this lesson and continues through 3 more to the end of certification prep.
Task statement 4.4 is "Design cost-optimized network architectures", and its skills are the most concrete in the domain. Verbatim:
The distinguishing question is: which direction is the byte going, and what does it pass through on the way? Every network cost answer is about removing a charged hop.
From the pages below, fetched 2026-09-25 and checked against the raw page text. The EC2 page's "Data Transfer within the same AWS Region" section is the most useful single source; its internet-egress rate table is filled in client-side and I don't quote it.
| Direction | Rule | Source |
|---|---|---|
| Internet → AWS | "There's no charge for data transfer from the internet to AWS." | CUR data transfer guide |
| AWS → internet | charged; "100 GB of free data transfer out to the internet free each month, aggregated across all AWS Services and Regions (except China and GovCloud)" | EC2 pricing |
| Between AZs (same Region) | "Data transferred "in" to and "out" from Amazon EC2, Amazon RDS, Amazon Redshift, Amazon DynamoDB Accelerator (DAX), Amazon ElastiCache instances, and Elastic Network Interfaces across Availability Zones in the same AWS Region is charged at $0.01/GB in each direction." | EC2 pricing |
| Same AZ | "Data transferred between Amazon EC2, Amazon RDS, Amazon Redshift, Amazon ElastiCache instances, and Elastic Network Interfaces in the same Availability Zone is free." | EC2 pricing |
| EC2 ↔ S3, DynamoDB, SQS, SNS, Kinesis, ECR… same Region | "Data transferred directly … between Amazon S3, … Amazon DynamoDB, Amazon SES, Amazon SQS, Amazon Kinesis, Amazon ECR, Amazon SNS or Amazon SimpleDB and Amazon EC2 instances in the same AWS Region is free." | EC2 pricing |
| …but a service in the path | "If other AWS services are in the path of your data transfer, you will be charged their associated data processing costs. These services include, but are not limited to, PrivateLink endpoints, NAT Gateway and Transit Gateway." | EC2 pricing |
| Between Regions | "There's no charge for the data transferred into the destination Region. The data transfer charge is determined by the data transferred out from the source Region." | CUR data transfer guide |
| S3 → any AWS service, same Region | no charge | S3 pricing |
| S3 → CloudFront | no charge | S3 pricing |
| AWS origin → CloudFront | "Data transfer between CloudFront and your AWS origins is automatically waived" | CloudFront pricing |
| VPC peering, same AZ | "All data transfer over a VPC peering connection that stays within an Availability Zone is free." | multi-VPC whitepaper |
| VPC peering, cross-AZ | "charged at the standard in-region data transfer rates"; the VPC pricing page: "charged at $0.01/GB in both "In" and "Out" direction" | whitepaper; VPC pricing |
| Direct Connect in | "data transferred into AWS over AWS Direct Connect is $0.00 per GB in all locations" | Direct Connect pricing |
That last row is the whole NAT-gateway story in one sentence: EC2 → S3 in the same Region is free, until a NAT gateway sits in the path and charges data processing on every byte.
The cost-shaped design rules that follow:
bytes IN from the internet free → ingest is cheap
bytes OUT to the internet charged → put CloudFront in front (origin fetch waived)
bytes between AZs charged ×2 → keep chatty tiers in one AZ where resilience allows
bytes between Regions charged → replicate only what you must
S3 ↔ same-Region service free → but a NAT gateway in the path is not (below)
⚠️ Resilience costs transfer. Multi-AZ designs from SAA2 send traffic across AZs, and that traffic
is charged. The exam's answer is almost never "collapse to one AZ to save money" for production — the
skill is "Determining the required availability for different classes of workloads". Non-production,
yes; production, no.
From Compare NAT gateways and NAT instances, fetched 2026-09-25 — the knowledge item is literally "NAT instance costs compared with NAT gateway costs":
| NAT gateway | NAT instance | |
|---|---|---|
| Cost basis | "the number of NAT gateways you use, duration of usage, and amount of data that you send through" | "the number of NAT instances that you use, duration of usage, and instance type and size" |
| Availability | "Highly available. NAT gateways in each Availability Zone are implemented with redundancy." | "Use a script to manage failover between instances." |
| Bandwidth | "Scale up to 100 Gbps." | "Depends on the bandwidth of the instance type." |
| Maintenance | "Managed by AWS." | "Managed by you" — patching, updates |
| Security groups | can't associate | can associate |
| Port forwarding / bastion | not supported | supported |
AWS's recommendation, verbatim: "We recommend that you use NAT gateways because they provide better availability and bandwidth and require less effort on your part to administer."
The cost trade in one line: a NAT gateway charges per GB processed on top of hourly; a NAT instance charges only for the instance, but you run it, patch it, and script its failover. At high volume the per-GB charge dominates; at tiny volume in a dev account, a small NAT instance can be cheaper. The exam's default answer for production is still the NAT gateway, on operational overhead.
Prices — from the US East (Ohio) worked example on Amazon VPC pricing, fetched 2026-09-25: "For this region, the rate is $0.045 per hour", and 1 GB through the gateway "will result in a charge of $0.045". "Data processing charges apply for each gigabyte processed through the NAT gateway regardless of the traffic's source or destination", and "You also incur standard AWS data transfer charges". The same example ends with the fix: "To avoid the NAT Gateway Data Processing charge in this example, you could set up a gateway Type VPC endpoint."
From Pricing for NAT gateways, fetched 2026-09-25:
"If your AWS resources send or receive a significant volume of traffic across Availability Zones, ensure that the resources are in the same Availability Zone as the NAT gateway. Alternatively, create a NAT gateway in each Availability Zone with resources."
And the comparison page: "Create a NAT gateway in each Availability Zone to ensure zone-independent architecture."
| Single shared NAT gateway | NAT gateway per AZ | |
|---|---|---|
| Hourly charges | one | one per AZ |
| Cross-AZ transfer | traffic from other AZs crosses AZs to reach it | none — each AZ uses its own |
| AZ failure | lose the NAT AZ → every private subnet loses outbound | zone-independent |
| Fits | dev/test, low traffic | production, or high traffic |
⚠️ The VPC pricing page also describes a Regional NAT Gateway: "you are charged for each hour that
the NAT Gateway is configured in each availability zone" — its Ohio example bills three AZs as three
NAT Gateway-hours. SAA2 flagged regional NAT gateways as unverified and I did not fetch the user-guide
page for them, so this lesson doesn't teach their behaviour. Read
docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html.
From Gateway endpoints, fetched 2026-09-25:
"Gateway VPC endpoints provide reliable connectivity to Amazon S3 and DynamoDB without requiring an internet gateway or a NAT device for your VPC."
"There is no additional charge for using gateway endpoints."
The VPC pricing page agrees: "There are no data processing or hourly charges for using Gateway Type VPC endpoints."
This is the highest-yield network cost fact on the exam. A private-subnet workload reading from S3 through a NAT gateway pays NAT per-GB processing on every byte. Add an S3 gateway endpoint and that traffic routes to the endpoint instead — free.
How it works: "Each subnet route table must have a route that sends traffic destined for the service to the gateway endpoint using the prefix list for the service." And by longest-prefix match, "the endpoint route takes precedence for traffic destined for the service … in the current Region."
⚠️ Limits that decide questions:
The NAT pricing page itself recommends the move: "If most traffic through your NAT gateway is to AWS services that support interface endpoints or gateway endpoints, consider creating an interface endpoint or gateway endpoint for these services."
⚠️ Interface endpoints are not free. The VPC pricing page lists them separately and I did not
capture their rates. They can still be cheaper than NAT for heavy traffic to one service — check
aws.amazon.com/privatelink/pricing/ before claiming it.
From the multi-VPC whitepaper, VPC peering section, fetched 2026-09-25:
"VPC peering offers the lowest overall cost and highest aggregate performance when compared to other options for inter-VPC connectivity."
"VPC peering is best used when … the number of VPCs to be connected is less than 10."
But it doesn't scale: "if you have 100 VPCs and you want to setup a full mesh peering between them, it
will take 4,950 peering connections [n(n-1)/2]", against "a maximum limit of 125 active
peering connections per VPC". And it's not transitive — from the peering guide: "you can't route
traffic from VPC B to VPC C through VPC A." Nor can a peered VPC borrow another's internet gateway,
NAT, VPN, Direct Connect, or gateway endpoint.
Transit Gateway, from Transit Gateway pricing, fetched 2026-09-25 — figures from the page's US East (Ohio) worked example:
| VPC peering | Transit Gateway | |
|---|---|---|
| Topology | point-to-point, no transitive routing | hub-and-spoke |
| Per-GB processing | none — only data transfer (free same-AZ) | $0.02/GB (Ohio) + transfer |
| Hourly | none stated | per attachment |
| Sweet spot | < 10 VPCs, high volume between a few | many VPCs, shared VPN/DX, central routing |
Exam signal: "two VPCs, heavy traffic, lowest cost" → peering. "Forty VPCs across accounts, plus on-premises, simple routing" → Transit Gateway, accepting the per-GB charge for operational sanity. "Connect one VPN to many VPCs" — the VPN quotas page recommends it: "To connect the same Site-to-Site VPN connection to multiple VPCs, we recommend that you explore using a transit gateway."
Site-to-Site VPN, from VPN pricing and VPN quotas, fetched 2026-09-25:
That last line is the answer to the skill "a single VPN compared with multiple VPNs": multiple VPN connections on a Transit Gateway, dynamic routing, ECMP. A virtual private gateway doesn't aggregate that way.
Direct Connect, from What is Direct Connect? and Direct Connect pricing, fetched 2026-09-25:
"Direct Connect links your internal network to a Direct Connect location over a standard Ethernet fiber-optic cable … bypassing internet service providers in your network path."
Bandwidth allocation — "Direct Connect speed": hosted connections give sub-1-Gbps steps; dedicated give 1 Gbps and up. Size to the sustained need, because port-hours bill whether you use them or not.
| Internet | Site-to-Site VPN | Direct Connect | |
|---|---|---|---|
| Setup | none | minutes | physical circuit, partner or colocation |
| Recurring | data transfer | connection-hours + data transfer | port-hours + data out |
| Egress rate | internet rate | internet rate | Direct Connect rate (lower on the page) |
| Bandwidth | variable | 1.25 Gbps/tunnel (ECMP to add) | 50 Mbps – 400 Gbps |
| Consistency | variable | variable ("internet weather") | consistent, bypasses ISPs |
⚠️ I did not fetch a page stating Direct Connect provisioning lead time or whether a Direct Connect
link is encrypted. SAA1 lesson 3 flags the same encryption gap. Read
docs.aws.amazon.com/directconnect/latest/UserGuide/ before answering either from memory.
Exam signal: "large, steady data egress from AWS to on-premises; reduce cost" → Direct Connect (lower per-GB out, and in is free). "Need connectivity this week, modest volume" → VPN. "Need more than 1.25 Gbps over VPN" → multiple VPNs on a Transit Gateway with ECMP.
The skill is "Determining strategic needs for content delivery networks (CDNs) and edge caching". From CloudFront pricing, fetched 2026-09-25:
The cost argument: every cache hit is a byte that doesn't leave your origin Region as internet
egress, and the origin-to-CloudFront leg is waived. Caching mechanics (TTLs, origin failover) are in
SAA2 lesson 6 and SAA3 lesson 4.
⚠️ I didn't retrieve CloudFront price classes — the page didn't mention them. Read the CloudFront developer guide before answering "restrict to cheaper edge locations".
⚠️ Global Accelerator appears in the routing skill. I did not fetch its pricing, so this module makes
no cost claim about it; SAA3 lesson 4 covers what it does.
⚠️ DNS ("Network services with appropriate use cases (for example, DNS)"): I did not fetch Route 53
pricing. The cost-relevant design facts about alias records and health checks are in SAA2 lesson 5.
The skill "Selecting an appropriate throttling strategy". From Throttle requests to your REST APIs, fetched 2026-09-25:
"API Gateway throttles requests to your API using the token bucket algorithm, where a token counts for a request."
Four levels, applied in this order:
When limits are exceeded, "Clients may receive 429 Too Many Requests error responses". And the
honesty clause: "Both throttles and quotas are applied on a best-effort basis and should be thought of
as targets rather than guaranteed request ceilings."
Exam signal: "limit each partner to 100 requests per second and 1 million a month" → usage plan + API keys. Throttling caps what a runaway client can make your Lambda and database spend.
| The stem says | Answer |
|---|---|
| "private instances read TBs from S3 via a NAT gateway; cut cost" | S3 gateway endpoint — no additional charge |
| "same, but for DynamoDB" | DynamoDB gateway endpoint |
| "same, for SQS / Secrets Manager" | interface endpoint (charged; no gateway option) |
| "dev VPC, 3 AZs, minimise NAT cost" | one shared NAT gateway |
| "production, must survive an AZ loss, heavy outbound" | NAT gateway per AZ |
| "patchable, cheapest, very low traffic, ops overhead acceptable" | NAT instance |
| "two VPCs, heavy traffic, lowest cost" | VPC peering |
| "dozens of VPCs + on-premises, central routing" | Transit Gateway |
| "static assets served globally; egress bill high" | CloudFront (origin fetch waived) |
| "large steady egress to on-premises" | Direct Connect |
| "need > 1.25 Gbps over VPN" | multiple VPNs, Transit Gateway, ECMP, dynamic routing |
| "cap each API customer's request rate" | API Gateway usage plan + API keys |
| "where is our data transfer cost coming from?" | CUR usage types (lesson 1) |