StudyToCert

All certifications / Solutions Architect Associate / Lessons

AWS Certified Solutions Architect – Associate SAA-C03 · Domain 1: Design Secure Architectures

Private access to AWS services: gateway endpoints, interface endpoints (PrivateLink) and endpoint policies

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Most AWS services, such as S3, DynamoDB, SQS and Secrets Manager, are reached through public service endpoints. A private instance can reach them through a NAT gateway, but then the traffic leaves your VPC's private address space, needs an internet path, and you pay NAT data processing charges. VPC endpoints let resources in your VPC reach AWS services privately, without an internet gateway, NAT device or public IP addresses, and the traffic stays on the AWS network. Many security and cost questions on the exam turn on choosing the right kind of endpoint. Gateway endpoints exist for exactly two services: Amazon S3 and Amazon DynamoDB. You create the endpoint and select route tables; AWS adds a route whose destination is the service's prefix list (a managed list of the service's IP ranges, shown as pl-xxxxxxxx) and whose target is the endpoint. Applications keep using the normal service hostname, and the route table does the rest. Gateway endpoints have no hourly or data charge. They only work for traffic that originates inside the VPC; they cannot be used from on-premises over VPN or Direct Connect, or from a peered VPC.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Solutions Architect Associate for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Solutions Architect Associate study plan