StudyToCert

All certifications / Solutions Architect Associate / Lessons

AWS Certified Solutions Architect – Associate SAA-C03 · Domain 1: Design Secure Architectures

VPC security layers: security groups vs network ACLs, public and private subnets, NAT gateways, bastion hosts vs Session Manager

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

A virtual private cloud (VPC) is your own isolated network in an AWS Region, defined by an IPv4 CIDR (Classless Inter-Domain Routing) block such as 10.0.0.0/16. You divide it into subnets, and each subnet lives in exactly one Availability Zone (AZ). Security in a VPC comes in layers: where a subnet can route, which firewalls sit in front of each resource, and how administrators reach machines. The exam expects you to design all three so that only the load balancer faces the internet and everything else stays private.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Solutions Architect Associate for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Solutions Architect Associate study plan