What the exam asks
Expect questions on data transfer paths (which hops are billed and how to reroute them), NAT and endpoints, VPC-to-VPC options (peering, Transit Gateway, PrivateLink), hybrid links (VPN or Direct Connect, and bandwidth), and edge and API controls (CloudFront, API Gateway caching and throttling).
Core ideas
The data transfer map
| Path | Charged? |
|---|---|
| Internet into AWS | Free |
| AWS out to the internet | Per GB |
| Same AZ, private IP addresses | Free |
| Across AZs in one Region | Per GB, in each direction |
| To a public or Elastic IP address, even in the same AZ | Per GB, like cross-AZ |
| Across Regions (peering, replication, TGW peering) | Per GB out of the source Region |
| EC2 to S3 or DynamoDB in the same Region | Free, unless it passes through a NAT gateway |
| Origin (S3, ALB, EC2) to CloudFront | Free; CloudFront to viewers is billed at CloudFront rates |
| Into AWS over Direct Connect | Free; outbound is billed at the lower DX rate |
Also know the per-resource charges:
- NAT gateway: hourly charge plus per GB processed.
- Interface endpoint: hourly charge per AZ plus per GB processed.
- Gateway endpoint: free.
- Transit Gateway: hourly charge per attachment plus per GB processed.
- VPC peering: no hourly charge. Same-AZ traffic over peering is free; cross-AZ and cross-Region traffic is billed.
- Public IPv4 addresses: every public IPv4 address, in use or idle, has an hourly charge.
- Network Load Balancer: turning on cross-zone load balancing adds inter-AZ data transfer charges. It is off by default.
NAT gateway economics
A NAT gateway bills per hour and per GB processed. The cheapest fixes, in order:
- Gateway endpoints for S3 and DynamoDB. They are free route-table targets that remove NAT processing for the heaviest traffic. They work only inside the VPC, in the same Region; they cannot be reached from on premises, through peering or through a transit gateway.
- Interface endpoints for other AWS services. They keep traffic private and cost less per GB than NAT, but each one bills hourly in every AZ.
- The right number of NAT gateways. Production uses one per AZ, which gives AZ-independent egress and avoids cross-AZ charges. Dev/test with light traffic can share one NAT gateway if losing egress during an AZ failure is acceptable. A NAT instance has a lower hourly cost but is self-managed, so it fails any “least operational overhead” requirement. (AWS now also offers regional NAT gateways that expand across AZs automatically; exam items are written around zonal NAT gateways.)
- Centralised egress. Many VPCs already attached to a transit gateway can share NAT gateways in one egress VPC. That removes dozens of NAT gateway-hours for a small TGW per-GB charge. VPC peering cannot do this, because peering does not allow edge-to-edge routing through a peer’s NAT gateway, internet gateway, VPN or Direct Connect.
- IPv6 egress goes through a free egress-only internet gateway, with no NAT needed.
Connecting VPCs
| Option | Cost model | Choose when |
|---|---|---|
| VPC peering | No hourly fee; same-AZ free, cross-AZ billed | Few VPCs, or one very chatty pair |
| Transit Gateway | Per attachment-hour + per GB processed | Many VPCs, transitive routing, shared VPN/DX, central egress |
| PrivateLink | Endpoint-hours per AZ + per GB, plus the NLB | One service exposed to many consumers, overlapping CIDRs |
A hybrid is common and cost-smart: keep the transit gateway as the hub, and add a direct peering connection for the one high-volume VPC pair. With longest-prefix routing, the specific peering route wins. For interface endpoints across many VPCs, centralise them in a shared services VPC: turn off their private DNS, create Route 53 private hosted zones for the service names, associate the zones with every VPC, and route through the transit gateway. AWS RAM cannot share interface endpoints.
Hybrid connectivity: internet, VPN or Direct Connect
- Site-to-Site VPN: low hourly cost and quick to set up. Traffic crosses the internet, so performance varies and egress is billed at internet rates. It makes a cheap backup to Direct Connect.
- Direct Connect: port-hours plus a lower outbound rate, with consistent performance. Choose it for steady, large, long-term transfers. Dedicated connections (1 Gbps and up) need your equipment in a DX location. Hosted connections from a DX Partner start at 50 Mbps and are the right-sized choice below 1 Gbps or with no colocation presence.
- Direct Connect gateway: one connection reaches VPCs in many Regions through a global DX gateway. Do not buy a circuit per Region.
- Sizing: 1 Gbps moves about 10.8 TB a day at full line rate, roughly 8 TB at realistic utilisation. Divide the data by the time window and add headroom.
- One-time bulk moves that would take weeks over the link go to the Snow Family, not a bigger circuit.
Edge and API cost controls
CloudFront cuts egress three ways: origin fetches are free, caching removes repeat origin transfers, and CloudFront’s rates are lower than S3 or EC2 internet rates. Use origin access control (OAC) to keep the S3 bucket private. Price classes can exclude the most expensive edge locations. S3 Transfer Acceleration and Global Accelerator improve performance and add charges, so they are never the cost answer. Requester Pays shifts S3 download costs to other authenticated AWS accounts, not to anonymous users. API Gateway caching answers repeated GETs without invoking the backend. Usage plans with API keys apply throttling and quotas per client. Edge-optimized endpoints do not cache responses.
Worked examples
Exam technique
- Trace the packet. Mark every NAT gateway, AZ or Region boundary, transit gateway and internet hop on the path. Each mark is a charge.
- Rule out options that break requirements first: public subnets when instances must stay private, one AZ in production, internet VPN when performance must be consistent.
- Prefer free building blocks: gateway endpoints, same-AZ placement, peering for chatty pairs, CloudFront origin fetches.
- Spot performance features posing as savings. Global Accelerator, Transfer Acceleration, ENA and bigger DX ports make traffic faster, not cheaper.
Common mistakes
Quick recap
- Free: inbound data, same-AZ private traffic, gateway endpoints, origin-to-CloudFront transfers and VPC peering hours.
- Billed per GB: cross-AZ (both directions), cross-Region, internet egress, NAT processing, TGW processing, interface endpoint processing, and NLB cross-zone traffic.
- S3 and DynamoDB from private subnets: gateway endpoint first.
- NAT gateways: one per AZ for production, one shared for light dev, and a central egress VPC via TGW for many VPCs.
- Two VPCs, or one chatty pair: peering. Many VPCs: TGW. Endpoints for many VPCs: centralise and use Route 53 private hosted zones.
- Steady, large hybrid traffic: Direct Connect. Below 1 Gbps: a hosted connection. Many Regions: a DX gateway. Backup: VPN.
- Global downloads: CloudFront with OAC. Repeated API GETs: API Gateway caching. Per-client limits: usage plans.