AWS Solutions Architect Handbook SAA-C03, from zero Bipin Singh
Networking

Network performance and cost

3 min readChapter 16 of 48By Bipin Singh

Task statements 3.4 and 4.4 ask you to design networks that are fast and cheap. Most of this comes down to knowing where AWS charges for data transfer, and which features increase network performance.

Where data transfer costs money

Traffic Typical charge
Internet → AWS (inbound) Free
Within the same AZ using private IPs Free
Between AZs in the same Region Charged (per GB, in each direction)
Between Regions Charged
AWS → internet (outbound) Charged, tiered
Through a NAT gateway Hourly + per GB processed
Via gateway endpoints (S3, DynamoDB) Free
Via interface endpoints Hourly + per GB (often cheaper than NAT processing)
CloudFront to users Usually cheaper than serving directly from origin; origin → CloudFront transfer is free from AWS origins
Direct Connect Lower data transfer out rates than internet
Key idea

Common cost wins: use gateway endpoints for S3/DynamoDB instead of NAT; serve content through CloudFront; keep chatty components in the same AZ where availability allows; avoid unnecessary cross-Region replication.

NAT gateway design trade-off

Design Pros Cons
One NAT gateway per AZ Highly available; no cross-AZ traffic More hourly cost
One shared NAT gateway Cheaper for dev/test Single point of failure; cross-AZ charges

Production → one per AZ. Non-production → a shared one is often acceptable (the exam guide explicitly tests this choice).

Choosing connectivity on cost and bandwidth

Option Bandwidth Cost profile
Internet Variable No fixed cost; standard egress rates
Site-to-Site VPN Up to ~1.25 Gbps per tunnel; more with multiple VPNs + ECMP on Transit Gateway Low hourly cost
Direct Connect 1/10/100 Gbps dedicated; hosted from 50 Mbps Port-hour charges; cheaper egress for large volumes

Performance features

For EC2

Type Layout Use
Cluster Packed close together in one AZ Lowest latency, highest throughput between instances (HPC) — but a single rack/AZ risk
Spread Each instance on distinct hardware (max 7 running instances per AZ per group) Small numbers of critical instances that must not fail together
Partition Groups of instances in separate partitions (racks), up to 7 partitions per AZ Large distributed systems (HDFS, Cassandra, Kafka)

At the edge

For APIs: throttling

Placing resources

Exam patterns

Bipin Singh
Written by Bipin Singh

Senior Full-Stack Engineer · AI & AWS. I design and run production systems on AWS — serverless, data and AI.

Work with me