Be able to select the right AWS control for a stated security goal: VPC endpoints for private service access, ACM plus ALB listeners for TLS, security group references for database isolation, and IAM and KMS for least privilege and encryption. Get the source of trust right.
Start practicing
Design Secure Architectures — choose a session length
Free · No account required
Domain overview
This domain covers how to design identity, network, and data protection controls on AWS. Questions present a scenario and ask you to pick the service or configuration that meets a stated security requirement, such as private S3 access, TLS termination, database isolation, or encryption of data in transit and at rest.
Exam objectives
Choosing S3 gateway VPC endpoints to keep traffic off the public internet
Using AWS Certificate Manager certificates with an Application Load Balancer HTTPS listener
Configuring RDS security groups to allow only a specific EC2 instance or security group
Applying IAM roles, KMS keys, and bucket policies for least-privilege access
Assuming an internet gateway or NAT gateway keeps S3 traffic private; a VPC endpoint is required for AWS-private connectivity.
Terminating TLS at the ALB but forgetting that backend traffic to EC2 is separate and may need its own encryption.
Opening a database security group to a CIDR range instead of referencing the application's security group as the source.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A company is concerned about unauthorized access and potential data exfiltration within their AWS environment. They need a service that can continuously monitor VPC Flow Logs, AWS CloudTrail management events, and DNS logs to identify suspicious activities using machine learning. Which solution should the architect recommend for centralized threat detection?
2An enterprise requires all data stored in Amazon S3 to be encrypted at rest. The security team must maintain full control over the encryption keys, including the ability to rotate them annually and define access policies for the keys themselves. Which encryption method meets these requirements with the least operational overhead?
3A security architect is designing a multi-tier application in a VPC. The requirement is to block all traffic from a specific range of malicious IP addresses (CIDR 192.0.2.0/24) while allowing standard web traffic (HTTPS) from all other sources to the web tier. Which TWO actions should the architect take to implement this? (Select TWO.)
4An application running on an Amazon EC2 instance needs to securely access data in an Amazon DynamoDB table. What is the most secure way to provide the application with the necessary permissions?
5A large corporation uses AWS Organizations to manage hundreds of accounts. The security team wants to ensure that no account can provision resources in unauthorized regions and that only approved AWS services can be used. Which TWO features should be used to enforce these constraints across the entire organization? (Select TWO.)
6An enterprise organization is planning a centralized logging architecture across hundreds of AWS accounts using AWS CloudTrail and Amazon S3. Security mandates state that all log files delivered to the centralized S3 bucket must be cryptographically verified to ensure they have not been modified or tampered with after delivery. Which TWO actions must a Solutions Architect implement to achieve this mandate? (Choose two.)
7A company wants to ensure that no developer can create an Amazon S3 bucket in any AWS region except for us-east-1 and us-west-2 across their entire AWS Organization. Which solution provides the most efficient and centralized way to enforce this across all member accounts?
8A financial services firm must store transaction logs in Amazon S3 for seven years to meet regulatory requirements. The logs must be protected against any modification or deletion by any user, including the root user, during this period. Which S3 feature should be implemented?
9A web application is deployed on Amazon EC2 instances within a private subnet. The application must receive traffic from an Application Load Balancer (ALB) in a public subnet and connect to an Amazon RDS MySQL database in a different private subnet. Which TWO steps are required to secure this architecture using security groups?
10Refer to the exhibit. A solutions architect reviews the following IAM policy applied to a user. What is the effect of this policy when the user attempts to access an object in the bucket from an IP address of 198.51.100.5?
11A company is concerned that its database credentials, currently stored as environment variables in AWS Lambda, are not being rotated regularly. Which AWS service should the company use to securely store and automatically rotate these credentials?
12A company's public-facing application is experiencing a Distributed Denial of Service (DDoS) attack. The application is hosted on EC2 instances behind an Application Load Balancer (ALB). Which TWO AWS services or features can be used to mitigate this attack and protect the application?
13A security team needs to identify and protect sensitive data, such as credit card numbers and passport IDs, that may be stored across hundreds of S3 buckets in multiple AWS accounts. Which service should they use to automate this discovery process?
14An organization is using AWS Control Tower to manage multiple AWS accounts. They need to implement a set of guardrails to ensure that all accounts remain compliant with security best practices. Which THREE components or features are part of a standard AWS Control Tower landing zone implementation?
15A company wants to improve the security of its Amazon RDS for PostgreSQL database. They want to eliminate the need for storing database passwords in application code and simplify the management of database access for their EC2-based applications. Which solution should they implement?
16Refer to the exhibit. A security audit identifies that data is being transmitted to an S3 bucket named 'corporate-data' without encryption in transit. Which behavior does this bucket policy enforce to address this concern?
17An organization needs to perform continuous security assessments of its Amazon EC2 instances to identify software vulnerabilities and unintended network exposure. Which service should they use to automate these assessments and provide a centralized view of the findings?
18A company is building a mobile application that needs to authenticate users and allow them to upload photos directly to an Amazon S3 bucket. Which TWO Amazon Cognito components should be used to provide a secure and scalable solution?
19A company wants to ensure that its internal applications can access Amazon S3 without the traffic ever leaving the AWS network or passing through the public internet. What should they implement to achieve this securely?
20An organization needs to issue and manage SSL/TLS certificates for its internal microservices, which are not accessible from the public internet. They want to avoid the overhead of managing their own PKI infrastructure. Which service should they use?
21A company is hosting a multi-tier web application on AWS using Amazon EC2 instances in a private subnet behind an Application Load Balancer (ALB). The security team requires that all incoming web traffic is encrypted in transit from the client to the ALB and from the ALB to the backend EC2 instances. Which combination of configurations meets these requirements?
22A company is hosting a sensitive web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The compliance team requires that all data at rest must be encrypted using keys that are rotated annually, and all access to these keys must be logged for auditing purposes. Which solution meets these requirements with the least administrative effort?
23A security engineer needs to block a specific range of malicious IP addresses from accessing an entire subnet within a VPC. The solution must ensure that the traffic is rejected before it reaches any EC2 instances. Which AWS feature should be used to implement this restriction?
24A solutions architect is designing a storage solution for a financial firm. The firm requires that data stored in Amazon S3 must be protected against accidental deletion and all changes to the data must be versioned. Which TWO features should the architect implement to meet these requirements? (Select TWO)
25Refer to the exhibit. A company has applied the following bucket policy to an S3 bucket named 'finance-reports'. A user is attempting to download a file from this bucket from the IP address 203.0.113.15 using an authenticated session without MFA. What will be the result of this request?
26A company's security team identifies that its public-facing web application is being targeted by SQL injection and cross-site scripting (XSS) attacks. The application is running on EC2 instances behind an Application Load Balancer (ALB). Which service should the solutions architect implement to protect the application from these specific web-based attacks?
27A company needs to store database credentials for an application running on Amazon ECS. The credentials must be encrypted and automatically rotated every 30 days without requiring an application restart. Which TWO AWS services should be used together to achieve this? (Select TWO)
28A company wants to implement a service that continuously monitors for malicious activity and unauthorized behavior across its AWS accounts, such as cryptocurrency mining or unusual API calls. Which AWS service should they use?
29Refer to the exhibit. A security administrator is reviewing a CloudTrail log entry for an 'Access Denied' error. The user 'Alice' is trying to upload a file to an S3 bucket. Alice has an IAM policy that allows 's3:PutObject' on all resources. What is the most likely cause of this error?
30A large enterprise uses AWS Organizations to manage multiple accounts. The Chief Information Security Officer (CISO) wants to ensure that no account within the organization can create any resources in regions other than 'us-east-1' and 'us-west-2'. What is the most efficient way to enforce this across the entire organization?
31A healthcare company must store patient records in Amazon S3 for a minimum of 7 years to meet regulatory requirements. During this period, the records must not be deleted or modified by any user, including the root user. Which S3 feature should be used to enforce this?
32A company is building a zero-trust architecture for its internal microservices running on Amazon EKS. Which THREE steps should the solutions architect take to ensure secure, least-privilege communication between services? (Select THREE)
33A data analytics company stores massive amounts of data in Amazon S3. They need a way to automatically identify and flag sensitive data, such as Personally Identifiable Information (PII) or financial records, to ensure it is not being mishandled. Which AWS service is designed for this task?
34A company is launching a high-profile marketing campaign and expects a significant increase in traffic. They are concerned about potential Distributed Denial of Service (DDoS) attacks targeting their Application Load Balancer. Which AWS service provides advanced protection and includes 24/7 access to the AWS Shield Response Team (SRT)?
35A company is developing a mobile application that allows users to sign in using their social media accounts (e.g., Google or Facebook). After signing in, the application needs to obtain temporary AWS credentials to upload photos directly to an Amazon S3 bucket. Which service should the architect use?
36A company is migrating a web application to AWS and needs to ensure that all data stored in Amazon S3 is encrypted at rest using keys managed by the company. The company must be able to rotate these keys annually and maintain full control over key access policies. Which solution meets these requirements?
37A developer needs to access an Amazon RDS database from an EC2 instance within a private subnet. The database must only accept traffic from the instance. Which security configuration is most appropriate?
38A company is designing a multi-tier application. The web tier is public, and the database tier is private. Which TWO actions should the architect take to ensure the database tier is secure? (Select TWO.)
39Refer to the exhibit. An IAM policy is applied to an IAM user to grant access to an S3 bucket. However, the user is still receiving an 'Access Denied' error when attempting to list the objects in the bucket. What is the cause of this error?
40A company must share an S3 bucket with a third-party vendor. The vendor has their own AWS account. What is the most secure method to grant the vendor access to the S3 bucket?
41A web application hosted on EC2 instances needs to access a DynamoDB table. What is the most secure way to provide the application with the necessary permissions?
42A company is experiencing unauthorized network traffic in their VPC. They need to inspect traffic patterns between subnets to identify the source of the traffic. Which tool should they use?
43An architect is designing a secure storage solution for highly sensitive financial data in S3. Which THREE security controls should be implemented? (Select THREE.)
44A company is using AWS Secrets Manager to manage database credentials. The company needs to automatically rotate these credentials every 30 days. How can this be accomplished?
45An organization wants to protect their web application from common web exploits like SQL injection and cross-site scripting (XSS). Which AWS service should they use?
46A security auditor requires that all EC2 instances must be running with specific software versions and that any instance not compliant with these versions must be automatically terminated. Which THREE services should be used to achieve this? (Select THREE.)
47Refer to the exhibit. This bucket policy grants access to a specific account. A user in that account still cannot access the object. What is the most likely reason?
48A company is hosting a web application on EC2 instances behind an Application Load Balancer. The security team requires that all data in transit between the client and the ALB be encrypted using TLS. Which service should the architect use to manage the SSL/TLS certificates for the ALB?
49A developer needs to access an S3 bucket from an EC2 instance. For security best practices, the developer must avoid hardcoding long-term credentials on the instance. What is the most secure method to provide the necessary permissions?
50Refer to the exhibit. An administrator has applied the provided bucket policy to 'my-secure-bucket'. What is the effect of this policy on access to the bucket?
51An architect is designing a secure VPC architecture. Which TWO actions should be taken to ensure the infrastructure is compliant with security best practices regarding network isolation?
Be able to select the right AWS control for a stated security goal: VPC endpoints for private service access, ACM plus ALB listeners for TLS, security group references for database isolation, and IAM and KMS for least privilege and encryption. Get the source of trust right.
The Courseiva SAA-C03 question bank contains 51 questions in the Design Secure Architectures domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Design Secure Architectures domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included