SAA-C03 Design Secure Architectures Practice Question
A company is designing a multi-tier application. The web tier is public, and the database tier is private. Which TWO actions should the architect take to ensure the database tier is secure? (Select TWO.)
⚠ Common exam trap
SAA-C03 often tests the misconception that a Network ACL alone can secure a database in a public subnet, but private subnet placement and security group references are essential.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Place the database instances in a private subnet.
Option B is correct because placing the database instances in a private subnet removes them from direct internet reachability, since private subnets have no route to an Internet Gateway, which is the foundational control for protecting a database tier. Option C is correct because referencing the web tier's security group as the source in the database security group's inbound rule enforces least-privilege, instance-level access so only the web tier can reach the database on the required port (for example, 3306 for MySQL or 5432 for PostgreSQL). Option A is wrong because a public subnet is routable to the internet, so even with a restrictive Network ACL the database would still be exposed at the subnet level. Option D is wrong because attaching an Internet Gateway to the private subnet's route table would make that subnet public and expose the database to inbound internet traffic. Option E is wrong because allowing all internet traffic to the database via a Network ACL directly violates the requirement to keep the database tier private and secure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Place the database instances in a public subnet with a restrictive Network ACL.
Why it's wrong here
Public subnets are routable from the internet. Placing a database here, even with an ACL, increases the attack surface significantly. Best practice mandates that databases containing sensitive data reside in private subnets where there is no direct internet gateway route, ensuring they remain isolated from external public traffic.
- ✓
Place the database instances in a private subnet.
Why this is correct
Private subnets are designed for backend resources that do not require direct internet access. By placing the database here, the architect ensures that the database is not exposed to the public internet, satisfying the fundamental security requirement for protecting backend data tiers from external unauthorized access attempts.
- ✓
Allow the database security group to receive traffic from the web tier security group.
Why this is correct
This configuration follows the principle of least privilege. By restricting inbound database traffic to only the web tier's security group, the architect limits the potential attack vectors. Even if an instance in a different part of the VPC is compromised, it cannot reach the database directly.
- ✗
Attach an Internet Gateway to the private subnet route table.
Why it's wrong here
Attaching an Internet Gateway to a private subnet converts it effectively into a public subnet. This would expose the database to the internet, negating the purpose of the private subnet and directly violating the security goal of isolating the database from public-facing infrastructure and external network threats.
- ✗
Use a Network ACL to allow all traffic from the internet to the database.
Why it's wrong here
Network ACLs should be used to restrict traffic, not enable broad access. Allowing all internet traffic to the database creates an immediate and severe security vulnerability. All inbound traffic to a private database must be explicitly and narrowly defined to ensure compliance and prevent unauthorized access by external actors.
Visual reference
About these practice questions
This SAA-C03 question is part of Courseiva's 149-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.